UBUNTU-CVE-2026-91776

Source
https://ubuntu.com/security/CVE-2026-91776
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91776.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-91776
Upstream
Published
2026-09-23T03:17:00Z
Modified
2026-09-24T02:02:54Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID.

References

Affected packages

Ubuntu:18.04:LTS
jackson-databind

Package

Name
jackson-databind
Purl
pkg:deb/ubuntu/jackson-databind?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.8.6-1
2.9.1-1
2.9.4-1
2.9.5-1
2.9.8-1~18.04

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "libjackson2-databind-java",
            "binary_version":  "2.9.8-1~18.04"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91776.json"
Ubuntu:20.04:LTS
jackson-databind

Package

Name
jackson-databind
Purl
pkg:deb/ubuntu/jackson-databind?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.9.9.3-1
2.10.0-2
2.10.1-1
2.10.2-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "libjackson2-databind-java",
            "binary_version":  "2.10.2-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91776.json"
Ubuntu:22.04:LTS
jackson-databind

Package

Name
jackson-databind
Purl
pkg:deb/ubuntu/jackson-databind?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.12.1-1
2.12.5-1
2.13.0-1
2.13.0-2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "libjackson2-databind-java",
            "binary_version":  "2.13.0-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91776.json"
Ubuntu:24.04:LTS
jackson-databind

Package

Name
jackson-databind
Purl
pkg:deb/ubuntu/jackson-databind?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.14.0-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "libjackson2-databind-java",
            "binary_version":  "2.14.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91776.json"
Ubuntu:26.04:LTS
jackson-databind

Package

Name
jackson-databind
Purl
pkg:deb/ubuntu/jackson-databind?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.14.0+ds-1
2.14.0+ds-1build1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "libjackson2-databind-java",
            "binary_version":  "2.14.0+ds-1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91776.json"
Ubuntu:Pro:14.04:LTS
jackson-databind

Package

Name
jackson-databind
Purl
pkg:deb/ubuntu/jackson-databind?arch=source&distro=esm-infra-legacy%2Ftrusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.2-1
2.2.2-1ubuntu0.1~esm1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "libjackson2-databind-java",
            "binary_version":  "2.2.2-1ubuntu0.1~esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91776.json"
Ubuntu:Pro:16.04:LTS
jackson-databind

Package

Name
jackson-databind
Purl
pkg:deb/ubuntu/jackson-databind?arch=source&distro=esm-apps%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.4.2-2
2.4.2-3
2.4.2-3ubuntu0.1~esm1
2.4.2-3ubuntu0.1~esm2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "libjackson2-databind-java",
            "binary_version":  "2.4.2-3ubuntu0.1~esm2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91776.json"