Fedora Account System
Red Hat Associate
Red Hat Customer
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
This issue has been addressed in the following products: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 Via RHSA-2026:36839 https://access.redhat.com/errata/RHSA-2026:36839
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:40895 https://access.redhat.com/errata/RHSA-2026:40895
This issue has been addressed in the following products: Red Hat Data Grid 8.6.2 Via RHSA-2026:41951 https://access.redhat.com/errata/RHSA-2026:41951
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:43218 https://access.redhat.com/errata/RHSA-2026:43218
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:43400 https://access.redhat.com/errata/RHSA-2026:43400
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:44062 https://access.redhat.com/errata/RHSA-2026:44062
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:44063 https://access.redhat.com/errata/RHSA-2026:44063
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:44061 https://access.redhat.com/errata/RHSA-2026:44061
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:44065 https://access.redhat.com/errata/RHSA-2026:44065
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:44066 https://access.redhat.com/errata/RHSA-2026:44066
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:44064 https://access.redhat.com/errata/RHSA-2026:44064
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:44271 https://access.redhat.com/errata/RHSA-2026:44271
This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151