CVE-2026-19032 | FasterXML jackson-databind up to 3.2.1 Deserializer input validation

SecurityVulns

A vulnerability, which was classified as problematic, has been found in FasterXML jackson-databind up to 2.18.9/2.21.5/2.22.1/3.1.5/3.2.1. Affected is the function JDKFromStringDeserializer.NioPathHelper.deserialize of the component Deserializer. The manipulation leads to improper input validation.

This vulnerability is uniquely identified as CVE-2026-19032. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More