Bug 2492015 (CVE-2026-54512)

Summary: CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aakkiang, aazores, abrianik, alinfoot, anthomas, ant, anujha, aschwart, asoldano, asyoung, aszczucz, ataylor, avibelli, bbaranow, bbrownin, bgeorges, bmaxwell, boliveir, bstansbe, ccranfor, cescoffi, cfu, chfoley, cmah, dandread, dbruscin, dfreiber, dhanak, dkreling, dlofthou, drichtar, drosa, drow, dschmidt, dsimansk, dtrifiro, eaguilar, ebaron, edewata, ehelms, ehugonne, ewittman, fmariani, fmongiar, gbenhaim, ggainey, ggrzybek, gkimetto, gmalinko, gsmet, gtanzill, istudens, ivassile, iweiss, janstey, jburrell, jbuscemi, jhollowa, jkoehler, jlanda, jmagne, jmartisk, jmatsuok, jnethert, jolong, jpasqual, jpechane, jraez, jtolenti, juwatts, jwon, kaycoth, kgaikwad, kingland, kshier, kvanderr, lphiri, lthon, manderse, mcarlett, mdellweg, mfargett, mhulan, mnovotny, mosmerov, mposolda, msvehla, nipatil, niyer, nmoumoul, nwallace, olubyans, osousa, pantinor, parichar, pberan, pcreech, pdelbell, pesilva, pgallagh, pjindal, pmackay, prichard, prisingh, probinso, rbryant, rchan, rgodfrey, rguimara, rhel-process-autobot, rkubis, rmartinc, rruss, rstancel, rstepani, rsvoboda, sausingh, sbiarozk, sdawley, simaishi, skhandel, smallamp, snegrini, ssilvert, stcannon, sthirugn, sthorger, swoodman, taherrin, tasato, tcunning, teagle, thjenkin, tmalecek, tqvarnst, twaugh, vdosoudi, vkumar, vmuzikar, watson-tool-maintainers, weaton, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious type ID, an attacker can place a denied class as a generic type parameter of an allowed container. This leads to the loading and instantiation of arbitrary classes, potentially resulting in arbitrary code execution.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2495203, 2495206, 2495210, 2495211, 2495212, 2495213, 2495204, 2495205, 2495207, 2495208, 2495209    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-23 22:02:12 UTC
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

Comment 2 Abhishek Raj 2026-07-03 09:02:52 UTC Comment hidden (spam)
Comment 3 errata-xmlrpc 2026-07-08 18:28:37 UTC
This issue has been addressed in the following products:

  Red Hat Build of Apache Camel 4.18 for Quarkus 3.33

Via RHSA-2026:36839 https://access.redhat.com/errata/RHSA-2026:36839

Comment 7 Abhishek Raj 2026-07-16 07:33:10 UTC
updated

Comment 9 errata-xmlrpc 2026-07-16 11:56:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:40895 https://access.redhat.com/errata/RHSA-2026:40895

Comment 10 errata-xmlrpc 2026-07-20 11:57:08 UTC
This issue has been addressed in the following products:

  Red Hat Data Grid 8.6.2

Via RHSA-2026:41951 https://access.redhat.com/errata/RHSA-2026:41951

Comment 11 errata-xmlrpc 2026-07-22 10:18:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:43400 https://access.redhat.com/errata/RHSA-2026:43400

Comment 12 errata-xmlrpc 2026-07-23 00:42:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:44062 https://access.redhat.com/errata/RHSA-2026:44062

Comment 13 errata-xmlrpc 2026-07-23 00:44:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:44063 https://access.redhat.com/errata/RHSA-2026:44063

Comment 14 errata-xmlrpc 2026-07-23 01:03:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:44061 https://access.redhat.com/errata/RHSA-2026:44061

Comment 15 errata-xmlrpc 2026-07-23 01:09:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:44065 https://access.redhat.com/errata/RHSA-2026:44065

Comment 16 errata-xmlrpc 2026-07-23 01:21:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:44066 https://access.redhat.com/errata/RHSA-2026:44066

Comment 17 errata-xmlrpc 2026-07-23 01:28:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:44064 https://access.redhat.com/errata/RHSA-2026:44064

Comment 18 errata-xmlrpc 2026-07-23 06:31:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:44271 https://access.redhat.com/errata/RHSA-2026:44271

Comment 19 errata-xmlrpc 2026-07-29 19:53:39 UTC
This issue has been addressed in the following products:

  Cryostat 4 on RHEL 9

Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151

Comment 22 errata-xmlrpc 2026-08-13 14:51:04 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 4.18.3 for Spring Boot 3.5.16

Via RHSA-2026:54622 https://access.redhat.com/errata/RHSA-2026:54622

Comment 23 errata-xmlrpc 2026-09-03 22:01:33 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:63386 https://access.redhat.com/errata/RHSA-2026:63386

Comment 24 errata-xmlrpc 2026-09-03 22:57:11 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:63387 https://access.redhat.com/errata/RHSA-2026:63387

Comment 25 errata-xmlrpc 2026-09-03 22:58:16 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:63327 https://access.redhat.com/errata/RHSA-2026:63327

Comment 26 errata-xmlrpc 2026-09-10 16:36:40 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Broker 7.14.1

Via RHSA-2026:66488 https://access.redhat.com/errata/RHSA-2026:66488

Comment 27 errata-xmlrpc 2026-09-10 23:24:42 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Broker 7.13.6

Via RHSA-2026:66545 https://access.redhat.com/errata/RHSA-2026:66545

Comment 28 Jon Orris 2026-09-17 17:44:29 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4.25

Via RHSA-2026:53806 https://access.redhat.com/errata/RHSA-2026:53806

Comment 29 Jon Orris 2026-09-17 17:45:36 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9

Via RHSA-2026:53646 https://access.redhat.com/errata/RHSA-2026:53646

Comment 30 Jon Orris 2026-09-17 17:46:05 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7

Via RHSA-2026:53644 https://access.redhat.com/errata/RHSA-2026:53644

Comment 31 Jon Orris 2026-09-21 14:40:38 UTC
This issue has been addressed in the following products:

  AMQ Clients 2026.Q3

Via RHSA-2026:69459 https://access.redhat.com/errata/RHSA-2026:69459

Comment 32 Jon Orris 2026-09-22 12:56:45 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8

Via RHSA-2026:70228 https://access.redhat.com/errata/RHSA-2026:70228

Comment 33 Jon Orris 2026-09-22 12:59:10 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10

Via RHSA-2026:70230 https://access.redhat.com/errata/RHSA-2026:70230

Comment 34 Jon Orris 2026-09-22 13:01:20 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9

Via RHSA-2026:70229 https://access.redhat.com/errata/RHSA-2026:70229

Comment 35 Jon Orris 2026-09-22 15:36:20 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1

Via RHSA-2026:70277 https://access.redhat.com/errata/RHSA-2026:70277