{"id":"CVE-2026-54512","title":"jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)","summary":"A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious ty…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":["CWE-502","CWE-184"],"vendor":"Red Hat","product":"Red Hat JBoss EAP 7.4 ELS for RHEL 8","affected":["openshift_developer_tools_and_services","openshift_serverless","ai_inference_server","build_of_apache_camel_hawtio 4","build_of_apache_camel_4_for_quarkus 3","build_of_apicurio_registry 3","build_of_debezium 3","certificate_system 11","enterprise_linux 8","enterprise_linux_ai_rhel_ai 3","jboss_enterprise_application_platform 8","openshift_ai_rhoai","satellite 6","single_sign_on 7","streams_for_apache_kafka 2","jboss_eap_7_4_els_for_rhel_7_server","certificate_system_10_8_for_rhel 8","jboss_eap_7_4_els_for_rhel 8","satellite_6_16_for_rhel 8","cryostat_4_on_rhel 9","jboss_eap_7_4_els_for_rhel 9","build_of_keycloak 26.4","build_of_keycloak 26.6","satellite_6_16_for_rhel 9","satellite_6_17_for_rhel 9","satellite_6_18_for_rhel 9","satellite_6_19_for_rhel 9","amq_clients 2026.Q3","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_aus_v_8_4","enterprise_linux_appstream_eus_extension_v_8_4","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9"],"patched":["jboss_eap_7_4_els_for_rhel_7_server","certificate_system_10_8_for_rhel 8","jboss_eap_7_4_els_for_rhel 8","satellite_6_16_for_rhel 8","cryostat_4_on_rhel 9","jboss_eap_7_4_els_for_rhel 9","build_of_keycloak 26.4","build_of_keycloak 26.6","satellite_6_16_for_rhel 9","satellite_6_17_for_rhel 9","satellite_6_18_for_rhel 9","satellite_6_19_for_rhel 9","amq_clients 2026.Q3","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_aus_v_8_4","enterprise_linux_appstream_eus_extension_v_8_4","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","openshift_developer_tools_and_services 4.12","openshift_developer_tools_and_services 4.13","openshift_developer_tools_and_services 4.14","openshift_developer_tools_and_services 4.15","openshift_developer_tools_and_services 4.16","openshift_developer_tools_and_services 4.17","openshift_developer_tools_and_services 4.18","openshift_developer_tools_and_services 4.19","openshift_developer_tools_and_services 4.20","openshift_developer_tools_and_services 4.21","openshift_developer_tools_and_services 4.22","ai_inference_server 3.2","ai_inference_server 3.3","amq_broker 7.13.6","amq_broker 7.14.1"],"published":"2026-06-23","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:11:32+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54512.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54512.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-54512"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492015"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-54512"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512"},{"url":"https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"},{"url":"https://github.com/FasterXML/jackson-databind/issues/5988"},{"url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"},{"url":"https://access.redhat.com/errata/RHSA-2026:53644"},{"url":"https://access.redhat.com/errata/RHSA-2026:48095"},{"url":"https://access.redhat.com/errata/RHSA-2026:53645"},{"url":"https://access.redhat.com/errata/RHSA-2026:63327"},{"url":"https://access.redhat.com/errata/RHSA-2026:48151"},{"url":"https://access.redhat.com/errata/RHSA-2026:53646"},{"url":"https://access.redhat.com/errata/RHSA-2026:50847"},{"url":"https://access.redhat.com/errata/RHSA-2026:50849"},{"url":"https://access.redhat.com/errata/RHSA-2026:63387"},{"url":"https://access.redhat.com/errata/RHSA-2026:63386"},{"url":"https://access.redhat.com/errata/RHSA-2026:63385"},{"url":"https://access.redhat.com/errata/RHSA-2026:69459"},{"url":"https://access.redhat.com/errata/RHSA-2026:44271"},{"url":"https://access.redhat.com/errata/RHSA-2026:43400"},{"url":"https://access.redhat.com/errata/RHSA-2026:44062"},{"url":"https://access.redhat.com/errata/RHSA-2026:44061"},{"url":"https://access.redhat.com/errata/RHSA-2026:44066"},{"url":"https://access.redhat.com/errata/RHSA-2026:44063"},{"url":"https://access.redhat.com/errata/RHSA-2026:44065"},{"url":"https://access.redhat.com/errata/RHSA-2026:44064"},{"url":"https://access.redhat.com/errata/RHSA-2026:40895"},{"url":"https://access.redhat.com/errata/RHSA-2026:60247"},{"url":"https://access.redhat.com/errata/RHSA-2026:60249"},{"url":"https://access.redhat.com/errata/RHSA-2026:60248"},{"url":"https://access.redhat.com/errata/RHSA-2026:60239"},{"url":"https://access.redhat.com/errata/RHSA-2026:60251"},{"url":"https://github.com/advisories/GHSA-j3rv-43j4-c7qm"}],"tags":["csaf","vex","red-hat","exploit-available","ghsa","maven"],"epss":0.00873,"epssPercentile":0.56884,"exploits":{"github":2,"githubRepos":["https://github.com/avergnaud/flight-sql-jdbc-driver-cve-2026-54512","https://github.com/cklinisme/doris-spark-connector-cve"],"checkedAt":"2026-09-21T16:44:46.136Z"},"exploitAvailable":true,"ecosystem":"maven","ingestedAt":"2026-06-26T16:43:14.619Z","slug":"CVE-2026-54512","body":"## Overview\n\nA flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious type ID, an attacker can place a denied class as a generic type parameter of an allowed container. This leads to the loading and instantiation of arbitrary classes, potentially resulting in arbitrary code execution.