<Vulnerability name="CVE-2026-86321">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-07T15:00:11</PublicDate>
    <Bugzilla id="2529509" url="https://bugzilla.redhat.com/show_bug.cgi?id=2529509" xml:lang="en:us">
com.github.fge/jackson-coreutils: java-json-tools jackson-coreutils: Server-Side Request Forgery via JsonLoader.fromURL
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-918</CWE>
    <Details xml:lang="en:us" source="Mitre">
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in jackson-coreutils. This server-side request forgery (SSRF) vulnerability occurs when applications use the `JsonLoader.fromURL` function with untrusted input. A remote attacker can exploit this to induce the server to make arbitrary requests. This could lead to unauthorized information disclosure or access to internal network resources.
    </Details>
    <Statement xml:lang="en:us">
Moderate: A server-side request forgery (SSRF) vulnerability exists in `jackson-coreutils` when applications use `JsonLoader.fromURL` with untrusted input. This flaw allows a remote attacker to induce the server to make arbitrary requests, potentially leading to information disclosure or access to internal network resources. The impact is considered Moderate due to the need for an application to expose this functionality to untrusted input.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:jboss_fuse:7">
        <ProductName>Red Hat Fuse 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>jackson-coreutils</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>jackson-coreutils</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>jboss-eap-7/eap74-els-openjdk11-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>jboss-eap-7/eap74-els-openjdk17-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>jboss-eap-7/eap74-els-openjdk8-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:8">
        <ProductName>Red Hat JBoss Enterprise Application Platform 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>jackson-coreutils</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jbosseapxp">
        <ProductName>Red Hat JBoss Enterprise Application Platform Expansion Pack</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>jackson-coreutils</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:red_hat_single_sign_on:7">
        <ProductName>Red Hat Single Sign-On 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>jackson-coreutils</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-86321
https://nvd.nist.gov/vuln/detail/CVE-2026-86321
https://github.com/java-json-tools/jackson-coreutils/
https://github.com/java-json-tools/jackson-coreutils/issues/64
https://vuldb.com/cve/CVE-2026-86321
https://vuldb.com/submit/908323
https://vuldb.com/vuln/399511
https://vuldb.com/vuln/399511/cti
    </References>
</Vulnerability>