CVE-2026-54513: jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
Summary BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist.
Impact Applications using BasicPolymorphicTypeValidator with allowIfSubTypeIsArray() as a safeguard get no protection for concrete array component types; an attacker controlling JSON can instantiate non-allowlisted types via an array wrapper, re-opening the gadget-instantiation risk PTV is meant to prevent.
Affected / Patched (verified via git tag --contains) - 2.18 line: >= 2.10.0, < 2.18.8 -> fixed in 2.18.8 - 2.19-2.21 line: >= 2.19.0, < 2.21.4 -> fixed in 2.21.4 - 3.x line: >= 3.0.0, < 3.1.4 -> fixed in 3.1.4
PolymorphicTypeValidator was added in 2.10.0 so vulnerability N/A for versions prior to that.
Severity / CWE Maintainer: significant. Reporter: HIGH. CWE-184 (Incomplete List of Disallowed Inputs); related CWE-502.
Upstream fix FasterXML/jackson-databind#5981; fix PR #5983 (24529da), 2.18 backport PR #5984 (01d1692). Released 2026-06-04 in 2.18.8 / 2.21.4 / 3.1.4.
Credits Omkhar Arasaratnam (@omkhar) - finder.
Other sources
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/tools.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 3.1.4 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 3.1.4 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.21.4 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.18.8 - Upgrade
Upgrade
jackson-databindto a version that resolves this vulnerability.Fixed in 2.18.8Patch FasterXML/jackson-databind#5981 - Upgrade
Upgrade
jackson-databindto a version that resolves this vulnerability.Fixed in 2.21.4Patch FasterXML/jackson-databind#5981 - Upgrade
Upgrade
jackson-databindto a version that resolves this vulnerability.Fixed in 3.1.4Patch FasterXML/jackson-databind#5981
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54513?
CVE-2026-54513 has a high severity score of 8.1.
How do I fix CVE-2026-54513?
To fix CVE-2026-54513, upgrade jackson-databind to a version that is not affected, such as versions 2.18.9, 2.21.5, or 3.1.5 and later.
What systems are affected by CVE-2026-54513?
CVE-2026-54513 affects jackson-databind versions from 2.10.0 through 2.18.8, 2.21.4, and 3.1.4.
What is the impact of CVE-2026-54513?
The impact of CVE-2026-54513 is a potential bypass of the array subtype allowlist, which may lead to security vulnerabilities.
Who should be concerned about CVE-2026-54513?
Developers and organizations using the jackson-databind library should be concerned about CVE-2026-54513 due to its high severity and potential for exploitation.