jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
FasterXML · jackson-databindReferences
https://access.redhat.com/errata/RHSA-2026:36839https://access.redhat.com/errata/RHSA-2026:40895https://access.redhat.com/errata/RHSA-2026:41951https://access.redhat.com/errata/RHSA-2026:43218https://access.redhat.com/errata/RHSA-2026:43400https://access.redhat.com/errata/RHSA-2026:44061https://access.redhat.com/errata/RHSA-2026:44062https://access.redhat.com/errata/RHSA-2026:44063https://access.redhat.com/errata/RHSA-2026:44064https://access.redhat.com/errata/RHSA-2026:44065https://access.redhat.com/errata/RHSA-2026:44066https://access.redhat.com/errata/RHSA-2026:44271