High [CVE-2026-54513] Security bypass allows arbitrary code execution
This high-severity Red Hat Linux advisory covers CVE-2026-54513 affecting AMQ Clients 2026.Q3, Cryostat 4 on RHEL 9, Red Hat AMQ Broker 7.13.6.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.
Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted.
When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types.
By sending specially crafted input, an attacker can force the system to process untrusted data, which may lead to the execution of malicious code. This could result in a complete compromise of the affected system, impacting its confidentiality, integrity, and availability.
This Important flaw in `jackson-databind` allows for a security bypass, enabling arbitrary code execution.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
- 2.18.8
- 2.21.4
- 3.1.4
- jackson-databind
- cryostat/cryostat-reports-rhel9:4.2.0-13
- cryostat/cryostat-rhel9:4.2.0-13
- cryostat/jfr-datasource-rhel9:4.2.0-13
- rhbk/keycloak-operator-bundle:26.4.14-1
- rhbk/keycloak-rhel9:26.4-22
- rhbk/keycloak-rhel9-operator:26.4-22
- rhbk/keycloak-rhel9-operator
- rhbk-openshift-rhel9/rhbk-openshift-rhel9
- rhbk-rhel9-operator/rhbk-rhel9-operator
- rhbk/keycloak-operator-bundle:26.6.5-1
- rhbk/keycloak-rhel9:26.6-11
- rhbk/keycloak-rhel9-operator:26.6-11
- rhbk/keycloak-rhel9
- redhat-pki:10-8100020260728001635.f9354743
- dogtag-pki-0:11.9.0-4.el10_2
- dogtag-pki-0:11.6.0-2.el10_0
- pki-deps:10.6-8100020260714102233.489197e6
- pki-deps:10.6-8040020260720064222.522a0ee4
- pki-deps:10.6-8060020260720025549.ad008a3a
- pki-deps:10.6-8080020260714161755.63b34585
- jackson-databind-0:2.21.4-1.el9_8
- jackson-databind-0:2.21.4-1.el9_2
- jackson-databind-0:2.21.4-1.el9_4
- jackson-databind-0:2.21.4-1.el9_6
- eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el10eap
- eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el10eap
- eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el10eap
- eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el10eap
- eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el10eap
- eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el10eap
- eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el10eap
- eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el10eap
- eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el10eap
- eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el10eap
- eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el10eap
- eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el10eap
- eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el10eap
- eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el10eap
- eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el10eap
- RHSA-2026:69459
- RHSA-2026:48151
- RHSA-2026:66545
- RHSA-2026:66488
- RHSA-2026:54622
- RHSA-2026:50847
- RHSA-2026:50846
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
Mitigation checklist
- Upgrade to version 2.18.8, 2.21.4, or 3.1.4 or later to address this vulnerability. If upgrading is not immediately possible, remove BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() from the application’s ObjectMapper configuration to eliminate the affected deserialization path. Rebuild and restart the application to apply the configuration change. As an additional mitigation, disable polymorphic deserialization of untrusted data where possible by avoiding or removing default typing features such as activateDefaultTyping() or enableDefaultTyping(). When polymorphic deserialization is required, restrict allowed subtypes using a strict whitelist of trusted application packages and avoid broad or permissive type validation rules.
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.