jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
Moderate severity
GitHub Reviewed
Published
Jul 10, 2026
in
FasterXML/jackson-databind
•
Updated Jul 21, 2026
Description
Published by the National Vulnerability Database
Jul 14, 2026
Published to the GitHub Advisory Database
Jul 21, 2026
Reviewed
Jul 21, 2026
Last updated
Jul 21, 2026
Summary
For Java Records,
POJOPropertiesCollector._removeUnwantedIgnorals()records a@JsonIgnore-annotated component under its original implicit name before_renameUsing()applies thePropertyNamingStrategy. After the rename,_ignoredPropertyNamesstill holds only the pre-rename name, so_ignorablePropsis built from the stale key. The renamed JSON key passesIgnorePropertiesUtil.shouldIgnore()and is assigned to the Record's constructor parameter, defeating the@JsonIgnore.Impact
A Record using a naming strategy that relies on
@JsonIgnoreto keep an internal/privileged component out of deserialization can have that component set from the wire via its renamed key (e.g. a role/flag controlled by an untrusted client).Affected / Patched (verified via
git tag --contains)>= 2.15.0, < 2.18.8-> fixed in 2.18.8 (backportc7c6783)>= 2.19.0, < 2.21.4-> fixed in 2.21.4>= 3.0.0, < 3.1.4-> fixed in 3.1.4 (#5974,baa2cdf)Severity / CWE
Maintainer: minor. Reporter: Moderate. CWE-915; related CWE-345.
Credits
Omkhar Arasaratnam (@omkhar) - finder.
References