---
id: CVE-2026-54512
title: >-
  jackson-databind: jackson-databind: Arbitrary code execution via
  PolymorphicTypeValidator bypass (CVE-2026-54512)
summary: >-
  A flaw was found in jackson-databind. This vulnerability allows a remote
  attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing
  is enabled and a type identifier contains generic parameters. By crafting a
  malicious ty…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe:
  - CWE-502
  - CWE-184
vendor: Red Hat
product: Red Hat JBoss EAP 8.1 for RHEL 8
affected:
  - openshift_developer_tools_and_services
  - openshift_serverless
  - ai_inference_server
  - build_of_apache_camel_hawtio 4
  - build_of_apache_camel_4_for_quarkus 3
  - build_of_apicurio_registry 3
  - build_of_debezium 3
  - certificate_system 11
  - enterprise_linux 8
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - satellite 6
  - single_sign_on 7
  - streams_for_apache_kafka 2
  - jboss_eap_8_1_for_rhel 10
  - jboss_eap_7_4_els_for_rhel_7_server
  - certificate_system_10_8_for_rhel 8
  - jboss_eap_7_4_els_for_rhel 8
  - jboss_eap_8_1_for_rhel 8
  - satellite_6_16_for_rhel 8
  - cryostat_4_on_rhel 9
  - jboss_eap_7_4_els_for_rhel 9
  - jboss_eap_8_1_for_rhel 9
  - build_of_keycloak 26.4
  - build_of_keycloak 26.6
  - satellite_6_16_for_rhel 9
  - satellite_6_17_for_rhel 9
  - satellite_6_18_for_rhel 9
  - satellite_6_19_for_rhel 9
  - amq_clients 2026.Q3
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
patched:
  - jboss_eap_8_1_for_rhel 10
  - jboss_eap_7_4_els_for_rhel_7_server
  - certificate_system_10_8_for_rhel 8
  - jboss_eap_7_4_els_for_rhel 8
  - jboss_eap_8_1_for_rhel 8
  - satellite_6_16_for_rhel 8
  - cryostat_4_on_rhel 9
  - jboss_eap_7_4_els_for_rhel 9
  - jboss_eap_8_1_for_rhel 9
  - build_of_keycloak 26.4
  - build_of_keycloak 26.6
  - satellite_6_16_for_rhel 9
  - satellite_6_17_for_rhel 9
  - satellite_6_18_for_rhel 9
  - satellite_6_19_for_rhel 9
  - amq_clients 2026.Q3
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - openshift_developer_tools_and_services 4.12
  - openshift_developer_tools_and_services 4.13
  - openshift_developer_tools_and_services 4.14
  - openshift_developer_tools_and_services 4.15
  - openshift_developer_tools_and_services 4.16
  - openshift_developer_tools_and_services 4.17
  - openshift_developer_tools_and_services 4.18
  - openshift_developer_tools_and_services 4.19
  - openshift_developer_tools_and_services 4.20
  - openshift_developer_tools_and_services 4.21
  - openshift_developer_tools_and_services 4.22
  - ai_inference_server 3.2
published: '2026-06-23'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T15:32:09+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54512.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54512.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-54512'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2492015'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-54512'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54512'
  - url: >-
      https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5
  - url: 'https://github.com/FasterXML/jackson-databind/issues/5988'
  - url: >-
      https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm
  - url: 'https://access.redhat.com/errata/RHSA-2026:70230'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53644'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48095'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53645'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70228'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63327'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48151'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53646'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70229'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50847'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50849'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63387'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63386'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63385'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69459'
  - url: 'https://access.redhat.com/errata/RHSA-2026:44271'
  - url: 'https://access.redhat.com/errata/RHSA-2026:43400'
  - url: 'https://access.redhat.com/errata/RHSA-2026:44062'
  - url: 'https://access.redhat.com/errata/RHSA-2026:44061'
  - url: 'https://access.redhat.com/errata/RHSA-2026:44066'
  - url: 'https://access.redhat.com/errata/RHSA-2026:44063'
  - url: 'https://access.redhat.com/errata/RHSA-2026:44065'
  - url: 'https://access.redhat.com/errata/RHSA-2026:44064'
  - url: 'https://access.redhat.com/errata/RHSA-2026:40895'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60247'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60249'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60248'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60239'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60251'
  - url: 'https://github.com/advisories/GHSA-j3rv-43j4-c7qm'
tags:
  - csaf
  - vex
  - red-hat
  - exploit-available
  - ghsa
  - maven
epss: 0.00873
epssPercentile: 0.57416
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/avergnaud/flight-sql-jdbc-driver-cve-2026-54512'
    - 'https://github.com/cklinisme/doris-spark-connector-cve'
  checkedAt: '2026-09-24T07:53:07.144Z'
exploitAvailable: true
ecosystem: maven
ingestedAt: '2026-06-26T16:43:14.619Z'
---

## Overview

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious type ID, an attacker can place a denied class as a generic type parameter of an allowed container. This leads to the loading and instantiation of arbitrary classes, potentially resulting in arbitrary code execution.

