Back

MEDIUM

java-json-tools jackson-coreutils URL Validation JsonLoader.java JsonLoader.fromURL server-side request forgery

Published Sep 7, 2026

Description

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

Remediation

Red Hat statement

Moderate: A server-side request forgery (SSRF) vulnerability exists in `jackson-coreutils` when applications use `JsonLoader.fromURL` with untrusted input. This flaw allows a remote attacker to induce the server to make arbitrary requests, potentially leading to information disclosure or access to internal network resources. The impact is considered Moderate due to the need for an application to expose this functionality to untrusted input.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 7, 2026
Updated Sep 8, 2026
Reserved Sep 7, 2026
CISA Vulnrichment
Updated Sep 8, 2026
NVD
Status Deferred
Modified Sep 8, 2026
Red Hat
Severity Moderate
Public date Sep 7, 2026