cbcvebase.
CVE-2026-19032
published 2026-09-01

CVE-2026-19032: jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In…

PriorityP434medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.46%
38.8th percentile
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version.

Affected

80 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platform-24de-minimal-rhel8
ansible-automation-platform-24de-minimal-rhel9
ansible-automation-platform-25de-minimal-rhel8
ansible-automation-platform-25de-minimal-rhel9
ansible-automation-platform-26de-minimal-rhel9
ansible-automation-platform-27de-minimal-rhel9
ansible-automation-platform-27de-supported-rhel9
candlepinprojectcandlepin
debianceph
debiandogtag-pki
debianpuppetserver
devspacesmulticluster-redirector-rhel9
devspacesopenvsx-rhel9
devspacespluginregistry-rhel9
devspacesserver-rhel9
exploit-intelligenceagent-client-rhel9
fasterxmljackson-databind
fasterxmljackson-databind>= 2.19.0 < 2.21.62.21.6
fasterxmljackson-databind>= 2.22.0 < 2.22.22.22.2
fasterxmljackson-databind>= 2.8.0 < 2.18.102.18.10
fasterxmljackson-databind>= 3.0.0 < 3.1.63.1.6
fasterxmljackson-databind>= 3.2.0 < 3.2.23.2.2
jboss-eap-7eap74-els-openjdk11-openshift-rhel8
jboss-eap-7eap74-els-openjdk17-openshift-rhel8
jboss-eap-7eap74-els-openjdk8-openshift-rhel8

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.