THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-54513 (HIGH 8.1) — jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(),

[NVD] CVE-2026-54513 (HIGH 8.1) — jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(),

lownvdPublished 2026-06-23

CVE-2026-54513 CVSS: 8.1 HIGH Published: 2026-06-23T21:17:02.333

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) typ

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54513