{"id":"CVE-2026-54516","summary":"jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields","details":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty(\"renamed\") on the getter and @JsonIgnore on the setter to be renamed rather than dropped. With MapperFeature.INFER_PROPERTY_MUTATORS enabled (default), the private backing field is retained; during deserialization BeanDeserializerFactory.addBeanProps() sees hasField()==true, builds a FieldProperty, and makes the backing field writable. An attacker supplying the renamed JSON key writes the backing field directly, bypassing the @JsonIgnore on the setter. This vulnerability is fixed in 3.1.4.","aliases":["GHSA-9fxm-vc8v-hj55"],"modified":"2026-07-22T00:15:43.880343Z","published":"2026-06-23T20:48:52.730Z","related":["CGA-xx82-ppw2-x9rh"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-915"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54516.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54516.json"},{"type":"ADVISORY","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-9fxm-vc8v-hj55"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54516"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/commit/c3d56dd25d52319828147c5b9aeabf2d485c250a"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/commit/e88cb17006b6af4883b973058f0bb6486e5074af"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/pull/5967"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/pull/5968"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fasterxml/jackson-databind","events":[{"introduced":"220ee04ec724e5f5ea60fe5e638670e83e994765"},{"fixed":"dd72fa6c89b5cea6c4eba5a8604f248bbc5d93e5"},{"introduced":"d51183e4fa171235bcd31c63268c5ad1745afb8c"},{"fixed":"0105ba7c8c7d2aa59707c458eeb6c27e77779734"},{"fixed":"c3d56dd25d52319828147c5b9aeabf2d485c250a"},{"fixed":"e88cb17006b6af4883b973058f0bb6486e5074af"}],"database_specific":{"cpe":"cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.21.0"},{"fixed":"2.21.4"},{"introduced":"3.0.0"},{"fixed":"3.1.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["jackson-databind-3.1.3","jackson-databind-2.21.3","jackson-databind-3.1.2","jackson-databind-3.1.1","jackson-databind-2.21.2","jackson-databind-3.1.0","jackson-databind-2.21.1","jackson-databind-3.1.0-rc1","jackson-databind-2.21.0","jackson-databind-3.0.1","jackson-databind-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54516.json","vanir_signatures_modified":"2026-07-22T00:15:43Z","vanir_signatures":[{"target":{"file":"src/main/java/com/fasterxml/jackson/databind/introspect/POJOPropertiesCollector.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["160983967107924362856032577835046935536","66006577227634563902249830092701527053","181914976144073772348822697160405962495","279912769992190282774476092720641459464"]},"id":"CVE-2026-54516-21ecd0a2","signature_type":"Line","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/c3d56dd25d52319828147c5b9aeabf2d485c250a"},{"digest":{"line_hashes":["194776998429239810324610076395519724484","155487807618097576192415416781919487708","246072457094870626036358093939123154438","255878668903609712628559694115138834692","63738827068156596284166420683346681084","61753038763153761082360210743101911020","210479603992691962655367637633816870558","40863382586478508997329583861047449542","16901806537768055304550790128147888985","131287176306620799203782691484080956719","15377240238933967109629754292319175169","162802024910255013917168955623760009380"],"threshold":0.9},"id":"CVE-2026-54516-2d1a8dc9","signature_type":"Line","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/e88cb17006b6af4883b973058f0bb6486e5074af","target":{"file":"src/test/java/tools/jackson/databind/introspect/JsonPropertyRename5398Test.java"},"deprecated":false},{"digest":{"function_hash":"234760816525587816902148003027593983092","length":311},"id":"CVE-2026-54516-3369f89f","signature_type":"Function","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/e88cb17006b6af4883b973058f0bb6486e5074af","target":{"file":"src/test/java/tools/jackson/databind/introspect/JsonPropertyRename5398Test.java","function":"testStandardPropertyWithIgnoredSetter5398"},"deprecated":false},{"source":"https://github.com/fasterxml/jackson-databind/commit/e88cb17006b6af4883b973058f0bb6486e5074af","target":{"file":"src/main/java/tools/jackson/databind/introspect/POJOPropertiesCollector.java"},"deprecated":false,"digest":{"line_hashes":["160983967107924362856032577835046935536","66006577227634563902249830092701527053","181914976144073772348822697160405962495","279912769992190282774476092720641459464"],"threshold":0.9},"id":"CVE-2026-54516-3f552efb","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/c3d56dd25d52319828147c5b9aeabf2d485c250a","target":{"file":"src/test/java/com/fasterxml/jackson/databind/introspect/JsonPropertyRename5398Test.java","function":"testRenamedPropertyWithIgnoredSetter5398"},"deprecated":false,"digest":{"function_hash":"52184710190326488042796868400434277474","length":318},"id":"CVE-2026-54516-85f9142d","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"234760816525587816902148003027593983092","length":311},"id":"CVE-2026-54516-895ecdd1","signature_type":"Function","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/c3d56dd25d52319828147c5b9aeabf2d485c250a","target":{"file":"src/test/java/com/fasterxml/jackson/databind/introspect/JsonPropertyRename5398Test.java","function":"testStandardPropertyWithIgnoredSetter5398"}},{"deprecated":false,"digest":{"function_hash":"44767582397531675263937527384611442802","length":301},"id":"CVE-2026-54516-9e96d942","signature_type":"Function","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/e88cb17006b6af4883b973058f0bb6486e5074af","target":{"file":"src/test/java/tools/jackson/databind/introspect/JsonPropertyRename5398Test.java","function":"testRenamedPropertyWithIgnoredSetter5398"}},{"source":"https://github.com/fasterxml/jackson-databind/commit/e88cb17006b6af4883b973058f0bb6486e5074af","target":{"function":"_renameProperties","file":"src/main/java/tools/jackson/databind/introspect/POJOPropertiesCollector.java"},"deprecated":false,"digest":{"function_hash":"22577668028068857418819197970305537737","length":1038},"id":"CVE-2026-54516-af7c1777","signature_type":"Function","signature_version":"v1"},{"digest":{"function_hash":"22577668028068857418819197970305537737","length":1038},"id":"CVE-2026-54516-b1616623","signature_type":"Function","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/c3d56dd25d52319828147c5b9aeabf2d485c250a","target":{"function":"_renameProperties","file":"src/main/java/com/fasterxml/jackson/databind/introspect/POJOPropertiesCollector.java"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/c3d56dd25d52319828147c5b9aeabf2d485c250a","target":{"file":"src/test/java/com/fasterxml/jackson/databind/introspect/JsonPropertyRename5398Test.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["194776998429239810324610076395519724484","155487807618097576192415416781919487708","246072457094870626036358093939123154438","255878668903609712628559694115138834692","63738827068156596284166420683346681084","61753038763153761082360210743101911020","210479603992691962655367637633816870558","40863382586478508997329583861047449542","16901806537768055304550790128147888985","131287176306620799203782691484080956719","15377240238933967109629754292319175169","162802024910255013917168955623760009380"]},"id":"CVE-2026-54516-bdf268f4","signature_type":"Line"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}