CVE-2026-54515Medium· 5.3▾ TwilightPoC availableA flaw was found in jackson-databind. This vulnerability occurs in the data-binding functionality where properties intended to be ignored are incorrectly restored and become writable again. An attacker could potentially exploit this by pro…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
1 GitHub repo
Last analysed / modified upstream
0.3% → 0.4%
A flaw was found in jackson-databind. This vulnerability occurs in the data-binding functionality where properties intended to be ignored are incorrectly restored and become writable again. An attacker could potentially exploit this by providing input that modifies data through these supposedly ignored properties. This could lead to unintended changes in application data, impacting data integrity.
jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified — rated Moderate by Red Hat. Released 2026-06-23, updated 2026-09-15.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67604
Workarounds / mitigations:
Affected packages:
com.fasterxml.jackson.core:jackson-databind >= 3.1.0, < 3.1.4tools.jackson.core:jackson-databind >= 3.1.0, < 3.1.4com.fasterxml.jackson.core:jackson-databind >= 2.8.0, < 2.18.9com.fasterxml.jackson.core:jackson-databind >= 2.19.0, < 2.21.5Patched in:
com.fasterxml.jackson.core:jackson-databind 3.1.4tools.jackson.core:jackson-databind 3.1.4com.fasterxml.jackson.core:jackson-databind 2.18.9com.fasterxml.jackson.core:jackson-databind 2.21.5Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59889Medium· 6.5com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties (CVE…
CVE-2026-54512High· 8.1jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
CVE-2026-59888Medium· 6.5com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records (CVE…
CVE-2026-0603High· 8.3A flaw was found in Hibernate
CVE-2026-50193High· 7.5jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193)
CVE-2026-54516Medium· 5.3jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties (CVE-2026-54516)