CVE-2026-54513: high-severity vulnerability in FasterXML jackson-databind
jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 1.2%
exploitation probability
1.2%top 32% of all CVEs
observed exploitation
nono source reports it
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
FasterXML · jackson-databindRelated CVEs — FasterXML jackson-databind
In the same product, most dangerous first.
CVE-2017-7525—CVE-2017-7525EPSS 37.7%CVE-2017-15095—CVE-2017-15095EPSS 8.4%CVE-2026-54512HIGHjackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiationEPSS 1.0%CVE-2026-83557MEDIUMjackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base typesEPSS 0.7%CVE-2026-50193MEDIUMjackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()EPSS 0.6%CVE-2026-68497HIGHjackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of serviceEPSS 0.6%
References
https://access.redhat.com/errata/RHSA-2026:36839https://access.redhat.com/errata/RHSA-2026:40895https://access.redhat.com/errata/RHSA-2026:41951https://access.redhat.com/errata/RHSA-2026:43218https://access.redhat.com/errata/RHSA-2026:43400https://access.redhat.com/errata/RHSA-2026:44061https://access.redhat.com/errata/RHSA-2026:44062https://access.redhat.com/errata/RHSA-2026:44063https://access.redhat.com/errata/RHSA-2026:44064https://access.redhat.com/errata/RHSA-2026:44065https://access.redhat.com/errata/RHSA-2026:44066https://access.redhat.com/errata/RHSA-2026:44271