CVE-2026-59888
Last modified
CVE-2026-59888 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FasterXML | jackson-databind | >= 2.15.0, < 2.18.8; >= 2.19.0, < 2.21.4; >= 3.0.0, < 3.1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-59888?
How severe is CVE-2026-59888?
How do I fix CVE-2026-59888?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59882guzzlehttp/psr7 is a PSR-7 HTTP message library implementati…6.5
- CVE-2026-59883Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, Co…6.1
- CVE-2026-59884pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4…7.5
- CVE-2026-59885pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4…7.5
- CVE-2026-59886pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4…7.5
- CVE-2026-59887linkify-it is a links recognition library with full Unicode …7.5
- CVE-2026-59889jackson-databind contains the general-purpose data-binding f…6.5
- CVE-2026-5989A flaw has been found in Tenda F451 1.0.0.7. Affected is the…8.8
- CVE-2026-59890setuptools is a package that allows users to download, build…6.1
- CVE-2026-59891sigstore-js provides JavaScript libraries for interacting wi…9.6
- CVE-2026-59892OpenTelemetry JavaScript is the OpenTelemetry JavaScript cli…7.5
- CVE-2026-59893sqlparse is a non-validating SQL parser module for Python. P…7.5
Are you affected by CVE-2026-59888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
