Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-54513

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
Back to all
CVE

CVE-2026-54513

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

Summary

BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist.

Impact

Applications using BasicPolymorphicTypeValidator with allowIfSubTypeIsArray() as a safeguard get no protection for concrete array component types; an attacker controlling JSON can instantiate non-allowlisted types via an array wrapper, re-opening the gadget-instantiation risk PTV is meant to prevent.

Affected / Patched (verified via git tag --contains)

  • 2.18 line: >= 2.10.0, < 2.18.8 -> fixed in 2.18.8
  • 2.19-2.21 line: >= 2.19.0, < 2.21.4 -> fixed in 2.21.4
  • 3.x line: >= 3.0.0, < 3.1.4 -> fixed in 3.1.4

PolymorphicTypeValidator was added in 2.10.0 so vulnerability N/A for versions prior to that.

Severity / CWE

Maintainer: significant. Reporter: HIGH. CWE-184 (Incomplete List of Disallowed Inputs); related CWE-502.

Upstream fix

FasterXML/jackson-databind#5981; fix PR #5983 (24529da), 2.18 backport PR #5984 (01d1692). Released 2026-06-04 in 2.18.8 / 2.21.4 / 3.1.4.

Credits

Omkhar Arasaratnam (@omkhar) - finder.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
8.1
-
3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
8.1
-
3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Related Resources

No items found.

References

https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f, https://nvd.nist.gov/vuln/detail/CVE-2026-54513, https://github.com/FasterXML/jackson-databind/issues/5983, https://github.com/FasterXML/jackson-databind/issues/5981, https://github.com/FasterXML/jackson-databind/pull/5984, https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e, https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5, https://access.redhat.com/errata/RHSA-2026:50849, https://access.redhat.com/errata/RHSA-2026:54435, https://access.redhat.com/errata/RHSA-2026:54622, https://access.redhat.com/errata/RHSA-2026:62260, https://access.redhat.com/errata/RHSA-2026:66488, https://access.redhat.com/errata/RHSA-2026:66545, https://access.redhat.com/security/cve/CVE-2026-54513, https://bugzilla.redhat.com/show_bug.cgi?id=2492010, https://github.com/FasterXML/jackson-databind, https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json, https://access.redhat.com/errata/RHSA-2026:36839, https://access.redhat.com/errata/RHSA-2026:40895, https://access.redhat.com/errata/RHSA-2026:41951, https://access.redhat.com/errata/RHSA-2026:43218, https://access.redhat.com/errata/RHSA-2026:43400, https://access.redhat.com/errata/RHSA-2026:44061, https://access.redhat.com/errata/RHSA-2026:44062, https://access.redhat.com/errata/RHSA-2026:44063, https://access.redhat.com/errata/RHSA-2026:44064, https://access.redhat.com/errata/RHSA-2026:44065, https://access.redhat.com/errata/RHSA-2026:44066, https://access.redhat.com/errata/RHSA-2026:44271, https://access.redhat.com/errata/RHSA-2026:48095, https://access.redhat.com/errata/RHSA-2026:48151, https://access.redhat.com/errata/RHSA-2026:50846, https://access.redhat.com/errata/RHSA-2026:50847, https://access.redhat.com/errata/RHSA-2026:50848

Severity

8.1

CVSS Score
0
10

Basic Information

Base CVSS
8.1
EPSS Probability
0.00892%
EPSS Percentile
0.57418%
Introduced Version
2.10.0,3.0.0,3.0.0-rc1,2.19.0-rc2,2.10.1,2.10.0.pr1,0
Fix Available
2.18.8,3.1.4,2.21.4,2.0.0-r3,3.3.0-r3,0.27.1-r5,5.19.8-r1,6.1.8-r8,6.2.7-r1,6.1.8-r11,4.18.1-r6,2.18.1-r2,2.11.0-r6,4.0.11-r4,4.2.3-r1,4.2.2-r4,2.9.4-r17,3.0.0-r27,3.1.0-r33,3.2.3-r13,3.3.1-r5,2.9.4-r9,3.0.0-r9,3.1.0-r11,3.2.3-r9,3.3.1-r2,10.1.5-r1,3.3.0-r6,4.0.20-r1,4.1.11-r1,5.0.8-r7,4.0.20-r3,5.0.8-r2,4.2.5-r3,0.5.4-r28,0.6.3-r9,8.19.19-r0,9.3.8-r0,9.4.4-r0,3.31.0-r1,7.6.9-r6,8.4.0.253-r2,8.4.0.253-r1,4.14.2-r3,5.0.2-r1,37.0.0-r19,8.19.17-r1,9.2.8-r13,9.4.5-r3,9.5.2-r6,9.4.5-r5,9.5.2-r5,13.0.0-r1,12.9.0-r1,2.27.5-r14,2.28.4-r3,3.0.0-r1,8.14.5-r1,9.6.1-r1,1.6.0-r10,3.3.6-r14,3.3.6-r23,3.5.0-r8,2.7.0-r26,15.0.22-r13,15.1.7-r24,15.2.6-r22,16.0.13-r2,16.1.4-r5,2.572-r0,2.555.3-r2,2.568.1-r2,2.15.0-r4,5.6.3-r2,1.5.0-r3,1.5.0-r2,3.7.2-r57,3.8.1-r57,3.9.2-r8,4.0.2-r4,4.1.2-r3,4.2.1-r3,4.3.1-r1,1.0.0-r7,1.0.0-r4,4.1.2-r4,2025.4.6-r4,2026.0.4-r6,2026.1.1-r2,2025.4.6-r1,2026.0.4-r3,26.6.4-r1,6.5.1-r5,1.21.4-r9,1.22.1-r10,1.21.4-r2,1.22.1-r6,0.12.0-r36,0.5.4-r0,4.14.0-r16,9.4.2-r7,9.4.2-r6,0.1.122-r1,3.2.2-r3,3.2.2-r1,2026.05.0-r6,5.26.27-r3,26.04.4-r1,2023.40-r8,5.5.0-r11,5.5.0-r7,2.19.6-r2,3.7.0-r13,3.7.0-r12,1.5.1-r1,3.5.28-r5,26.4.7-r19,26.5.7-r9,0.5.2-r0,0.5.0-r1,3.2.0-r3,3.2.0-r4,3.3.8-r2,3.8.4-r6,2.6.0-r19,10.0.0-r6,9.10.1-r10,26.8.0.126808-r1,3.5.8-r16,4.0.3-r2,4.1.3-r3,4.2.0-r8,3.5.8-r4,0.9.0-r4,0.9.0-r3,2.0.6-r5,1.0.1-r2,1.0.1-r1,0.10.5-r17,4.3.1.2-r12,482-r0,13.9-r21,4.14.5-r4,7.3.0-r3,3.6.1-r15,3.8.6-r8,3.9.5-r8,3.9.5-r5

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading