RHSA-2026:54440HighCVSS 8.1

Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes security update

Published
August 12, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2026-50193 — jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass CVE-2026-59888 — com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records CVE-2026-68494 — com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser

🎯 Affected products5

  • Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
  • registry.redhat.io/rh-lightspeed-runtimes/runtimes-agent-init-rhel9@sha256:5281c5150f8c786098bbaf43d036ca89ed21cf2bf68f09236de82fda4740dd27_s390x as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
  • registry.redhat.io/rh-lightspeed-runtimes/runtimes-agent-init-rhel9@sha256:5e413617445a6f5b238d5b45dae157df63c974b5a0262bce8754cdd3296f86a3_arm64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
  • registry.redhat.io/rh-lightspeed-runtimes/runtimes-agent-init-rhel9@sha256:a2dd47734aa704b52c3ff8c9101c8309ea5647abf5d0b6d5a4e38627270f3d61_ppc64le as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
  • registry.redhat.io/rh-lightspeed-runtimes/runtimes-agent-init-rhel9@sha256:a6fc33e05610c80a5f2be7589394eaf9ea7e85568d001c601a214535df7e9a85_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (7)