CVE-2026-77310: Server-Side Request Forgery via DNS Resolution in jackson-databind
Vulnerability ID: CVE-2026-77310
CVSS Score: 5.3
Published: 2026-09-28
A Server-Side Request Forgery (SSRF) vulnerability exists in FasterXML jackson-databind before versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. The flaw occurs during the deserialization of java.net.InetAddress fields, where the library implicitly triggers eager DNS lookups. Unauthenticated remote attackers can exploit this behavior by passing arbitrary hostnames in JSON fields, forcing target servers to make outbound DNS lookup requests.
TL;DR
Jackson Databind's deserializer for java.net.InetAddress executes synchronous, blocking DNS resolution when processing hostnames, enabling remote, unauthenticated attackers to trigger outbound Server-Side Request Forgery (SSRF) via crafted JSON payloads.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-918 (Server-Side Request Forgery)
- Attack Vector: Network (Unauthenticated)
- CVSS v3.1 Score: 5.3 (Medium)
- Exploit Status: Proof-of-Concept Available
- CISA KEV Status: Not Listed
- Impact Category: Low Confidentiality (SSRF via DNS)
Affected Systems
- Applications utilizing FasterXML jackson-databind to deserialize untrusted JSON into models containing java.net.InetAddress properties.
-
jackson-databind (com.fasterxml.jackson.core): >= 2.0.0, < 2.18.9 (Fixed in:
2.18.9) -
jackson-databind (com.fasterxml.jackson.core): >= 2.19.0, < 2.21.5 (Fixed in:
2.21.5) -
jackson-databind (com.fasterxml.jackson.core): >= 2.22.0, < 2.22.1 (Fixed in:
2.22.1) -
jackson-databind (tools.jackson.core): >= 3.0.0, < 3.1.5 (Fixed in:
3.1.5) -
jackson-databind (tools.jackson.core): >= 3.2.0, < 3.2.1 (Fixed in:
3.2.1)
Code Analysis
Commit: 2fc7bd9
Prevent DNS lookup: only accept valid IP address literals for STD_INET_ADDRESS case.
Exploit Details
- GitHub Security Advisory: Vulnerability details and reference issues outlining how resolving domain configurations impacts local services.
Mitigation Strategies
- Upgrade jackson-databind to a patched release line.
- Implement network egress filtering to restrict unauthorized outbound DNS requests.
- Configure a custom deserializer to sanitize java.net.InetAddress inputs manually.
Remediation Steps:
- Identify all projects pulling com.fasterxml.jackson.core:jackson-databind or tools.jackson.core:jackson-databind.
- Update the project configuration (Maven pom.xml or Gradle build files) to force the patched versions.
- Rebuild the application and verify that passing hostnames to InetAddress fields yields a 400 Bad Request or parsing exception.
References
- FasterXML Jackson Databind Security Advisory GHSA-vvgp-rfg2-7rr6
- NVD Vulnerability Record
- GitHub Pull Request #6058
Read the full report for CVE-2026-77310 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)