java-json-tools jackson-coreutils URL Validation JsonLoader.java JsonLoader.fromURL server-side request forgery
Published Sep 7, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.66%
Description
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
-
- Version 2.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Java-Json-Tools | Jackson-Coreutils | n/a |
|
No data.
No data.
Red Hat Fuse 7
jackson-coreutils
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jackson-coreutils
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk11-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk17-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk8-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 8
jackson-coreutils
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
jackson-coreutils
Fix deferred
Red Hat Single Sign-On 7
jackson-coreutils
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | jackson-coreutils | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jackson-coreutils | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jackson-coreutils | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jackson-coreutils | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | jackson-coreutils | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Moderate: A server-side request forgery (SSRF) vulnerability exists in `jackson-coreutils` when applications use `JsonLoader.fromURL` with untrusted input. This flaw allows a remote attacker to induce the server to make arbitrary requests, potentially leading to information disclosure or access to internal network resources. The impact is considered Moderate due to the need for an application to expose this functionality to untrusted input.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-86321 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2529509 Issue Tracking
- https://github.com/java-json-tools/jackson-coreutils/ product
- https://github.com/java-json-tools/jackson-coreutils/issues/64 exploitissue-tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-86321
- https://vuldb.com/cve/CVE-2026-86321 third-party-advisory
- https://vuldb.com/submit/908323 third-party-advisory
- https://vuldb.com/vuln/399511 vdb-entrytechnical-description
- https://vuldb.com/vuln/399511/cti signaturepermissions-required
- https://www.cve.org/CVERecord?id=CVE-2026-86321
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-86321 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2529509 | Issue Tracking | |
| https://github.com/java-json-tools/jackson-coreutils/ | product | |
| https://github.com/java-json-tools/jackson-coreutils/issues/64 | exploitissue-tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-86321 | ||
| https://vuldb.com/cve/CVE-2026-86321 | third-party-advisory | |
| https://vuldb.com/submit/908323 | third-party-advisory | |
| https://vuldb.com/vuln/399511 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/399511/cti | signaturepermissions-required | |
| https://www.cve.org/CVERecord?id=CVE-2026-86321 |
Change history (0)
No recorded changes yet.