Deserialization of Untrusted Data in jackson-databind - CVE-2026-54512
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to instantiate arbitrary classes.
The vulnerability exists due to deserialization of untrusted data in DatabindContext._resolveAndValidateGeneric() and PolymorphicTypeValidator handling when processing polymorphic type identifiers with generic parameters during deserialization. A remote attacker can supply a specially crafted type identifier and JSON data to instantiate arbitrary classes.
Only applications that accept untrusted JSON and have polymorphic typing enabled while relying on a configured PolymorphicTypeValidator allow-list are affected.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Development Tools Module
Basesystem Module
Fedora
Netezza Appliance
Db2 Bridge
CICS Transaction Gateway Desktop Edition
WebSphere Automation
Crucible Data Center
Crucible Server
Crowd Data Center
IBM Sterling Connect:Direct Web Services
IBM Common Licensing
IBM Maximo Application Suite - Manage Component
Red Hat build of Quarkus
IBM SPSS Collaboration and Deployment Services
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
jackson-dataformat-cbor
jackson-core
jackson-annotations
jackson-databind
jackson-annotations (Red Hat package)
jackson-parent
jackson-core (Red Hat package)
jackson-databind (Red Hat package)
jackson-jaxrs-providers (Red Hat package)
jackson-modules-base (Red Hat package)
jackson-bom
jackson-modules-base
jackson-jaxrs-providers
dogtag-pki (Red Hat package)
fasterxml-oss-parent
Red Hat Camel for Spring Boot
EntireX
JBoss Data Grid
How to mitigate CVE-2026-54512
Netezza Appliance - update to 1.0.2.0
Db2 Bridge - update to 1.1.5.1
WebSphere Automation - update to 1.13.0
Crucible Data Center - update to 4.9.13
Crucible Server - update to 4.9.13
Crowd Data Center - update to 7.2.2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.20, 6.4.0.9
IBM Common Licensing - update to 9.1
IBM Maximo Application Suite - Manage Component - addressed in versions 9.0.28, 9.1.20, 9.2.1
jackson-dataformat-cbor - update to 2.18.8-150200.3.21.3
jackson-core - update to 2.18.8-150200.3.22.3
jackson-annotations - update to 2.18.8-150200.3.22.3
jackson-databind - update to 2.18.8-150200.3.28.2
jackson-annotations (Red Hat package) - addressed in versions 2.21-1.el9_2, 2.21-1.el9_4, 2.21-1.el9_6, 2.21-1.el9_8
jackson-parent - update to 2.21-1.fc45
jackson-core (Red Hat package) - addressed in versions 2.21.4-1.el9_2, 2.21.4-1.el9_4, 2.21.4-1.el9_6, 2.21.4-1.el9_8
jackson-databind (Red Hat package) - addressed in versions 2.21.4-1.el9_2, 2.21.4-1.el9_4, 2.21.4-1.el9_6, 2.21.4-1.el9_8
jackson-jaxrs-providers (Red Hat package) - addressed in versions 2.21.4-1.el9_2, 2.21.4-1.el9_4, 2.21.4-1.el9_6, 2.21.4-1.el9_8
jackson-modules-base (Red Hat package) - addressed in versions 2.21.4-1.el9_2, 2.21.4-1.el9_4, 2.21.4-1.el9_6, 2.21.4-1.el9_8
jackson-databind - update to 2.21.5-1.fc45
jackson-bom - update to 2.21.5-1.fc45
jackson-modules-base - update to 2.21.5-1.fc45
jackson-jaxrs-providers - update to 2.21.5-1.fc45
jackson-core - update to 2.21.5-1.fc45
jackson-annotations - update to 2.21-6.fc45
Red Hat build of Quarkus - addressed in versions 3.27.4.SP2, 3.33.2.SP2
Red Hat Camel for Spring Boot - update to 4.18
IBM SPSS Collaboration and Deployment Services - addressed in versions 8.4.0.0 IF005, 8.5.0.0 IF005, 8.6.0.0 IF005
JBoss Data Grid - update to 8.6.2
dogtag-pki (Red Hat package) - addressed in versions 11.6.0-2.el10_0, 11.9.0-4.el10_2
EntireX - update to 12.1.0.0003-0779
fasterxml-oss-parent - update to 75-1.fc45
External References
Related Security Bulletins
- Multiple vulnerabilities in jackson-databind
- Fedora 45 update for fasterxml-oss-parent, jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-jaxrs-providers, jackson-modules-base, jackson-parent
- Red Hat Enterprise Linux 9 update for multiple packages
- Red Hat Enterprise Linux 10 update for dogtag-pki
- SUSE update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent
- Red Hat Enterprise Linux 8 update for the pki-deps:10.6 module
- Red Hat Enterprise Linux 8 update for the pki-deps:10.6 module
- Red Hat Enterprise Linux 9 update for multiple packages
- Red Hat Enterprise Linux 9 update for multiple packages
- Red Hat Enterprise Linux 9 update for multiple packages
- Red Hat Enterprise Linux 8 update for the pki-deps:10.6 module
- Red Hat Enterprise Linux 10 update for dogtag-pki
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM WebSphere Automation
- Multiple vulnerabilities in IBM EntireX
- Multiple vulnerabilities in IBM Db2 Bridge
- Multiple vulnerabilities in IBM Maximo Application Suite - Manage Component
- Multiple vulnerabilities in IBM Netezza Appliance
- Multiple vulnerabilities in Red Hat build of Quarkus 3.27.4
- Multiple vulnerabilities in Red Hat build of Quarkus 3.33.2
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4
- Multiple vulnerabilities in JBoss Data Grid 8.6
- Multiple vulnerabilities in Crucible Data Center and Crucible Server
- Multiple vulnerabilities in Crowd Data Center
- Multiple vulnerabilities in IBM Common Licensing