{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "fix CVE-2026-54513: validate array element type in BasicPolymorphicTypeValidator allowIfSubTypeIsArray",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784801122",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784801122"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/almalinux9.2esu/advisories/2026/clsa-2026_1784801122.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-06T11:15:00Z",
      "generator": {
        "date": "2026-08-06T11:15:00Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1784801122",
      "initial_release_date": "2026-07-23T10:06:32Z",
      "revision_history": [
        {
          "date": "2026-07-23T10:06:32Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-06T11:15:00Z",
          "number": "2",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "jackson-databind: Fix of CVE-2026-54513"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.2",
                "product": {
                  "name": "AlmaLinux 9.2",
                  "product_id": "AlmaLinux-9.2",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.2:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch",
                "product": {
                  "name": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch",
                  "product_id": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/pki-jackson-databind@2.14.1-2.el9_2.tuxcare.els6?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch",
                "product": {
                  "name": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch",
                  "product_id": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/pki-jackson-databind@2.14.1-2.el9_2.tuxcare.els3?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
                "product": {
                  "name": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
                  "product_id": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/pki-jackson-databind@2.14.1-2.el9.tuxcare.els2?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
                "product": {
                  "name": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
                  "product_id": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/pki-jackson-databind@2.14.1-2.el9.tuxcare.els1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch"
        },
        "product_reference": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch"
        },
        "product_reference": "pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch"
        },
        "product_reference": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch"
        },
        "product_reference": "pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
        "relates_to_product_reference": "AlmaLinux-9.2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-54513",
      "cwe": {
        "id": "CWE-184",
        "name": "Incomplete List of Disallowed Inputs"
      },
      "notes": [
        {
          "category": "description",
          "text": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch"
        ],
        "known_affected": [
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-54513"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
          "url": "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e",
          "url": "https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/issues/5981",
          "url": "https://github.com/FasterXML/jackson-databind/issues/5981"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/issues/5983",
          "url": "https://github.com/FasterXML/jackson-databind/issues/5983"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/pull/5984",
          "url": "https://github.com/FasterXML/jackson-databind/pull/5984"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f",
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:36839",
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:40895",
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:41951",
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:43218",
          "url": "https://access.redhat.com/errata/RHSA-2026:43218"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:43400",
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:44061",
          "url": "https://access.redhat.com/errata/RHSA-2026:44061"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:44062",
          "url": "https://access.redhat.com/errata/RHSA-2026:44062"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:44063",
          "url": "https://access.redhat.com/errata/RHSA-2026:44063"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:44064",
          "url": "https://access.redhat.com/errata/RHSA-2026:44064"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:44065",
          "url": "https://access.redhat.com/errata/RHSA-2026:44065"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:44066",
          "url": "https://access.redhat.com/errata/RHSA-2026:44066"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:44271",
          "url": "https://access.redhat.com/errata/RHSA-2026:44271"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:48095",
          "url": "https://access.redhat.com/errata/RHSA-2026:48095"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:48151",
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-54513",
          "url": "https://access.redhat.com/security/cve/CVE-2026-54513"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"
        }
      ],
      "release_date": "2026-06-23T21:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-23T10:05:28.217427Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1784801122",
          "product_ids": [
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784801122"
        },
        {
          "category": "none_available",
          "date": "2026-06-23T21:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-54514",
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      },
      "notes": [
        {
          "category": "description",
          "text": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch"
        ],
        "known_affected": [
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-54514"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4",
          "url": "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/pull/5951",
          "url": "https://github.com/FasterXML/jackson-databind/pull/5951"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5",
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"
        }
      ],
      "release_date": "2026-06-23T21:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-23T10:05:28.217427Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1784801122",
          "product_ids": [
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784801122"
        },
        {
          "category": "none_available",
          "date": "2026-06-23T21:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-54515",
      "cwe": {
        "id": "CWE-915",
        "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes"
      },
      "notes": [
        {
          "category": "description",
          "text": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch"
        ],
        "known_affected": [
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
          "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-54515"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa",
          "url": "https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/issues/5962",
          "url": "https://github.com/FasterXML/jackson-databind/issues/5962"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/issues/5964",
          "url": "https://github.com/FasterXML/jackson-databind/issues/5964"
        },
        {
          "category": "external",
          "summary": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v",
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"
        }
      ],
      "release_date": "2026-06-23T21:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-23T10:05:28.217427Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1784801122",
          "product_ids": [
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784801122"
        },
        {
          "category": "none_available",
          "date": "2026-06-23T21:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els1.noarch",
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9.tuxcare.els2.noarch",
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els3.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:pki-jackson-databind-0:2.14.1-2.el9_2.tuxcare.els6.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}