\n\n## Vendor advisories\n\n- **RHSA-2026:53644** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53644)\n- **RHSA-2026:48095** · Red Hat · fixed in: Red Hat Certificate System 10.8 for RHEL 8 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48095)\n- **RHSA-2026:53645** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 8 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53645)\n- **RHSA-2026:63327** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63327)\n- **RHSA-2026:48151** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48151)\n- **RHSA-2026:53646** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 9 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53646)\n- **RHSA-2026:50847** · Red Hat · fixed in: Red Hat build of Keycloak 26.4 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50847)\n- **RHSA-2026:50849** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50849)\n- **RHSA-2026:63387** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63387)\n- **RHSA-2026:63386** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63386)\n- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)\n- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat AI Inference Server, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, … · no fix planned: Red Hat AI Inference Server, Red Hat build of Debezium 3, OpenShift Developer Tools and Services, OpenShift Serverless, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54512.json)\n- **RHSA-2026:44271** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44271)\n- **RHSA-2026:43400** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43400)\n- **RHSA-2026:44062** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44062)\n\n**jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass** — rated Important by Red Hat. Released 2026-06-23, updated 2026-09-21.\n\nAffected:\n\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat AI Inference Server\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apache Camel 4 for Quarkus 3\n- Red Hat build of Apicurio Registry 3\n- Red Hat build of Debezium 3\n- Red Hat Certificate System 11\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat JBoss Enterprise Application Platform 8\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n- streams for Apache Kafka 2\n\nFixed:\n\n- Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server\n- Red Hat Certificate System 10.8 for RHEL 8\n- Red Hat JBoss EAP 7.4 ELS for RHEL 8\n- Red Hat Satellite 6.16 for RHEL 8\n- Cryostat 4 on RHEL 9\n- Red Hat JBoss EAP 7.4 ELS for RHEL 9\n- Red Hat build of Keycloak 26.4\n- Red Hat build of Keycloak 26.6\n- Red Hat Satellite 6.16 for RHEL 9\n- Red Hat Satellite 6.17 for RHEL 9\n- Red Hat Satellite 6.18 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- AMQ Clients 2026.Q3\n- Red Hat Enterprise Linux AppStream EUS (v. 10.0)\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream AUS (v.8.4)\n- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)\n- Red Hat Enterprise Linux AppStream AUS (v.8.6)\n- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)\n- Red Hat Enterprise Linux AppStream E4S (v.8.8)\n- Red Hat Enterprise Linux AppStream TUS (v.8.8)\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream E4S (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- OpenShift Developer Tools and Services 4.12\n- OpenShift Developer Tools and Services 4.13\n- OpenShift Developer Tools and Services 4.14\n- OpenShift Developer Tools and Services 4.15\n- OpenShift Developer Tools and Services 4.16\n- OpenShift Developer Tools and Services 4.17\n- OpenShift Developer Tools and Services 4.18\n- OpenShift Developer Tools and Services 4.19\n- OpenShift Developer Tools and Services 4.20\n- OpenShift Developer Tools and Services 4.21\n- OpenShift Developer Tools and Services 4.22\n- Red Hat AI Inference Server 3.2\n- Red Hat AI Inference Server 3.3\n- Red Hat AMQ Broker 7.13.6\n- Red Hat AMQ Broker 7.14.1\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat build of Debezium 3\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apache Camel 4 for Quarkus 3\n- Red Hat build of Apicurio Registry 3\n- Red Hat Certificate System 11\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat JBoss Enterprise Application Platform 8\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n- streams for Apache Kafka 2\n\nNot affected:\n\n- Red Hat Satellite 6.16 for RHEL 8\n- Cryostat 4 on RHEL 9\n- Red Hat Satellite 6.16 for RHEL 9\n- Red Hat Satellite 6.17 for RHEL 9\n- Red Hat Satellite 6.18 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream E4S (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Red Hat Enterprise Linux AppStream (v. 9)\n\n## Remediation\n\nBefore applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:53644\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:48095\nBefore applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:53645\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2026-54512)\n\nAffected packages:\n\n- `com.fasterxml.jackson.core:jackson-databind >= 2.10.0, <= 2.18.7`\n- `com.fasterxml.jackson.core:jackson-databind >= 3.0.0, <= 3.1.3`\n- `com.fasterxml.jackson.core:jackson-databind >= 2.19.0, <= 2.21.3`\n- `tools.jackson.core:jackson-databind >= 3.0.0, <= 3.1.3`\n\nPatched in:\n\n- `com.fasterxml.jackson.core:jackson-databind 2.18.8`\n- `com.fasterxml.jackson.core:jackson-databind 3.1.4`\n- `com.fasterxml.jackson.core:jackson-databind 2.21.4`\n- `tools.jackson.core:jackson-databind 3.1.4`\n\nSource: https://github.com/advisories/GHSA-j3rv-43j4-c7qm","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":206986,"id":"CVE-2026-54512","ts":1789749734485,"field":"exploit_available","old":"false","new":"true"}]}