Jackson-Annotations, Jackson-Core, Jackson-Databind, Jackson-Jaxrs-Providers, And Jackson-Modules-Base Security Update — AlmaLinux 9 (ALSA-2026:40895)
The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration. Security Fix(es): * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-545…
The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.
Security Fix(es):
* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-545…
Security Fix(es):
* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
* jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| Architecture | Package | Checksum |
| noarch | pki-jackson-databind-2.21.4-1.el9_8.noarch.rpm | 5d70286446cdb2416a754f1113a794c5cd48ff1bbec59db6163f2e5e2d29997b |
| noarch | pki-jackson-jaxrs-providers-2.21.4-1.el9_8.noarch.rpm | 645bff697f24f756541b9fc6a3c323c13ae54c4cdbe7efd9677c77e135267cd7 |
| noarch | pki-jackson-module-jaxb-annotations-2.21.4-1.el9_8.noarch.rpm | 71839cc322908f26d651befd7abf661b8a1ac508e56bd55cd19f822c83dd21ba |
| noarch | pki-jackson-core-2.21.4-1.el9_8.noarch.rpm | 8435724b5a5b5e037898b15d17880d3c1202e1a82c9b8ef93d9a9bbef6c9c240 |
| noarch | pki-jackson-annotations-2.21-1.el9_8.noarch.rpm | 8b9b129b1ac53f3c58858b72d8367e01a4bc7b489bec6695e97c6cfbbeb87942 |
| noarch | pki-jackson-jaxrs-json-provider-2.21.4-1.el9_8.noarch.rpm | e5de871877caaca1638b95c9577c8b0cf3ad1757d1b62c2671288758b8402e31 |
How to Apply the Fix
Update the affected packages on your server to the patched release, then restart the relevant services.
sudo dnf update
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System