Junglewise Threat Intelligence

CVE-2026-54512: FasterXML jackson-databind PolymorphicTypeValidator bypass via generic types

CVE-2026-54512 · Severity: high · CVSS 8.1 · Published 2026-06-23

Technologies: FasterXML, tools.jackson.core Jackson Databind. Vendors: FasterXML.

Executive brief

A vulnerability in the Jackson data-processing library allows attackers to bypass security filters designed to prevent the loading of malicious code. By disguising unauthorized Java classes inside allowed data containers (like lists or maps), an attacker can force the application to execute unintended actions. This can lead to full system compromise, unauthorized data access, or service disruption if the application processes untrusted JSON data.

Technical details

A deserialization vulnerability exists in jackson-databind's PolymorphicTypeValidator (PTV) due to incomplete validation of generic type parameters. When polymorphic typing is enabled, the 'DatabindContext._resolveAndValidateGeneric()' method validates only the raw container class (e.g., java.util.ArrayList) against the PTV allow-list, failing to inspect nested type arguments. An attacker can provide a type identifier containing a malicious 'gadget' class as a generic parameter (e.g., ArrayList<EvilGadget>), which the validator ignores. This results in the instantiation and property population of the unauthorized class, potentially leading to remote code execution (RCE) if exploitable classes are present on the classpath. The issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4 by implementing recursive validation of type parameters.

Affected products

  • FasterXML jackson-databind >= 2.10.0, < 2.18.8
  • FasterXML jackson-databind >= 2.19.0, < 2.21.4
  • FasterXML, tools.jackson.core jackson-databind >= 3.0.0, < 3.1.4

Timeline

  • 2026-05-11: other: Fix implemented in source code
  • 2026-06-16: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published to NVD

References

Related threats