CVE-2026-54513

EUVD-2026-38593
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 50.18%
Affected Products (NVD)
VendorProductVersion
fasterxmljackson-databind
2.10.0 ≤
𝑥
< 2.18.8
fasterxmljackson-databind
2.19.0 ≤
𝑥
< 2.21.4
fasterxmljackson-databind
3.0.0 ≤
𝑥
< 3.1.4
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatCryostat 4 on RHEL 9
4.2.0-13 ≤
𝑥
< *
ADP
Red HatCryostat 4 on RHEL 9
4.2.0-13 ≤
𝑥
< *
ADP
Red HatCryostat 4 on RHEL 9
4.2.0-13 ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.4
26.4.14-1 ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.4
26.4-22 ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.4
26.4-22 ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.4.14
rhel9-operator ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.4.14
openshift-rhel9 ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.4.14
rhel9-operator ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.6
26.6.5-1 ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.6
26.6-11 ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.6
26.6-11 ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.6.5
rhel9-operator ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.6.5
openshift-rhel9 ≤
𝑥
< *
ADP
Red HatRed Hat build of Keycloak 26.6.5
rhel9-operator ≤
𝑥
< *
ADP
Red HatRed Hat Certificate System 10.8 for RHEL-8
8100020260728001635.f9354743 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10
0:11.9.0-4.el10_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:11.6.0-2.el10_0 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
8100020260714102233.489197e6 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
8040020260720064222.522a0ee4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
8040020260720064222.522a0ee4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
8060020260720025549.ad008a3a ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
8060020260720025549.ad008a3a ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
8080020260714161755.63b34585 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
8080020260714161755.63b34585 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:2.21.4-1.el9_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:2.21.4-1.el9_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
0:2.21.4-1.el9_4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:2.21.4-1.el9_6 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
jackson-databind
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jackson-databind
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
jackson-annotations
suse enterprise desktop 15 SP7
2.18.8-150200.3.22.3
fixed
suse enterprise sap 15 SP4
2.18.8-150200.3.22.3
fixed
suse enterprise sap 15 SP5
2.18.8-150200.3.22.3
fixed
suse enterprise sap 15 SP6
2.18.8-150200.3.22.3
fixed
suse enterprise sap 15 SP7
2.18.8-150200.3.22.3
fixed
suse enterprise server 15 SP4
2.18.8-150200.3.22.3
fixed
suse enterprise server 15 SP5
2.18.8-150200.3.22.3
fixed
suse enterprise server 15 SP6
2.18.8-150200.3.22.3
fixed
suse enterprise server 15 SP7
2.18.8-150200.3.22.3
fixed
jackson-core
suse enterprise desktop 15 SP7
2.18.8-150200.3.22.3
fixed
suse enterprise sap 15 SP4
2.18.8-150200.3.22.3
fixed
suse enterprise sap 15 SP5
2.18.8-150200.3.22.3
fixed
suse enterprise sap 15 SP6
2.18.8-150200.3.22.3
fixed
suse enterprise sap 15 SP7
2.18.8-150200.3.22.3
fixed
suse enterprise server 15 SP4
2.18.8-150200.3.22.3
fixed
suse enterprise server 15 SP5
2.18.8-150200.3.22.3
fixed
suse enterprise server 15 SP6
2.18.8-150200.3.22.3
fixed
suse enterprise server 15 SP7
2.18.8-150200.3.22.3
fixed
jackson-databind
suse enterprise desktop 15 SP7
2.18.8-150200.3.28.2
fixed
suse enterprise sap 15 SP4
2.18.8-150200.3.28.2
fixed
suse enterprise sap 15 SP5
2.18.8-150200.3.28.2
fixed
suse enterprise sap 15 SP6
2.18.8-150200.3.28.2
fixed
suse enterprise sap 15 SP7
2.18.8-150200.3.28.2
fixed
suse enterprise server 15 SP4
2.18.8-150200.3.28.2
fixed
suse enterprise server 15 SP5
2.18.8-150200.3.28.2
fixed
suse enterprise server 15 SP6
2.18.8-150200.3.28.2
fixed
suse enterprise server 15 SP7
2.18.8-150200.3.28.2
fixed
jackson-dataformat-cbor
suse enterprise sap 15 SP4
2.18.8-150200.3.21.3
fixed
suse enterprise sap 15 SP5
2.18.8-150200.3.21.3
fixed
suse enterprise sap 15 SP6
2.18.8-150200.3.21.3
fixed
suse enterprise server 15 SP4
2.18.8-150200.3.21.3
fixed
suse enterprise server 15 SP5
2.18.8-150200.3.21.3
fixed
suse enterprise server 15 SP6
2.18.8-150200.3.21.3
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
pki-jackson-databind
RHEL 9
0:2.21.4-1.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
jackson-databind
Amazon Linux 2023
0:2.16.1-4.amzn2023.0.2
fixed