Red Hat Security Advisory: pki-deps:10.6 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-54513 — jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
🎯 Affected products56
- Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-collections-0:3.2.2-10.module+el8.10.0+20993+d0f024b0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-collections-0:3.2.2-10.module+el8.10.0+20993+d0f024b0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-lang-0:2.6-21.module+el8.10.0+20993+d0f024b0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-lang-0:2.6-21.module+el8.10.0+20993+d0f024b0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-net-0:3.6-3.module+el8.10.0+20993+d0f024b0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-net-0:3.6-3.module+el8.10.0+20993+d0f024b0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bea-stax-0:1.2.0-16.module+el8.10.0+20993+d0f024b0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bea-stax-api-0:1.2.0-16.module+el8.10.0+20993+d0f024b0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-fastinfoset-0:1.2.13-9.module+el8.10.0+20993+d0f024b0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-fastinfoset-0:1.2.13-9.module+el8.10.0+20993+d0f024b0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-0:2.2.11-12.module+el8.10.0+20993+d0f024b0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-api-0:2.2.12-8.module+el8.10.0+21035+a01f6469.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-api-0:2.2.12-8.module+el8.10.0+21035+a01f6469.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-core-0:2.2.11-12.module+el8.10.0+20993+d0f024b0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-runtime-0:2.2.11-12.module+el8.10.0+20993+d0f024b0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-txw2-0:2.2.11-12.module+el8.10.0+20993+d0f024b0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-annotations-0:2.21-1.module+el8.10.0+24523+f75fb079.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-annotations-0:2.21-1.module+el8.10.0+24523+f75fb079.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-core-0:2.21.4-1.module+el8.10.0+24523+f75fb079.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-core-0:2.21.4-1.module+el8.10.0+24523+f75fb079.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-databind-0:2.21.4-1.module+el8.10.0+24523+f75fb079.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-databind-0:2.21.4-1.module+el8.10.0+24523+f75fb079.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-jaxrs-json-provider-0:2.21.4-1.module+el8.10.0+24523+f75fb079.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-jaxrs-providers-0:2.21.4-1.module+el8.10.0+24523+f75fb079.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-jaxrs-providers-0:2.21.4-1.module+el8.10.0+24523+f75fb079.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-module-jaxb-annotations-0:2.21.4-2.module+el8.10.0+24523+f75fb079.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-modules-base-0:2.21.4-2.module+el8.10.0+24523+f75fb079.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jakarta-commons-httpclient-1:3.1-28.module+el8.10.0+20993+d0f024b0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jakarta-commons-httpclient-1:3.1-28.module+el8.10.0+20993+d0f024b0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +26 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Upgrade to version 2.18.8, 2.21.4, or 3.1.4 or later to address this vulnerability. If upgrading is not immediately possible, remove BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() from the application’s ObjectMapper configuration to eliminate the affected deserialization path. Rebuild and restart the application to apply the configuration change. As an additional mitigation, disable polymorphic deserialization of untrusted data where possible by avoiding or removing default typing features such as activateDefaultTyping() or enableDefaultTyping(). When polymorphic deserialization is required, restrict allowed subtypes using a strict whitelist of trusted application packages and avoid broad or permissive type validation rules.