DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-19032: CVE-2026-19032: Insecure Deserialization and Class Loading via java.nio.file.Path Resolution in FasterXML jackson-databind

CVE-2026-19032: Insecure Deserialization and Class Loading via java.nio.file.Path Resolution in FasterXML jackson-databind

Vulnerability ID: CVE-2026-19032
CVSS Score: 5.3
Published: 2026-09-28

An insecure deserialization vulnerability exists in FasterXML jackson-databind due to improper validation of URI schemes when resolving java.nio.file.Path properties. When binding untrusted JSON input to a Path field, the deserializer resolves attacker-supplied URIs without restriction. If the scheme is unrecognized by the default filesystem, the application falls back to querying registered SPI FileSystemProvider instances, causing class loading and potential side effects in environments with custom providers.

TL;DR

Unauthenticated remote attackers can trigger unsafe Java ServiceLoader class loading and execute arbitrary FileSystemProvider resolution logic by supplying crafted URIs in JSON properties deserialized as java.nio.file.Path fields.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-470, CWE-610
  • Attack Vector: Network
  • CVSS v3.1 Score: 5.3 (Medium)
  • EPSS Score: 0.00529 (0.529%)
  • Exploit Status: poc
  • CISA KEV Status: Not Listed
  • Impact: Low (Unsafe Class Loading / Resource Querying / SSRF)

Affected Systems

  • Applications deploying com.fasterxml.jackson.core:jackson-databind between 2.8.0 and 2.18.9
  • Applications deploying com.fasterxml.jackson.core:jackson-databind between 2.19.0 and 2.21.5
  • Applications deploying com.fasterxml.jackson.core:jackson-databind between 2.22.0 and 2.22.1
  • Applications deploying tools.jackson.core:jackson-databind between 3.0.0 and 3.1.5
  • Applications deploying tools.jackson.core:jackson-databind between 3.2.0 and 3.2.1
  • jackson-databind (2.x): >= 2.8.0, < 2.18.10 (Fixed in: 2.18.10)
  • jackson-databind (2.x): >= 2.19.0, < 2.21.6 (Fixed in: 2.21.6)
  • jackson-databind (2.x): >= 2.22.0, < 2.22.2 (Fixed in: 2.22.2)
  • jackson-databind (3.x): >= 3.0.0, < 3.1.6 (Fixed in: 3.1.6)
  • jackson-databind (3.x): >= 3.2.0, < 3.2.2 (Fixed in: 3.2.2)

Code Analysis

Commit: cc6756b

Fix Path deserialization vulnerability (CVE-2026-19032) in 2.x branch by adding URI scheme validation and restricting to allowed schemes.

Commit: d94bb63

Merge scheme validation security fix into 3.1 branch.

Commit: ce26eda

Merge scheme validation security fix into 3.2 branch.

Mitigation Strategies

  • Upgrade jackson-databind to a patched version immediately.
  • Avoid binding untrusted JSON parameters directly to java.nio.file.Path fields.
  • Explicitly configure custom allowed URI schemes on a manually instantiated NioPathDeserializer if multi-filesystem support is mandatory.

Remediation Steps:

  1. Identify all internal services and third-party applications importing com.fasterxml.jackson.core:jackson-databind or tools.jackson.core:jackson-databind.
  2. Update project dependencies (Maven pom.xml or Gradle build files) to use 2.18.10+, 2.21.6+, 2.22.2+, 3.1.6+, or 3.2.2+.
  3. Implement integration tests to verify that deserializing non-file URI schemes to Path fields now results in a WeirdStringValueException.

References


Read the full report for CVE-2026-19032 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)