CVE-2026-54513Disclosure(fasterxml / jackson-databind)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jackson-databind

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
jackson-databind

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-23: 2Technical Details · 2026-06-23: 206-23
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-54513 Polymorphic Type Validator Bypass in jackson-databind Array Type ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-54513 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The text announces a new CVE (2026‑54513) affecting jackson-databind with a polymorphic type validator bypass and provides a link for additional details.

    0000093
    4.1K followersView on X
  • DailyCVE@dailycve
    General

    🔴 Jackson-databind, Array Subtype Allowlist Bypass, #CVE-2026-54513 (High) -DC-Jun2026-605 https://dailycve.com/jackson-databind-array-subtype-allowlist-bypass-cve-2026-54513-high-dc-jun2026-605/

    Post summary

    The post announces a new high‑severity vulnerability (CVE-2026-54513) in Jackson-databind that allows bypassing the array subtype allowlist. No evidence of PoC, exploit availability, active exploitation, or remediation is provided.

    0000044
    216 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfasterxmljackson-databind---

Explore more