CVE-2026-83557 | FasterXML jackson-databind up to 3.2.1 DefaultBaseTypeLimitingValidator isSafeSubType deserialization

SecurityVulns

A vulnerability classified as critical was found in FasterXML jackson-databind up to 2.18.9/2.21.5/2.22.1/3.1.5/3.2.1. This issue affects the function isSafeSubType of the component DefaultBaseTypeLimitingValidator. The manipulation results in deserialization.

This vulnerability was named CVE-2026-83557. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More