A AegiFlow
MEDIUMCVSS 6.5EPSS 0.2%

CVE-2026-59888

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

Published
2026-07-21
Modified
2026-07-21
EPSS percentile
16%
Aliases
GHSA-3pjw-73gf-8qr5
Sources
github-advisory

Summary

## Summary For Java Records, `POJOPropertiesCollector._removeUnwantedIgnorals()` records a `@JsonIgnore`-annotated component under its original implicit name before `_renameUsing()` applies the `PropertyNamingStrategy`. After the rename, `_ignoredPropertyNames` still holds only the pre-rename name, so `_ignorableProps` is built from the stale key. The renamed JSON key passes `IgnorePropertiesUtil.shouldIgnore()` and is assigned to the Record's constructor parameter, defeating the `@JsonIgnore`. ## Impact A Record using a naming strategy that relies on `@JsonIgnore` to keep an internal/privileged component out of deserialization can have that component set from the wire via its renamed key (e.g. a role/flag controlled by an untrusted client). ## Affected / Patched (verified via `git tag --contains`) - 2.15-2.18 line: `>= 2.15.0, fixed in **2.18.8** (backport `c7c6783`) - 2.19-2.21 line: `>= 2.19.0, fixed in **2.21.4** - 3.x line: `>= 3.0.0, fixed in **3.1.4** (#5974, `baa2cdf`) ## Severity / CWE Maintainer: minor. Reporter: Moderate. CWE-915; related CWE-345. ## Credits Omkhar Arasaratnam (@omkhar) - finder.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavencom.fasterxml.jackson.core:jackson-databind2.18.8, 2.21.4
Maventools.jackson.core:jackson-databind3.1.4

Remediation: Upgrade to 2.18.8 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.