CVE-2026-77310 - jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress deserialization (Incomplete fix for CVE-2026-54514)
Brief
CVE ID : CVE-2026-77310
Published : Aug. 24, 2026, 8:17 p. m.
- 54 minutes ago
Description : jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.
- 9, 2.
- 5, 2.
- 1, 3.
- 5, and 3.
- 1 on their respective release lines, the java. net. InetAddress branch of FromStringDeserializer. Std. _deserialize() calls InetAddress.
getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.
- 9, 2.
- 5, 2.
- 1, 3.
- 5, and 3.
- 1.
Severity: 5.3
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
