{"id":"CVE-2026-54518","summary":"jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind","details":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.","aliases":["GHSA-rcqc-6cw3-h962"],"modified":"2026-07-22T00:02:55.779559Z","published":"2026-06-23T21:02:07.539Z","related":["CGA-qm4f-rfvv-gqxq"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54518.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54518.json"},{"type":"ADVISORY","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rcqc-6cw3-h962"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54518"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/commit/721fa07ebbd4aab4a659a1a68940878315c3e341"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/commit/d633bc038f200c1397c07f1a2b46f58e72c91eea"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/pull/5971"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/pull/5973"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fasterxml/jackson-databind","events":[{"introduced":"220ee04ec724e5f5ea60fe5e638670e83e994765"},{"fixed":"dd72fa6c89b5cea6c4eba5a8604f248bbc5d93e5"},{"introduced":"d51183e4fa171235bcd31c63268c5ad1745afb8c"},{"fixed":"0105ba7c8c7d2aa59707c458eeb6c27e77779734"},{"fixed":"721fa07ebbd4aab4a659a1a68940878315c3e341"},{"fixed":"d633bc038f200c1397c07f1a2b46f58e72c91eea"}],"database_specific":{"extracted_events":[{"introduced":"2.21.0"},{"fixed":"2.21.4"},{"introduced":"3.0.0"},{"fixed":"3.1.4"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*"}}],"versions":["jackson-databind-3.1.3","jackson-databind-2.21.3","jackson-databind-3.1.2","jackson-databind-3.1.1","jackson-databind-2.21.2","jackson-databind-3.1.0","jackson-databind-2.21.1","jackson-databind-3.1.0-rc1","jackson-databind-2.21.0","jackson-databind-3.0.1","jackson-databind-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54518.json","vanir_signatures_modified":"2026-07-22T00:02:55Z","vanir_signatures":[{"id":"CVE-2026-54518-0418700e","signature_type":"Function","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/721fa07ebbd4aab4a659a1a68940878315c3e341","target":{"function":"processUnwrappedCreatorProperties","file":"src/main/java/com/fasterxml/jackson/databind/deser/impl/UnwrappedPropertyHandler.java"},"deprecated":false,"digest":{"function_hash":"270021673585925501920415031431070629194","length":293}},{"deprecated":false,"digest":{"line_hashes":["31939339860176856758054239954025204494","84720306002230945563420128231871178890","171962627351220145160681759565800433341","193293940089482145531496277924878454081","194277424942688234023298899431949778871"],"threshold":0.9},"id":"CVE-2026-54518-4077483c","signature_type":"Line","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/721fa07ebbd4aab4a659a1a68940878315c3e341","target":{"file":"src/main/java/com/fasterxml/jackson/databind/deser/impl/UnwrappedPropertyHandler.java"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/d633bc038f200c1397c07f1a2b46f58e72c91eea","target":{"file":"src/main/java/tools/jackson/databind/deser/impl/UnwrappedPropertyHandler.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["240833332574917885990290933343771068049","244563088736451193678807314552267982232","169252211704151078595712519892517570032","58531169091840653315785574132347039268","65431008233652785129151657035790131248"]},"id":"CVE-2026-54518-59471f20"},{"deprecated":false,"digest":{"function_hash":"70352276435819969745484968464390855134","length":238},"id":"CVE-2026-54518-c3872258","signature_type":"Function","signature_version":"v1","source":"https://github.com/fasterxml/jackson-databind/commit/d633bc038f200c1397c07f1a2b46f58e72c91eea","target":{"file":"src/main/java/tools/jackson/databind/deser/impl/UnwrappedPropertyHandler.java","function":"processUnwrappedCreatorProperties"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}