CVE-2026-83557 is a polymorphic deserialization vulnerability in Jackson Databind's DefaultBaseTypeLimitingValidator. The validator is applied automatically when @JsonTypeInfo is used without a custom PolymorphicTypeValidator. It rejects a fixed set of unsafe base types, but omits java.lang.Comparable; its isSafeSubType method unconditionally accepts subtypes of base types outside that set. Applications using Comparable as an annotated polymorphic base type can consequently accept attacker-supplied type identifiers for essentially any Comparable implementation. This enables attacker-controlled object instantiation, demonstrated by constructing java.io.File with an attacker-selected path. Further harmful behavior depends on how the application subsequently uses the object. Global Default Typing through activateDefaultTyping is unaffected because it requires an explicit validator.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A medium-severity polymorphic deserialization validation flaw in Jackson Databind. DefaultBaseTypeLimitingValidator omits java.lang.Comparable from its unsafe base-type list, allowing attacker-controlled object instantiation when Comparable is used as an @JsonTypeInfo base type without a custom validator. A demonstrated case constructs java.io.File with an attacker-chosen path; subsequent path-sensitive application operations could create path-traversal-related risk. The content identifies no Comparable implementation enabling code execution through deserialization alone. Global Default Typing through activateDefaultTyping is unaffected. Affected Jackson 2.x ranges are 2.11.0–before 2.18.10, 2.19.0–before 2.21.6, and 2.22.0–before 2.22.2; affected Jackson 3.x ranges are 3.0.0–before 3.1.6 and 3.2.0–before 3.2.2. Fixed releases are 2.18.10, 2.21.6, 2.22.2, 3.1.6, and 3.2.2. The reported CVSS v3 base score is 5.6.
A medium-severity Jackson Databind polymorphic deserialization flaw that can allow attacker-controlled object instantiation when an application uses @JsonTypeInfo with Comparable as the base type and no custom validator. Demonstrated impact includes arbitrary-path java.io.File construction; the notice states that no Comparable implementation has been identified that enables remote code execution through deserialization alone.
An incomplete polymorphic-type-validation denylist in Jackson Databind. Applications using bare @JsonTypeInfo with Comparable as the declared base type and no restrictive custom PolymorphicTypeValidator may accept attacker-selected Comparable implementations, enabling controlled object instantiation such as java.io.File with an arbitrary path.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.