{"record":{"id":"5f4f9a6b8c06723f","repo":"FasterXML/jackson-databind","slug":"argument-allowedschemes-must-not-be-null","errorCode":null,"errorMessage":"Argument `allowedSchemes` must not be null","messagePattern":"Argument `allowedSchemes` must not be null","errorType":"validation","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"src/main/java/tools/jackson/databind/deser/jdk/JDKFromStringDeserializer.java","lineNumber":402,"sourceCode":"\n        public NioPathDeserializer() { this(DEFAULT_ALLOWED_SCHEMES); }\n\n        /**\n         * Constructor for specifying URI schemes to accept: matching is done\n         * case-insensitively, same as by {@code java.nio.file.Path.of(URI)}.\n         *<p>\n         * NOTE: for allowed schemes that have no provider installed for the system\n         * class loader, look up is also attempted using this thread's context class\n         * loader (see [databind#2120]); this is never done for schemes that are not\n         * allowed.\n         *\n         * @param allowedSchemes URI schemes to accept; must not be {@code null}\n         *   (but may be empty to only accept scheme-less values)\n         */\n        public NioPathDeserializer(Collection<String> allowedSchemes) {\n            super(Path.class, -1);\n            if (allowedSchemes == null) {\n                throw new IllegalArgumentException(\"Argument `allowedSchemes` must not be null\");\n            }\n            _allowedSchemes = allowedSchemes;\n        }\n\n        @Override\n        public Object _deserialize(String value, DeserializationContext ctxt) throws JacksonException {\n            return deserialize(ctxt, value, _allowedSchemes);\n        }\n\n        public static Path deserialize(DeserializationContext ctxt, String value,\n                Collection<String> allowedSchemes) throws JacksonException {\n            // If someone gives us an input with no : at all, treat as local path,\n            // instead of failing with invalid URI.\n\n            int colonIx = value.indexOf(':');\n            if (colonIx < 0) {\n                return Path.of(value);\n            }","sourceCodeStart":384,"sourceCodeEnd":420,"githubUrl":"https://github.com/FasterXML/jackson-databind/blob/87876ca5c0569b4933aec2d30d6225e4b9ba3a43/src/main/java/tools/jackson/databind/deser/jdk/JDKFromStringDeserializer.java#L384-L420","documentation":"NioPathDeserializer (the deserializer for java.nio.file.Path) requires a non-null collection of allowed URI schemes; passing null is a programmer error because the allow-list semantics need an explicit (possibly empty) set. The constructor throws IllegalArgumentException at JDKFromStringDeserializer.java:402. The public no-arg constructor already supplies DEFAULT_ALLOWED_SCHEMES, so this only fires when the Collection overload is called directly.","triggerScenarios":"Manually instantiating new NioPathDeserializer(null); registering a custom Path deserializer via a SimpleModule and passing null for the scheme allow-list; wrapping NioPathDeserializer in a delegating deserializer that forwards a null configuration.","commonSituations":"Building a security-hardened Path deserializer (see databind#6129) and forgetting to initialize the scheme list; copy-paste from older code that pre-dates the allowedSchemes constructor; DI frameworks that inject null for an optional-looking Collection parameter.","solutions":["Pass NioPathDeserializer.DEFAULT_ALLOWED_SCHEMES (file only) when you want default behavior.","Pass Collections.emptyList() when you want to accept only scheme-less (local path) values.","Pass an explicit allow-list such as List.of(\"file\",\"jar\") to permit exactly those schemes.","Prefer the no-arg constructor new NioPathDeserializer() unless you need a custom scheme set."],"exampleFix":"// before\nSimpleModule m = new SimpleModule();\nm.addDeserializer(Path.class, new NioPathDeserializer(null));\n\n// after\nm.addDeserializer(Path.class, new NioPathDeserializer(NioPathDeserializer.DEFAULT_ALLOWED_SCHEMES));","handlingStrategy":"validation","validationCode":"Collection<String> schemes = (configured == null)\n    ? NioPathDeserializer.DEFAULT_ALLOWED_SCHEMES\n    : configured;\nm.addDeserializer(Path.class, new NioPathDeserializer(schemes));","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use the no-arg NioPathDeserializer() unless you need a custom scheme set.","Treat allowedSchemes as a required parameter in any wrapper and fail fast with a clear message if null.","Add an Objects.requireNonNull(schemes) guard at the boundary of your own configuration."],"tags":["deserialization","path","uri","security","illegal-argument","nio"],"backgroundTag":null,"analyzedSha":"87876ca5c0569b4933aec2d30d6225e4b9ba3a43","analyzedAt":"2026-08-11T12:55:24.033Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}