Security update for jackson-annotations, jackson-core, jackson-databind
This security update addresses multiple vulnerabilities in jackson-annotations, jackson-core, and jackson-databind libraries. The issues include bypasses of @JsonIgnoreProperties exclusions, unauthorized writes to @JsonView restricted fields due to missing view guards, and bypasses of @JsonIgnore restrictions on Java Records caused by mismatches in property renaming and ignore-filtering. The update advances all three components to version 2.18.9, which includes fixes for these vulnerabilities.
AI Analysis
Technical Summary
The update for jackson-annotations, jackson-core, and jackson-databind fixes three vulnerabilities: CVE-2026-54515 allows bypassing @JsonIgnoreProperties exclusions by rebuilding the property map from unfiltered bean properties; CVE-2026-59889 involves missing view guards when deserializing @JsonUnwrapped properties, potentially allowing unauthorized writes to fields restricted by @JsonView; CVE-2026-59888 concerns a mismatch between property renaming and ignore-filtering on Java Records, enabling bypass of @JsonIgnore restrictions. The fixed versions are 2.18.9 for all three components, which also honors @JsonView for external-type-id properties.
Potential Impact
These vulnerabilities could allow attackers to bypass intended property exclusion and view restrictions during JSON deserialization, potentially leading to unauthorized data exposure or modification within applications using affected versions of the jackson libraries.
Mitigation Recommendations
Upgrade jackson-annotations, jackson-core, and jackson-databind to version 2.18.9 or later to apply the official fixes for these vulnerabilities.
Security update for jackson-annotations, jackson-core, jackson-databind
Description
This security update addresses multiple vulnerabilities in jackson-annotations, jackson-core, and jackson-databind libraries. The issues include bypasses of @JsonIgnoreProperties exclusions, unauthorized writes to @JsonView restricted fields due to missing view guards, and bypasses of @JsonIgnore restrictions on Java Records caused by mismatches in property renaming and ignore-filtering. The update advances all three components to version 2.18.9, which includes fixes for these vulnerabilities.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The update for jackson-annotations, jackson-core, and jackson-databind fixes three vulnerabilities: CVE-2026-54515 allows bypassing @JsonIgnoreProperties exclusions by rebuilding the property map from unfiltered bean properties; CVE-2026-59889 involves missing view guards when deserializing @JsonUnwrapped properties, potentially allowing unauthorized writes to fields restricted by @JsonView; CVE-2026-59888 concerns a mismatch between property renaming and ignore-filtering on Java Records, enabling bypass of @JsonIgnore restrictions. The fixed versions are 2.18.9 for all three components, which also honors @JsonView for external-type-id properties.
Potential Impact
These vulnerabilities could allow attackers to bypass intended property exclusion and view restrictions during JSON deserialization, potentially leading to unauthorized data exposure or modification within applications using affected versions of the jackson libraries.
Mitigation Recommendations
Upgrade jackson-annotations, jackson-core, and jackson-databind to version 2.18.9 or later to apply the official fixes for these vulnerabilities.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:21375-1
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-59888","CVE-2026-59889"]
- State
- PUBLISHED
Threat ID: 6aab496a55bf5e2cf5990d14
Added to database: 09/17/2026, 01:59:06 UTC
Last enriched: 09/17/2026, 02:12:22 UTC
Last updated: 09/17/2026, 02:12:22 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.