← Vulnerability feed

Vulnerability record · CVE-2026-54513 · published 23 June 2026

CVE-2026-54513: Fasterxml jackson-databind vulnerability

Fasterxml · Jackson Databind

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

8.1 CVSS 3.1 High EPSS 1.2% · top 32.4% CWE-184 · CWE-184
8.1CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References
14 Sep 2026Last modified by NVD

Description

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5 Patch
https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e Patch
https://github.com/FasterXML/jackson-databind/issues/5981 Issue Tracking
https://github.com/FasterXML/jackson-databind/issues/5983 Issue TrackingPatch
https://github.com/FasterXML/jackson-databind/pull/5984 Issue TrackingPatch
https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f PatchVendor Advisory
https://access.redhat.com/errata/RHSA-2026:36839
https://access.redhat.com/errata/RHSA-2026:40895
https://access.redhat.com/errata/RHSA-2026:41951
https://access.redhat.com/errata/RHSA-2026:43218
https://access.redhat.com/errata/RHSA-2026:43400
https://access.redhat.com/errata/RHSA-2026:44061
https://access.redhat.com/errata/RHSA-2026:44062
https://access.redhat.com/errata/RHSA-2026:44063
https://access.redhat.com/errata/RHSA-2026:44064
https://access.redhat.com/errata/RHSA-2026:44065
https://access.redhat.com/errata/RHSA-2026:44066
https://access.redhat.com/errata/RHSA-2026:44271
https://access.redhat.com/errata/RHSA-2026:48095
https://access.redhat.com/errata/RHSA-2026:48151
https://access.redhat.com/errata/RHSA-2026:50846
https://access.redhat.com/errata/RHSA-2026:50847
https://access.redhat.com/errata/RHSA-2026:50848
https://access.redhat.com/errata/RHSA-2026:50849
https://access.redhat.com/errata/RHSA-2026:54435
https://access.redhat.com/errata/RHSA-2026:54622
https://access.redhat.com/errata/RHSA-2026:62260
https://access.redhat.com/errata/RHSA-2026:66488
https://access.redhat.com/errata/RHSA-2026:66545
https://access.redhat.com/security/cve/CVE-2026-54513
https://bugzilla.redhat.com/show_bug.cgi?id=2492010
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json

Track CVE-2026-54513 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2018-14721Fasterxml jackson-databind server-side request forgery (ssrf) vulnerabilityFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …EPSS 10%9.8CVE-2019-14893Fasterxml jackson-databind information exposure vulnerabilityA flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of ma…EPSS 4.1%9.8CVE-2019-14892Fasterxml jackson-databind information exposure vulnerabilityA flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…EPSS 5.6%9.8CVE-2020-9547Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engi…EPSS 18%9.8CVE-2020-9548Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.An…EPSS 18%9.8CVE-2020-9546Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shad…EPSS 4.6%9.8CVE-2020-8840Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiC…EPSS 27%9.8CVE-2019-20330Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.EPSS 8.6%

Source: NIST National Vulnerability Database (record CVE-2026-54513), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.