CRITICALMaven →
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
Affected packages
- com.fasterxml.jackson.core:jackson-databind— 2.10.0 → 2.18.8
- tools.jackson.core:jackson-databind— 3.0.0 → 3.1.4
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.71%
- EPSS percentile
- 50.1%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 50%.
Sources
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f
- https://nvd.nist.gov/vuln/detail/CVE-2026-54513
- https://github.com/FasterXML/jackson-databind/issues/5983
- https://github.com/FasterXML/jackson-databind/issues/5981
- https://github.com/FasterXML/jackson-databind/pull/5984
- https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e
- https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json
- https://github.com/FasterXML/jackson-databind
- https://bugzilla.redhat.com/show_bug.cgi?id=2492010
- https://access.redhat.com/security/cve/CVE-2026-54513
- https://access.redhat.com/errata/RHSA-2026:48151
- https://access.redhat.com/errata/RHSA-2026:48095
- https://access.redhat.com/errata/RHSA-2026:44271
- https://access.redhat.com/errata/RHSA-2026:44066
- https://access.redhat.com/errata/RHSA-2026:44065
- https://access.redhat.com/errata/RHSA-2026:44064
- https://access.redhat.com/errata/RHSA-2026:44063
- https://access.redhat.com/errata/RHSA-2026:44062
- https://access.redhat.com/errata/RHSA-2026:44061
- https://access.redhat.com/errata/RHSA-2026:43400
- https://access.redhat.com/errata/RHSA-2026:43218
- https://access.redhat.com/errata/RHSA-2026:41951
- https://access.redhat.com/errata/RHSA-2026:40895
- https://access.redhat.com/errata/RHSA-2026:36839
Structured record: https://osv.dev/vulnerability/GHSA-rmj7-2vxq-3g9f
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta