Back

MEDIUM

jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields

Published Jun 23, 2026

Description

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the getter and @JsonIgnore on the setter to be renamed rather than dropped. With MapperFeature.INFER_PROPERTY_MUTATORS enabled (default), the private backing field is retained; during deserialization BeanDeserializerFactory.addBeanProps() sees hasField()==true, builds a FieldProperty, and makes the backing field writable. An attacker supplying the renamed JSON key writes the backing field directly, bypassing the @JsonIgnore on the setter. This vulnerability is fixed in 3.1.4.

Affected products

Remediation

Red Hat statement

Moderate: This flaw in jackson-databind allows for property tampering and mass assignment in Red Hat products. When `MapperFeature.INFER_PROPERTY_MUTATORS` is enabled by default, an attacker can bypass `@JsonIgnore` annotations on setters by supplying a renamed JSON key, directly writing to private backing fields and circumventing intended security controls.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jun 23, 2026
Updated Jun 24, 2026
Reserved Jun 15, 2026

CISA Vulnrichment

Updated Jun 24, 2026

NVD

Status Analyzed
Modified Jun 27, 2026

Red Hat

Severity Moderate
Public date Jun 23, 2026
Bugzilla 2491996

ENISA EUVD

Assigner GitHub_M
Published Jun 23, 2026
Updated Jun 24, 2026