RHSA-2026:40895
Advisory lineage Upstream: 2 Downstream: 0
Upstream
Published: 17 Jul 2026, 10:09
Last modified:19 Sept 2026, 10:10
Vulnerability Summary
Overall Risk (default)
medium
32/100 CVSS Score
8.1 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
17 Jul 2026, 10:09
Published
Vulnerability first disclosed
19 Sept 2026, 10:10
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•jackson-databind
< 0:2.21.4-1.el9_8
- redhat•pki-jackson-databind
< 0:2.21.4-1.el9_8
References (20)
- https://access.redhat.com/errata/RHSA-2026:40895
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2492010
- https://bugzilla.redhat.com/show_bug.cgi?id=2492015
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40895.json
- https://access.redhat.com/security/cve/CVE-2026-54512
- https://www.cve.org/CVERecord?id=CVE-2026-54512
- https://nvd.nist.gov/vuln/detail/CVE-2026-54512
- https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5
- https://github.com/FasterXML/jackson-databind/issues/5988
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm
- https://access.redhat.com/security/cve/CVE-2026-54513
- https://www.cve.org/CVERecord?id=CVE-2026-54513
- https://nvd.nist.gov/vuln/detail/CVE-2026-54513
- https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5
- https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e
- https://github.com/FasterXML/jackson-databind/issues/5981
- https://github.com/FasterXML/jackson-databind/issues/5983
- https://github.com/FasterXML/jackson-databind/pull/5984
- https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f