Back to Security Advisories
High 2026-07-17

Jackson-Annotations, Jackson-Core, Jackson-Databind, Jackson-Jaxrs-Providers, And Jackson-Modules-Base Security Update — AlmaLinux 9 (ALSA-2026:40895)

AlmaLinux 9

The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration. Security Fix(es): * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-545…

The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.

Security Fix(es):

* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-545…

Type:
security

Severity:
important

Release date:
2026-07-17

Description:
The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.

Security Fix(es):

* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
* jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
noarch pki-jackson-databind-2.21.4-1.el9_8.noarch.rpm 5d70286446cdb2416a754f1113a794c5cd48ff1bbec59db6163f2e5e2d29997b
noarch pki-jackson-jaxrs-providers-2.21.4-1.el9_8.noarch.rpm 645bff697f24f756541b9fc6a3c323c13ae54c4cdbe7efd9677c77e135267cd7
noarch pki-jackson-module-jaxb-annotations-2.21.4-1.el9_8.noarch.rpm 71839cc322908f26d651befd7abf661b8a1ac508e56bd55cd19f822c83dd21ba
noarch pki-jackson-core-2.21.4-1.el9_8.noarch.rpm 8435724b5a5b5e037898b15d17880d3c1202e1a82c9b8ef93d9a9bbef6c9c240
noarch pki-jackson-annotations-2.21-1.el9_8.noarch.rpm 8b9b129b1ac53f3c58858b72d8367e01a4bc7b489bec6695e97c6cfbbeb87942
noarch pki-jackson-jaxrs-json-provider-2.21.4-1.el9_8.noarch.rpm e5de871877caaca1638b95c9577c8b0cf3ad1757d1b62c2671288758b8402e31

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System