GHSA-3pjw-73gf-8qr5

    Dashboard / Vulnerabilities / GHSA-3pjw-73gf-8qr5

    GHSA-3pjw-73gf-8qr5

    Published: 21 Jul 2026Last Modified: 10 Sept 2026

    Summary: jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

    Details: ## Summary For Java Records, `POJOPropertiesCollector._removeUnwantedIgnorals()` records a `@JsonIgnore`-annotated component under its original implicit name before `_renameUsing()` applies the `PropertyNamingStrategy`. After the rename, `_ignoredPropertyNames` still holds only the pre-rename name, so `_ignorableProps` is built from the stale key. The renamed JSON key passes `IgnorePropertiesUtil.shouldIgnore()` and is assigned to the Record's constructor parameter, defeating the `@JsonIgnore`. ## Impact A Record using a naming strategy that relies on `@JsonIgnore` to keep an internal/privileged component out of deserialization can have that component set from the wire via its renamed key (e.g. a role/flag controlled by an untrusted client). ## Affected / Patched (verified via `git tag --contains`) - 2.15-2.18 line: `>= 2.15.0, < 2.18.8` -> fixed in **2.18.8** (backport `c7c6783`) - 2.19-2.21 line: `>= 2.19.0, < 2.21.4` -> fixed in **2.21.4** - 3.x line: `>= 3.0.0, < 3.1.4` -> fixed in **3.1.4** (#5974, `baa2cdf`) ## Severity / CWE Maintainer: minor. Reporter: Moderate. CWE-915; related CWE-345. ## Credits Omkhar Arasaratnam (@omkhar) - finder.

    Affected packages

    Package

    Name: com.fasterxml.jackson.core:jackson-databind

    Purl: pkg:maven/com.fasterxml.jackson.core/jackson-databind

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.15.0
    Fixed -2.18.8

    Affected versions

    2.15.0
    2.15.1
    2.15.2
    2.15.3
    2.15.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High