## Vendor advisories

- **RHSA-2026:70230** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 10 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70230)
- **RHSA-2026:53644** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53644)
- **RHSA-2026:48095** · Red Hat · fixed in: Red Hat Certificate System 10.8 for RHEL 8 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48095)
- **RHSA-2026:53645** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 8 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53645)
- **RHSA-2026:70228** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 8 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70228)
- **RHSA-2026:63327** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63327)
- **RHSA-2026:48151** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48151)
- **RHSA-2026:53646** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 9 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53646)
- **RHSA-2026:70229** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 9 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70229)
- **RHSA-2026:50847** · Red Hat · fixed in: Red Hat build of Keycloak 26.4 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50847)
- **RHSA-2026:50849** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50849)
- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat AI Inference Server, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, … · no fix planned: Red Hat AI Inference Server, Red Hat build of Debezium 3, OpenShift Developer Tools and Services, OpenShift Serverless, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54512.json)
- **RHSA-2026:63387** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63387)
- **RHSA-2026:63386** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63386)
- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)
- **RHSA-2026:44271** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44271)
- **RHSA-2026:43400** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43400)
- **RHSA-2026:44062** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44062)

**jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass** — rated Important by Red Hat. Released 2026-06-23, updated 2026-09-22.

Affected:

- OpenShift Developer Tools and Services
- OpenShift Serverless
- Red Hat AI Inference Server
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apache Camel 4 for Quarkus 3
- Red Hat build of Apicurio Registry 3
- Red Hat build of Debezium 3
- Red Hat Certificate System 11
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6
- Red Hat Single Sign-On 7
- streams for Apache Kafka 2

Fixed:

- Red Hat JBoss EAP 8.1 for RHEL 10
- Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server
- Red Hat Certificate System 10.8 for RHEL 8
- Red Hat JBoss EAP 7.4 ELS for RHEL 8
- Red Hat JBoss EAP 8.1 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 8
- Cryostat 4 on RHEL 9
- Red Hat JBoss EAP 7.4 ELS for RHEL 9
- Red Hat JBoss EAP 8.1 for RHEL 9
- Red Hat build of Keycloak 26.4
- Red Hat build of Keycloak 26.6
- Red Hat Satellite 6.16 for RHEL 9
- Red Hat Satellite 6.17 for RHEL 9
- Red Hat Satellite 6.18 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- AMQ Clients 2026.Q3
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream AUS (v.8.4)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- Red Hat Enterprise Linux AppStream AUS (v.8.6)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.8)
- Red Hat Enterprise Linux AppStream TUS (v.8.8)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- OpenShift Developer Tools and Services 4.12
- OpenShift Developer Tools and Services 4.13
- OpenShift Developer Tools and Services 4.14
- OpenShift Developer Tools and Services 4.15
- OpenShift Developer Tools and Services 4.16
- OpenShift Developer Tools and Services 4.17
- OpenShift Developer Tools and Services 4.18
- OpenShift Developer Tools and Services 4.19
- OpenShift Developer Tools and Services 4.20
- OpenShift Developer Tools and Services 4.21
- OpenShift Developer Tools and Services 4.22
- Red Hat AI Inference Server 3.2

No fix planned:

- Red Hat AI Inference Server
- Red Hat build of Debezium 3
- OpenShift Developer Tools and Services
- OpenShift Serverless
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apache Camel 4 for Quarkus 3
- Red Hat build of Apicurio Registry 3
- Red Hat Certificate System 11
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6
- Red Hat Single Sign-On 7
- streams for Apache Kafka 2

Not affected:

- Red Hat Satellite 6.16 for RHEL 8
- Cryostat 4 on RHEL 9
- Red Hat Satellite 6.16 for RHEL 9
- Red Hat Satellite 6.17 for RHEL 9
- Red Hat Satellite 6.18 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)

## Remediation

Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:70230
Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:53644
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:48095

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2026-54512)

Affected packages:

- `com.fasterxml.jackson.core:jackson-databind >= 2.10.0, <= 2.18.7`
- `com.fasterxml.jackson.core:jackson-databind >= 3.0.0, <= 3.1.3`
- `com.fasterxml.jackson.core:jackson-databind >= 2.19.0, <= 2.21.3`
- `tools.jackson.core:jackson-databind >= 3.0.0, <= 3.1.3`

Patched in:

- `com.fasterxml.jackson.core:jackson-databind 2.18.8`
- `com.fasterxml.jackson.core:jackson-databind 3.1.4`
- `com.fasterxml.jackson.core:jackson-databind 2.21.4`
- `tools.jackson.core:jackson-databind 3.1.4`

Source: https://github.com/advisories/GHSA-j3rv-43j4-c7qm
