CVE-2026-54513: fallo de gravedad alta en FasterXML jackson-databind
jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.1epss 1.2%
probabilidad de explotación
1.2%top 32% de las CVE
explotación observada
noninguna fuente lo reporta
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
FasterXML · jackson-databindCVEs relacionadas — FasterXML jackson-databind
En el mismo producto, de las más peligrosas a las menos.
CVE-2017-7525—CVE-2017-7525EPSS 37.7%CVE-2017-15095—CVE-2017-15095EPSS 8.4%CVE-2026-54512HIGHjackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiationEPSS 1.0%CVE-2026-83557MEDIUMjackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base typesEPSS 0.7%CVE-2026-50193MEDIUMjackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()EPSS 0.6%CVE-2026-68497HIGHjackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of serviceEPSS 0.6%
Referencias
https://access.redhat.com/errata/RHSA-2026:36839https://access.redhat.com/errata/RHSA-2026:40895https://access.redhat.com/errata/RHSA-2026:41951https://access.redhat.com/errata/RHSA-2026:43218https://access.redhat.com/errata/RHSA-2026:43400https://access.redhat.com/errata/RHSA-2026:44061https://access.redhat.com/errata/RHSA-2026:44062https://access.redhat.com/errata/RHSA-2026:44063https://access.redhat.com/errata/RHSA-2026:44064https://access.redhat.com/errata/RHSA-2026:44065https://access.redhat.com/errata/RHSA-2026:44066https://access.redhat.com/errata/RHSA-2026:44271