CVE-2026-19032: jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution
A java.nio.file.Path field bound from untrusted JSON reaches JDKFromStringDeserializer.NioPathHelper.deserialize. The attacker string flows through new URI(value) → Path.of(uri), then on FileSystemNotFoundException into a ServiceLoader<FileSystemProvider> enumeration that calls provider.getPath(uri) on the first scheme-matching provider. No scheme is rejected, so untrusted JSON can drive an arbitrary registered provider under the default JsonMapper.builder().build().
Impact is bounded. The JDK built-in providers (file, jar/zipfs) do no network I/O and do not mount, so the path is inert without a side-effecting third-party provider. Binding Path from untrusted input is already an anti-pattern.
References
- github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551
- github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166
- github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d
- github.com/FasterXML/jackson-databind/pull/6129
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2
- github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf
- github.com/advisories/GHSA-wjgm-6hv5-3cvf
- nvd.nist.gov/vuln/detail/CVE-2026-19032
Code Behaviors & Features
Detect and mitigate CVE-2026-19032 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →