已关闭
CVE-2026-19032 #1392
opengauss_bot创建于  9月1日关闭于  23 天前
opengauss_bot
opengauss_bot成员
9月1日 创建

一、漏洞信息
漏洞编号:CVE-2026-19032
漏洞归属组件:jackson-databind, https://gitcode.com/opengauss/openGauss-workbench
漏洞归属的版本:2.13.4,2.21.5,UNKNOWN
CVSS分值:
 BaseScore: N/A None
 Vector: N/A

漏洞简述:
jackson-databind_x27;s deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version.

漏洞公开时间:2026-09-01 12:18:00
漏洞创建时间:2026-09-01 13:40:10
漏洞详情参考链接:
https://nvd.nist.gov/vuln/detail/CVE-2026-19032
漏洞补丁信息:

二、漏洞分析结构反馈
影响性分析说明:
jackson-databind 在反序列化 java.nio.file.Path 时,未限制攻击者可控 URI 的 scheme;经 Path.of / FileSystemProvider 可能触发任意已注册 provider 的类加载(CWE-502)。仅有 JDK 内置 file/jar 时影响有限;若 classpath 存在有副作用的第三方 FileSystemProvider 则风险升高。受影响区间含 2.19.0~<2.21.6 等;修复线 2.18.10 / 2.21.6 / 2.22.2(见 CVE-2026-19032)。

与本仓库 master 的对应关系:
根 pom.xml 中 jackson.version 为 2.21.5(< 2.21.6),多模块经 ${jackson.version} 引入 jackson-databind,属于受影响区间。

漏洞评分(openGauss评分):
 BaseScore: 5.3
 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

受影响版本排查(受影响/不受影响):
1.master:受影响

likedislike
opengauss_botopengauss_bot成员
9月1日 添加了label:CVE/UNFIXED
opengauss_bot
opengauss_bot成员
9月1日 评论:

issue处理注意事项:
1. 当前issue受影响的分支提交pr时, 须在pr描述中填写当前issue编号进行关联, 否则无法关闭当前issue;
2. 模板内容需要填写完整, 无论是受影响或者不受影响都需要填写完整内容,未引入的分支不需要填写, 否则无法关闭当前issue;
3. 以下为模板中需要填写完整的内容, 请复制到评论区回复, 注: 内容的标题名称(影响性分析说明, opengauss评分, 受影响版本排查(受影响/不受影响))不能省略,省略后cve-manager将无法正常解析填写内容.


影响性分析说明:

漏洞评分(opengauss评分):
BaseScore: x.x(浮点格式)
Vector:

受影响版本排查(受影响/不受影响):
1.master:


likedislike
opengauss_bot
opengauss_bot成员
9月1日 评论:

This issue requires an assignee. Since you haven't specified one, we've assigned TestManager as the default assignee for this issue.

likedislike
opengauss_botopengauss_bot成员
9月1日 将 TestManager 设为负责人
opengauss_botopengauss_bot成员
9月1日 添加了label:sig/Tools
opengauss_bot
opengauss_bot成员
9月1日 评论:

Welcome To openGauss Community

Hey @opengauss_bot , thanks for your contribution to the community.

Bot Usage Manual

I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands. You can self-configure the PR merge rules for this repository. For more details, please refer to Here.

Contact Guide

If you have any questions, please contact the SIG: Tools ,
and any of the maintainers: @CarrotGo, @chendong76, @chenxiaobin19, @congzhou2603, @dodders, @hwworkholic, @jemappellehc, @libiao2024, @muyulinzhong, @quemingjian, @shenzheng4, @shirley_zhengx, @superlchf, @totaj, @wlff234, @wofanzheng, @ywzq1161327784 ,
and any of the committers: @Louisyzh, @hw_hbj, @justbk, @libiao2024, @wang4721, @wang_xingmiao, @zengseliang, @zhangxubo .

likedislike
sungang14sungang14成员
9月3日 issue优先级由 无优先级 改变为 次要
sungang14sungang14成员
9月3日 关联了看板:openGauss 7.0.0-LTS
shenzheng4shenzheng4成员
29 天前 关联了pull request:fix jackson logback svgo
shenzheng4shenzheng4成员
29 天前 移除了负责人 TestManager
opengauss_bot
opengauss_bot成员
29 天前 评论:

This issue requires an assignee. Since you haven't specified one, we've assigned TestManager as the default assignee for this issue.

likedislike
opengauss_botopengauss_bot成员
29 天前 将 TestManager 设为负责人
shenzheng4shenzheng4成员
29 天前 将 shenzheng4 设为负责人,移除负责人 TestManager
shenzheng4
shenzheng4成员
25 天前 评论:

影响性分析说明: jackson-databind 在反序列化 java.nio.file.Path 时,未限制攻击者可控 URI 的 scheme;经 Path.of / FileSystemProvider 可能触发任意已注册 provider 的类加载(CWE-502)。仅有 JDK 内置 file/jar 时影响有限;若 classpath 存在有副作用的第三方 FileSystemProvider 则风险升高。受影响区间含 2.19.0~<2.21.6 等;修复线 2.18.10 / 2.21.6 / 2.22.2(见 CVE-2026-19032)。

与本仓库 master 的对应关系:
根 pom.xml 中 jackson.version 为 2.21.5(< 2.21.6),多模块经 ${jackson.version} 引入 jackson-databind,属于受影响区间。

漏洞评分(openGauss评分):
 BaseScore: 5.3
 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

受影响版本排查(受影响/不受影响):
1.master: 受影响

likedislike
opengauss_bot
opengauss_bot成员
25 天前 评论:

经过cve-manager解析,已分析的内容如下表所示:

状态 分析项目 内容
已分析 影响性分析说明 jackson-databind 在反序列化 java.nio.file.Path 时,未限制攻击者可控 URI 的 scheme;经 Path.of / FileSystemProvider 可能触发任意已注册 provider 的类加载(CWE-502)。仅有 JDK 内置 file/jar 时影响有限;若 classpath 存在有副作用的第三方 FileSystemProvider 则风险升高。受影响区间含 2.19.0~<2.21.6 等;修复线 2.18.10 / 2.21.6 / 2.22.2(见 CVE-2026-19032)。与本仓库 master 的对应关系:根 pom.xml 中 jackson.version 为 2.21.5(< 2.21.6),多模块经 ${jackson.version} 引入 jackson-databind,属于受影响区间。
已分析 BaseScore 5.3
已分析 Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
已分析 受影响版本排查 master:受影响

请确认分析内容的准确性, 确认无误后, 您可以进行后续步骤, 否则您可以继续分析.

likedislike
opengauss_botopengauss_bot成员
25 天前 修改了issue 的描述
shenzheng4
shenzheng4成员
25 天前 评论:

自验证:
image.png

likedislike
shenzheng4shenzheng4成员
25 天前 issue状态由 待办的 改变为 待回归
zhoucong<Okidoki>
zhoucong<Okidoki>成员
23 天前 评论:

pr已合入,问题单关闭

likedislike
zhoucong<Okidoki>zhoucong<Okidoki>成员
23 天前 issue状态由 待回归 改变为 已验收
zhoucong<Okidoki>zhoucong<Okidoki>成员
23 天前 关闭了 issue
opengauss_botopengauss_bot成员
23 天前 删除了label:CVE/UNFIXED
opengauss_botopengauss_bot成员
23 天前 添加了label:CVE/FIXED