UBUNTU-CVE-2026-54514
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 23 Jun 2026, 21:17
Last modified:25 Jun 2026, 17:17
Vulnerability Summary
Overall Risk (default)
low
21/100 CVSS Score
5.3 MEDIUM
3.1 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
23 Jun 2026, 21:17
Published
Vulnerability first disclosed
25 Jun 2026, 17:17
Last Modified
Vulnerability information updated
Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Systems
- ubuntu•jackson-databind
all | all | all | all | all | all | all
References (5)
- https://ubuntu.com/security/CVE-2026-54514
- https://www.cve.org/CVERecord?id=CVE-2026-54514
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5
- https://github.com/FasterXML/jackson-databind/pull/5951
- https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4