You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何禁用Jackson DefaultTyping?确认默认状态及关闭多态行为

Great question—let’s walk through this step by step since locking down Jackson against polymorphic deserialization vulnerabilities is super important, especially when you don’t need any polymorphic behavior at all.

First: Jackson 2.10.0 Default Behavior (Critical to Know)

First off, let’s clear up your biggest concern: DefaultTyping is NOT enabled by default in Jackson 2.10.0. Whether you’re using ObjectMapper (JSON), XmlMapper (XML), or CsvMapper (CSV), none of these will automatically process polymorphic type markers like @type to instantiate subclass types out of the box. So if you haven’t explicitly enabled this feature, your setup is already not using polymorphic deserialization.

Do NOT Call activateDefaultTyping()—It’s the Opposite of What You Want

You mentioned wondering if you need to call activateDefaultTyping() and use a PolymorphicTypeValidator to shut things down: don’t do this. The activateDefaultTyping() method is explicitly for enabling polymorphic type handling, not disabling it. Since you don’t need any polymorphic behavior, you shouldn’t touch this method at all.

How to Fully Block All Polymorphic Behavior (Even If Someone Tries to Enable It)

To make absolutely sure no polymorphic deserialization can happen—even if a teammate accidentally enables it later or a library dependency tries to override settings—use these configurations tailored to your Spring Boot 2.1.9 setup:

1. Spring Boot Configuration (JSON, XML, CSV)

For JSON (Default Jackson Setup)

Add these properties to your application.properties or application.yml to enforce secure defaults:

# Disable default typing entirely
spring.jackson.mapper.default-typing=DISABLED
# Reject unknown properties (blocks malicious fields like @type if someone sends them)
spring.jackson.deserialization.fail-on-unknown-properties=true

For XML (Using jackson-dataformat-xml)

If you’re working with XML, create a custom configuration bean to lock down XmlMapper:

@Configuration
public class JacksonXmlSecurityConfig {
    @Bean
    public XmlMapper xmlMapper() {
        XmlMapper xmlMapper = new XmlMapper();
        // Core: Turn off all polymorphic type handling
        xmlMapper.disable(MapperFeature.USE_DEFAULT_TYPING);
        // Reject any unknown properties to block malicious input
        xmlMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES);
        return xmlMapper;
    }
}

For CSV (Using jackson-dataformat-csv)

Similarly, configure CsvMapper explicitly to disable typing:

@Configuration
public class JacksonCsvSecurityConfig {
    @Bean
    public CsvMapper csvMapper() {
        CsvMapper csvMapper = new CsvMapper();
        csvMapper.disable(MapperFeature.USE_DEFAULT_TYPING);
        csvMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES);
        return csvMapper;
    }
}

2. Raw Jackson (Non-Spring Boot)

If you’re using Jackson directly outside Spring Boot’s auto-configuration, apply the same flags directly to your mapper instances:

// JSON
ObjectMapper jsonMapper = new ObjectMapper();
jsonMapper.disable(MapperFeature.USE_DEFAULT_TYPING);
jsonMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES);

// XML
XmlMapper xmlMapper = new XmlMapper();
xmlMapper.disable(MapperFeature.USE_DEFAULT_TYPING);
xmlMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES);

// CSV
CsvMapper csvMapper = new CsvMapper();
csvMapper.disable(MapperFeature.USE_DEFAULT_TYPING);
csvMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES);

Why This Configuration Is Rational for Your Use Case

Since you explicitly don’t need polymorphic behavior:

  • Disabling USE_DEFAULT_TYPING eliminates the entire attack surface for polymorphic deserialization vulnerabilities (like remote code execution via malicious @type values).
  • Enabling FAIL_ON_UNKNOWN_PROPERTIES adds an extra layer of defense: if an attacker tries to send a @type field (or any other unrecognized property), the deserialization will fail immediately.
  • This setup doesn’t interfere with normal serialization/deserialization of your non-polymorphic classes—you’ll still get all the core Jackson functionality you need without the risk.

Final Recap

  1. Your current default setup (Jackson 2.10.0 + Spring Boot 2.1.9) doesn’t have DefaultTyping enabled—no immediate risk there.
  2. Never call activateDefaultTyping() unless you specifically need polymorphic behavior (which you don’t).
  3. Use disable(MapperFeature.USE_DEFAULT_TYPING) to permanently block all polymorphic type handling.
  4. Pair it with FAIL_ON_UNKNOWN_PROPERTIES=true to harden against malicious input.

内容的提问来源于stack exchange,提问作者Stuart

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:14:43