PT-2026-51596 · Unknown+1 · Jackson-Databind+1

·

CVE-2026-54513

·

Published

2026-06-23

·

Updated

2026-08-31

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jackson-databind versions 2.10.0 through 2.18.7 jackson-databind versions 2.19.0 through 2.21.3 jackson-databind versions 3.0.0 through 3.1.3
Description The BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() function allowlists any array type based solely on clazz.isArray(), failing to validate the array's component type against the configured allowlist. This allows an attacker who controls JSON input to instantiate non-allowlisted types via an array wrapper, bypassing the protections intended by the Polymorphic Type Validator (PTV) and re-introducing the risk of gadget instantiation. This occurs because when Jackson deserializes elements without per-element type IDs, it instantiates the component type directly without further PTV checks.
Recommendations Update to version 2.18.8 Update to version 2.21.4 Update to version 3.1.4

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:40895
ALSA-2026:43218
ALSA-2026:43400
CLEANSTART-2026-BK55944
CLEANSTART-2026-DH82894
CLEANSTART-2026-FV79231
CLEANSTART-2026-LB41442
CLEANSTART-2026-NM00046
CLEANSTART-2026-SH44648
CLEANSTART-2026-WT54034
CVE-2026-54513
ECHO-5950-3CA7-8A02
GHSA-RMJ7-2VXQ-3G9F
OPENSUSE-SU-2026:11118-1
OPENSUSE-SU-2026:21201-1
RHSA-2026:40895
RHSA-2026:43218
RHSA-2026:43400
RHSA-2026:44061
RHSA-2026:44062
RHSA-2026:44063
RHSA-2026:44064
RHSA-2026:44065
RHSA-2026:44066
RHSA-2026:44271
SUSE-SU-2026:22504-1
SUSE-SU-2026:2801-1

Affected Products

Rocky Linux
Jackson-Databind