CVE-2026-54513

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
References
Link Resource
https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5 Patch
https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e Patch
https://github.com/FasterXML/jackson-databind/issues/5981 Issue Tracking
https://github.com/FasterXML/jackson-databind/issues/5983 Issue Tracking Patch
https://github.com/FasterXML/jackson-databind/pull/5984 Issue Tracking Patch
https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f Patch Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:36839
https://access.redhat.com/errata/RHSA-2026:40895
https://access.redhat.com/errata/RHSA-2026:41951
https://access.redhat.com/errata/RHSA-2026:43218
https://access.redhat.com/errata/RHSA-2026:43400
https://access.redhat.com/errata/RHSA-2026:44061
https://access.redhat.com/errata/RHSA-2026:44062
https://access.redhat.com/errata/RHSA-2026:44063
https://access.redhat.com/errata/RHSA-2026:44064
https://access.redhat.com/errata/RHSA-2026:44065
https://access.redhat.com/errata/RHSA-2026:44066
https://access.redhat.com/errata/RHSA-2026:44271
https://access.redhat.com/errata/RHSA-2026:48095
https://access.redhat.com/errata/RHSA-2026:48151
https://access.redhat.com/errata/RHSA-2026:50846
https://access.redhat.com/errata/RHSA-2026:50847
https://access.redhat.com/errata/RHSA-2026:50848
https://access.redhat.com/errata/RHSA-2026:50849
https://access.redhat.com/errata/RHSA-2026:54435
https://access.redhat.com/errata/RHSA-2026:54622
https://access.redhat.com/errata/RHSA-2026:62260
https://access.redhat.com/errata/RHSA-2026:66488
https://access.redhat.com/errata/RHSA-2026:66545
https://access.redhat.com/security/cve/CVE-2026-54513
https://bugzilla.redhat.com/show_bug.cgi?id=2492010
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-23 21:17

Updated : 2026-09-14 13:18


NVD link : CVE-2026-54513

Mitre link : CVE-2026-54513

CVE.ORG link : CVE-2026-54513


JSON object : View

Products Affected

fasterxml

  • jackson-databind
CWE
CWE-184

Incomplete List of Disallowed Inputs