CVE-2026-54512 Details
Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
A vulnerability in the Jackson Databind library's Polymorphic Type Validator (PTV) allows for a bypass of safety mechanisms during polymorphic deserialization. This issue is present in Jackson Databind versions 2.10.0 prior to 2.18.8, 2.21.4, and 3.0.0 prior to 3.1.4. The vulnerability arises because the PTV only validates the raw container class name against an allow-list, without checking nested generic type arguments. As a result, an attacker can exploit this by injecting a denied class as a generic parameter of an allowed container type, leading to unauthorized class instantiation with attacker-controlled data. This vulnerability is particularly concerning in applications that deserialize untrusted JSON and rely on PTV for security.
Users can upgrade to Jackson Databind versions 2.18.8, 2.21.4, or 3.1.4, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm | CISA-ADP | ExploitVendor Advisory |
| https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5 | [email protected] | Patch |
| https://github.com/FasterXML/jackson-databind/issues/5988 | [email protected] | Issue TrackingPatch |
| https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-184 | Incomplete List of Disallowed Inputs | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fasterxml jackson-databind | >= 2.10.0, < 2.18.8 >= 2.19.0, < 2.21.4 >= 3.0.0, < 3.1.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 27, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |