CVE-2026-54514
MEDIUMjackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
Title source: cnaDescription
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5
X_Refsource_Misc x_refsource_misc
https://github.com/FasterXML/jackson-databind/pull/5951
X_Refsource_Misc x_refsource_misc
https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4
Scores
CVSS v3
5.3
EPSS
0.0022
EPSS Percentile
12.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (9)
com.fasterxml.jackson.core/jackson-databind
2.0.0 - 2.18.8Maven
com.fasterxml.jackson.core/jackson-databind
2.19.0 - 2.21.4Maven
com.fasterxml.jackson.core/jackson-databind
3.0.0 - 3.1.4Maven
fasterxml/jackson-databind
2.0.0 - 2.18.8
FasterXML/jackson-databind
>= 2.0.0, < 2.18.8
FasterXML/jackson-databind
>= 2.19.0, < 2.21.4
FasterXML/jackson-databind
>= 3.0.0, < 3.1.4
tools.jackson.core/jackson-databind
2.19.0 - 2.21.4Maven
tools.jackson.core/jackson-databind
3.0.0 - 3.1.4Maven
Published
Jun 23, 2026
Tracked Since
Jun 24, 2026