{"id":"CVE-2026-54517","summary":"jackson-databind: @JsonView bypass for setterless creator properties","details":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch performed no prop.visibleInView(activeView) check. A change making SetterlessProperty.isMerging() return true routed setterless Collection/Map properties through this unguarded path, so a setterless collection annotated with a restricted @JsonView is populated from attacker JSON even when the active view excludes it. This vulnerability is fixed in 2.21.4 and 3.1.4.","aliases":["GHSA-5hh8-q8hv-fr38"],"modified":"2026-07-21T23:22:22.823702Z","published":"2026-06-23T20:47:22.977Z","related":["CGA-rj4w-hw9m-ffxf"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54517.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54517.json"},{"type":"ADVISORY","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5hh8-q8hv-fr38"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54517"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/commit/5bf23edb4221f7dd2ec8e71ff6d26c61640f261d"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/commit/94c5d215b3af1505098c686405d9641f041a9962"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/pull/5969"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/pull/5970"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fasterxml/jackson-databind","events":[{"introduced":"220ee04ec724e5f5ea60fe5e638670e83e994765"},{"fixed":"dd72fa6c89b5cea6c4eba5a8604f248bbc5d93e5"},{"introduced":"d51183e4fa171235bcd31c63268c5ad1745afb8c"},{"fixed":"0105ba7c8c7d2aa59707c458eeb6c27e77779734"},{"fixed":"5bf23edb4221f7dd2ec8e71ff6d26c61640f261d"},{"fixed":"94c5d215b3af1505098c686405d9641f041a9962"}],"database_specific":{"cpe":"cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.21.0"},{"fixed":"2.21.4"},{"introduced":"3.0.0"},{"fixed":"3.1.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["jackson-databind-3.1.3","jackson-databind-2.21.3","jackson-databind-3.1.2","jackson-databind-3.1.1","jackson-databind-2.21.2","jackson-databind-3.1.0","jackson-databind-2.21.1","jackson-databind-3.1.0-rc1","jackson-databind-2.21.0","jackson-databind-3.0.1","jackson-databind-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54517.json","vanir_signatures_modified":"2026-07-21T23:22:22Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["339904831188168028482291926813481431667","32255228255115019491344521766863799083","156270402583600399801406229816753451427"],"threshold":0.9},"id":"CVE-2026-54517-086263b8","signature_type":"Line","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/94c5d215b3af1505098c686405d9641f041a9962","target":{"file":"src/main/java/com/fasterxml/jackson/databind/deser/BeanDeserializer.java"}},{"signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/5bf23edb4221f7dd2ec8e71ff6d26c61640f261d","target":{"file":"src/main/java/tools/jackson/databind/deser/bean/BeanDeserializer.java"},"deprecated":false,"digest":{"line_hashes":["230518058737508378500648846864177612889","286754655310115899111298746967388199331","106873667088819741697159525463437569362","10610002977937522803712808018737834611"],"threshold":0.9},"id":"CVE-2026-54517-aed972b4","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"227106089903873680173210561414482762890","length":3147},"id":"CVE-2026-54517-bee47c72","signature_type":"Function","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/5bf23edb4221f7dd2ec8e71ff6d26c61640f261d","target":{"file":"src/main/java/tools/jackson/databind/deser/bean/BeanDeserializer.java","function":"_deserializeUsingPropertyBased"}},{"id":"CVE-2026-54517-c1486e81","signature_type":"Function","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/94c5d215b3af1505098c686405d9641f041a9962","target":{"file":"src/main/java/com/fasterxml/jackson/databind/deser/BeanDeserializer.java","function":"_deserializeUsingPropertyBased"},"deprecated":false,"digest":{"function_hash":"121069725795102287829327556081565801305","length":3199}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}