CVE-2026-91776

CVE-2026-91776 published: TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImp...

View full NVD advisory → ← Back to CVE watch