CVE-2026-54513High· 8.1▾ TwilightA flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the syst…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the vendor's CSAF advisory record, not NVD.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.7%
0.7% → 0.9%
Last analysed / modified upstream
A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the system to process untrusted data, which may lead to the execution of malicious code. This could result in a complete compromise of the affected system, impacting its confidentiality, integrity, and availability.
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution — rated Important by Red Hat. Released 2026-06-23, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:48095 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:48151 Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. https://access.redhat.com/errata/RHSA-2026:50847
Workarounds / mitigations:
As an additional mitigation, disable polymorphic deserialization of untrusted data where possible by avoiding or removing default typi…
Affected packages:
com.fasterxml.jackson.core:jackson-databind >= 2.10.0, < 2.18.8com.fasterxml.jackson.core:jackson-databind >= 2.19.0, < 2.21.4com.fasterxml.jackson.core:jackson-databind >= 3.0.0, < 3.1.4tools.jackson.core:jackson-databind >= 3.0.0, < 3.1.4Patched in:
com.fasterxml.jackson.core:jackson-databind 2.18.8com.fasterxml.jackson.core:jackson-databind 2.21.4com.fasterxml.jackson.core:jackson-databind 3.1.4tools.jackson.core:jackson-databind 3.1.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54512High· 8.1jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
CVE-2025-22866Medium· 5.3crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
CVE-2026-67325High· 8.8GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature
CVE-2026-49825High· 8.2lxml is a library for processing XML and HTML in the Python language
CVE-2026-80110High· 8.1A flaw was found in pki-core
CVE-2026-75939High· 7.4A flaw was found in openshift/oc-mirror