CVE-2026-77310: jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization
CVE-2026-54514 (GHSA-hgj6-7826-r7m5) fixed an eager-DNS-resolution / SSRF issue in jackson-databind’s deserialization of java.net.InetSocketAddress by switching to InetSocketAddress.createUnresolved(...) (PR #5951, commit 1f5a1037, released in 2.18.8 / 2.21.4 / 3.1.4). That fix did not cover the sibling java.net.InetAddress branch in the very same FromStringDeserializer.Std._deserialize() switch statement, which still calls InetAddress.getByName(value) and therefore performs an eager forward DNS lookup on attacker-controlled input at deserialization time. The fix is incomplete: the same vulnerability class remains reachable through InetAddress.
References
- github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd
- github.com/FasterXML/jackson-databind/pull/6058
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.9
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.5
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.1
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.5
- github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.1
- github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6
- github.com/advisories/GHSA-vvgp-rfg2-7rr6
- nvd.nist.gov/vuln/detail/CVE-2026-77310
Code Behaviors & Features
Detect and mitigate CVE-2026-77310 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →