Bug 2492015 (CVE-2026-54512) - CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
Summary: CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution v...
Keywords:
Status: NEW
Alias: CVE-2026-54512
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2495203 2495205 2495206 2495209 2495210 2495211 2495212 2495213 2495204 2495207 2495208
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-23 22:02 UTC by OSIDB Bzimport
Modified: 2026-08-04 17:37 UTC (History)
140 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:36839 0 None None None 2026-07-08 18:28:44 UTC
Red Hat Product Errata RHSA-2026:40895 0 None None None 2026-07-16 11:56:48 UTC
Red Hat Product Errata RHSA-2026:41951 0 None None None 2026-07-20 11:57:15 UTC
Red Hat Product Errata RHSA-2026:43400 0 None None None 2026-07-22 10:18:24 UTC
Red Hat Product Errata RHSA-2026:44061 0 None None None 2026-07-23 01:03:57 UTC
Red Hat Product Errata RHSA-2026:44062 0 None None None 2026-07-23 00:43:07 UTC
Red Hat Product Errata RHSA-2026:44063 0 None None None 2026-07-23 00:45:05 UTC
Red Hat Product Errata RHSA-2026:44064 0 None None None 2026-07-23 01:28:34 UTC
Red Hat Product Errata RHSA-2026:44065 0 None None None 2026-07-23 01:09:36 UTC
Red Hat Product Errata RHSA-2026:44066 0 None None None 2026-07-23 01:22:02 UTC
Red Hat Product Errata RHSA-2026:44271 0 None None None 2026-07-23 06:31:31 UTC
Red Hat Product Errata RHSA-2026:48151 0 None None None 2026-07-29 19:53:47 UTC

Description OSIDB Bzimport 2026-06-23 22:02:12 UTC
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

Comment 2 Abhishek Raj 2026-07-03 09:02:52 UTC Comment hidden (spam)
Comment 3 errata-xmlrpc 2026-07-08 18:28:37 UTC
This issue has been addressed in the following products:

  Red Hat Build of Apache Camel 4.18 for Quarkus 3.33

Via RHSA-2026:36839 https://access.redhat.com/errata/RHSA-2026:36839

Comment 7 Abhishek Raj 2026-07-16 07:33:10 UTC
updated

Comment 9 errata-xmlrpc 2026-07-16 11:56:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:40895 https://access.redhat.com/errata/RHSA-2026:40895

Comment 10 errata-xmlrpc 2026-07-20 11:57:08 UTC
This issue has been addressed in the following products:

  Red Hat Data Grid 8.6.2

Via RHSA-2026:41951 https://access.redhat.com/errata/RHSA-2026:41951

Comment 11 errata-xmlrpc 2026-07-22 10:18:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:43400 https://access.redhat.com/errata/RHSA-2026:43400

Comment 12 errata-xmlrpc 2026-07-23 00:42:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:44062 https://access.redhat.com/errata/RHSA-2026:44062

Comment 13 errata-xmlrpc 2026-07-23 00:44:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:44063 https://access.redhat.com/errata/RHSA-2026:44063

Comment 14 errata-xmlrpc 2026-07-23 01:03:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:44061 https://access.redhat.com/errata/RHSA-2026:44061

Comment 15 errata-xmlrpc 2026-07-23 01:09:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:44065 https://access.redhat.com/errata/RHSA-2026:44065

Comment 16 errata-xmlrpc 2026-07-23 01:21:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:44066 https://access.redhat.com/errata/RHSA-2026:44066

Comment 17 errata-xmlrpc 2026-07-23 01:28:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:44064 https://access.redhat.com/errata/RHSA-2026:44064

Comment 18 errata-xmlrpc 2026-07-23 06:31:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:44271 https://access.redhat.com/errata/RHSA-2026:44271

Comment 19 errata-xmlrpc 2026-07-29 19:53:39 UTC
This issue has been addressed in the following products:

  Cryostat 4 on RHEL 9

Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151


Note You need to log in before you can comment on or make changes to this bug.