[security - high] jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
エラータID: AXSA:2026-1514:01
The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.
Security Fix(es):
* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
* jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-54512
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CVE-2026-54513
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Update packages.
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
N/A
SRPMS
- jackson-annotations-2.21-1.el9_8.src.rpm
MD5: f4c12a41440ad3ff16ffd3258a576811
SHA-256: df85a4b22e652f0b5494576870d4a0ca2a8237d6c5d02672177637cf5cd974d4
Size: 95.28 kB - jackson-core-2.21.4-1.el9_8.src.rpm
MD5: 082ce302e2017f54d1e7cba55c0ff2f9
SHA-256: db6c37e738b033c4c9090a20299fbae40d860e66d87fdcdbc3902da55357a226
Size: 1.20 MB - jackson-databind-2.21.4-1.el9_8.src.rpm
MD5: 59f3c7f11052a579721ae7475281e6b0
SHA-256: 3f3dafe442c975d9c687bd5fa519846ce9e40cc19b84c11b6dedfc46e2a614be
Size: 1.70 MB - jackson-jaxrs-providers-2.21.4-1.el9_8.src.rpm
MD5: 337811fb7fd7ea71b09d95f8c71764ad
SHA-256: 6c0cc3134a865da6f28099af76e663d8b0de2abbcde900e6916635e85a1f515a
Size: 1.87 MB - jackson-modules-base-2.21.4-1.el9_8.src.rpm
MD5: f1f99f132ffda439741f0c03004e2ce5
SHA-256: af0f0e08dcb99b4914c665fd7149a6b760e1d9d3745dc2465dcf9769a331aaaa
Size: 2.26 MB
Asianux Server 9 for x86_64
- pki-jackson-annotations-2.21-1.el9_8.noarch.rpm
MD5: 7800d20f71679b0cb60eb61efebbf96d
SHA-256: fd3f5265d7b0a13646761788fa368b5a5c8ddd2d592fc84b638ec7b36e0d9a02
Size: 82.69 kB - pki-jackson-core-2.21.4-1.el9_8.noarch.rpm
MD5: c72812f12fdc0ce89da1bd66f2fb4dcb
SHA-256: ae998c91e9a8b51c0cbedef4772e2977806f8d1e52f0ab4430ecc1fb81b89e48
Size: 461.03 kB - pki-jackson-databind-2.21.4-1.el9_8.noarch.rpm
MD5: 0f2aabe4f22eb6fd4660a43a914c5860
SHA-256: 3670564f54159602075bec20bb6511667530c602106a4b33dc65f9312700e27f
Size: 1.60 MB - pki-jackson-jaxrs-json-provider-2.21.4-1.el9_8.noarch.rpm
MD5: 35808956c9f4b1afd0325ef5210bc376
SHA-256: 125d198625a38137caec94ab95d4507ef970ff7e84ac21233b74fff0254db32f
Size: 21.20 kB - pki-jackson-jaxrs-providers-2.21.4-1.el9_8.noarch.rpm
MD5: 133eb4afd26df47bdfa11c5fd1879c60
SHA-256: 27b6d6fd996cf52e7c79c2898d25a3fdc85d2185794ccf64af34deeed2db8fff
Size: 47.36 kB - pki-jackson-module-jaxb-annotations-2.21.4-1.el9_8.noarch.rpm
MD5: fa19fd4675d0e6e21ec9cf338fd22996
SHA-256: 423d44611cc57caf21ebc76d412363dacf65ada9b9efd7943e897a203d1eebf1
Size: 46.63 kB