{"id":"CVE-2026-59888","title":"com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records (CVE…","summary":"A flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cvssSource":"vendor","cwe":"CWE-915","vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["openshift_serverless","ai_inference_server","build_of_apicurio_registry 3","build_of_quarkus","enterprise_linux_ai_rhel_ai 3","jboss_enterprise_application_platform 8","jboss_enterprise_application_platform_expansion_pack","jboss_web_server 7","openshift_ai_rhoai","openshift_dev_spaces","streams_for_apache_kafka 2","streams_for_apache_kafka 3","ai_inference_server 3.3","amq_broker 7.13.6","lightspeed_formerly_insights_for_runtimes 1.0","openshift_dev_spaces 3.30"],"patched":["ai_inference_server 3.3","amq_broker 7.13.6","lightspeed_formerly_insights_for_runtimes 1.0","openshift_dev_spaces 3.30"],"published":"2026-07-14","updated":"2026-09-21","sourceUpdated":"2026-09-21T11:31:03+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59888.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59888.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59888"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500096"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59888"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59888"},{"url":"https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4"},{"url":"https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"},{"url":"https://github.com/FasterXML/jackson-databind/pull/5974"},{"url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"},{"url":"https://access.redhat.com/errata/RHSA-2026:68699"},{"url":"https://access.redhat.com/errata/RHSA-2026:66545"},{"url":"https://access.redhat.com/errata/RHSA-2026:54440"},{"url":"https://access.redhat.com/errata/RHSA-2026:62260"},{"url":"https://github.com/advisories/GHSA-3pjw-73gf-8qr5"}],"tags":["csaf","vex","red-hat","ghsa","maven"],"epss":0.00309,"epssPercentile":0.23904,"aliases":["GHSA-3pjw-73gf-8qr5"],"ecosystem":"maven","ingestedAt":"2026-07-21T19:53:40.045Z","slug":"CVE-2026-59888","body":"## Overview\n\nA flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter, even if it was intended to be ignored. Consequently, an untrusted client could set internal or privileged components from external input, potentially leading to unauthorized modification or disclosure of sensitive data.\n\n## Vendor advisories\n\n- **RHSA-2026:68699** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68699)\n- **RHSA-2026:66545** · Red Hat · fixed in: Red Hat AMQ Broker 7.13.6 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66545)\n- **RHSA-2026:54440** · Red Hat · fixed in: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54440)\n- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)\n- **Red Hat VEX** · Moderate · affected: OpenShift Serverless, Red Hat AI Inference Server, Red Hat build of Apicurio Registry 3, Red Hat build of Quarkus, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat JBoss Enterprise Application Platform 8, … · no fix planned: Red Hat AI Inference Server, Red Hat build of Apicurio Registry 3, Red Hat build of Quarkus, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59888.json)\n\n**com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records** — rated Moderate by Red Hat. Released 2026-07-14, updated 2026-09-21.\n\nAffected:\n\n- OpenShift Serverless\n- Red Hat AI Inference Server\n- Red Hat build of Apicurio Registry 3\n- Red Hat build of Quarkus\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat JBoss Enterprise Application Platform 8\n- Red Hat JBoss Enterprise Application Platform Expansion Pack\n- Red Hat JBoss Web Server 7\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Dev Spaces\n- streams for Apache Kafka 2\n- streams for Apache Kafka 3\n\nFixed:\n\n- Red Hat AI Inference Server 3.3\n- Red Hat AMQ Broker 7.13.6\n- Red Hat Lightspeed (formerly Insights) for Runtimes 1.0\n- Red Hat OpenShift Dev Spaces 3.30\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat build of Apicurio Registry 3\n- Red Hat build of Quarkus\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat JBoss Enterprise Application Platform 8\n- Red Hat JBoss Enterprise Application Platform Expansion Pack\n- Red Hat OpenShift AI (RHOAI)\n- streams for Apache Kafka 2\n- streams for Apache Kafka 3\n- OpenShift Serverless\n- Red Hat JBoss Web Server 7\n- Red Hat OpenShift Dev Spaces\n\nNot affected:\n\n- Red Hat OpenShift Dev Spaces 3.30\n- Cryostat 4\n- OpenShift Developer Tools and Services\n- Red Hat AMQ Clients\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apache Camel 4 for Quarkus 3\n- Red Hat build of Apache Camel for Spring Boot 4\n- Red Hat build of Debezium 3\n- Red Hat Build of Keycloak\n\n## Remediation\n\nFor more information visit https://access.redhat.com/errata/RHSA-2026:68699 https://access.redhat.com/errata/RHSA-2026:68699\nBefore applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.\n\nThe References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66545\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54440\n\n## Package advisory (CVE-2026-59888)\n\nAffected packages:\n\n- `com.fasterxml.jackson.core:jackson-databind >= 2.15.0, < 2.18.8`\n- `com.fasterxml.jackson.core:jackson-databind >= 2.19.0, < 2.21.4`\n- `tools.jackson.core:jackson-databind >= 3.0.0, < 3.1.4`\n\nPatched in:\n\n- `com.fasterxml.jackson.core:jackson-databind 2.18.8`\n- `com.fasterxml.jackson.core:jackson-databind 2.21.4`\n- `tools.jackson.core:jackson-databind 3.1.4`\n\nSource: https://github.com/advisories/GHSA-3pjw-73gf-8qr5","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}