CVE-2026-54518Medium· 6.5▾ SunlitA flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security view restrictions by sending specially crafted JSON (JavaScript Object Notation) data. The UnwrappedPropertyHandler component, which proce…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.4%
Last analysed / modified upstream
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security view restrictions by sending specially crafted JSON (JavaScript Object Notation) data. The UnwrappedPropertyHandler component, which processes unwrapped properties, incorrectly populates constructor parameters that should be hidden by an active security view. This can lead to unauthorized information disclosure or data manipulation.
jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass — rated Moderate by Red Hat. Released 2026-06-23, updated 2026-09-13.
Affected:
No fix planned:
Not affected:
Fix deferred
Workarounds / mitigations:
Affected packages:
com.fasterxml.jackson.core:jackson-databind >= 2.21.0, < 2.21.4tools.jackson.core:jackson-databind >= 3.0.0, < 3.1.4Patched in:
com.fasterxml.jackson.core:jackson-databind 2.21.4tools.jackson.core:jackson-databind 3.1.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54517Medium· 5.3jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application (CVE-2026-54517)
CVE-2026-56816High· 7.5io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 (CVE-2026-56816)
CVE-2026-59888Medium· 6.5com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records (CVE…
CVE-2026-45536Medium· 4.0netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message han…
CVE-2026-54514Medium· 5.3jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution (CVE-2026-54514)
CVE-2026-80110High· 8.1A flaw was found in pki-core