Maven · com.fasterxml.jackson.core:jackson-databind
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect.
An attacker controlling JSON deserialized into an InetSocketAddress-bearing type can force outbound DNS lookups for attacker-chosen hostnames at deserialization time (SSRF / DNS-based out-of-band interaction / internal-resolver probing), purely from binding.
git tag --contains on 1f5a103)>= 2.18.0, < 2.18.8 -> fixed in 2.18.8>= 2.19.0, < 2.21.4 -> fixed in 2.21.4>= 3.0.0, < 3.1.4 -> fixed in 3.1.4Maintainer: minor. Reporter: LOW. CWE-918 (SSRF).
FasterXML/jackson-databind#5951 ("Improve InetSocketAddress deserialization"). Released 2026-06-04 in 2.18.8 / 2.21.4 / 3.1.4.
Omkhar Arasaratnam (@omkhar) - finder.
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.