Vulnerability Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955
- https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed215278
- https://github.com/FasterXML/jackson-databind/pull/5974
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf
FAQ
What is CVE-2026-59888?
CVE-2026-59888 is a vulnerability with a CVSS score of 6.5 (MEDIUM). jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStra...
How severe is CVE-2026-59888?
CVE-2026-59888 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-59888?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.