Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

github логотип

GHSA-rmj7-2vxq-3g9f

около 1 месяца назад

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-54513

около 1 месяца назад

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-54513

около 1 месяца назад

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-54513

около 1 месяца назад

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-54513

около 1 месяца назад

jackson-databind contains the general-purpose data-binding functionali ...

CVSS3: 8.1
EPSS: Низкий
rocky логотип

RLSA-2026:43218

9 дней назад

Important: pki-deps:10.6 security update

EPSS: Низкий
rocky логотип

RLSA-2026:43400

8 дней назад

Important: dogtag-pki security update

EPSS: Низкий
rocky логотип

RLSA-2026:40895

14 дней назад

Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-43400

8 дней назад

ELSA-2026-43400: dogtag-pki security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-40895

11 дней назад

ELSA-2026-40895: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21201-1

около 1 месяца назад

Security update for jackson-annotations, jackson-core, jackson-databind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2801-1

23 дня назад

Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-rmj7-2vxq-3g9f

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

CVSS3: 8.1
1%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-54513

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

CVSS3: 8.1
1%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-54513

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

CVSS3: 8.1
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-54513

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

CVSS3: 8.1
1%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-54513

jackson-databind contains the general-purpose data-binding functionali ...

CVSS3: 8.1
1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:43218

Important: pki-deps:10.6 security update

1%
Низкий
9 дней назад
rocky логотип
RLSA-2026:43400

Important: dogtag-pki security update

8 дней назад
rocky логотип
RLSA-2026:40895

Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update

14 дней назад
oracle-oval логотип
ELSA-2026-43400

ELSA-2026-43400: dogtag-pki security update (IMPORTANT)

8 дней назад
oracle-oval логотип
ELSA-2026-40895

ELSA-2026-40895: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update (IMPORTANT)

11 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21201-1

Security update for jackson-annotations, jackson-core, jackson-databind

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2801-1

Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent

23 дня назад

Уязвимостей на страницу