FasterXML Jackson bug can crash services

Published September 11, 2026

FasterXML Jackson has a CERT-Bund advisory for 8 vulnerabilities in versions before 2.21.4. A remote, anonymous attacker can exploit multiple vulnerabilities in FasterXML Jackson to bypass protection mechanisms and authorization rules, manipulate data, disclose information, or cause a denial of service.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 2.21.4Fix recorded today
Affected versions
before 2.21.4
Affects
FasterXML Jackson+4 more
Exploited
Not confirmedNo confirmation recorded

How it works

A remote, anonymous attacker can exploit multiple vulnerabilities in FasterXML Jackson to bypass protection mechanisms and authorization rules, manipulate data, disclose information, or cause a denial of service.

What to do

Check your FasterXML Jackson version. If it is before 2.21.4, this advisory applies.

Update FasterXML Jackson to 2.21.4 or newer.

Technical details

Affected software: FasterXML Jackson, Linux, Sonstiges, UNIX, Windows

A remote, anonymous attacker can exploit multiple vulnerabilities in FasterXML Jackson to bypass protection mechanisms and authorization rules, manipulate data, disclose information, or cause a denial of service. The advisory tracks CVE-2026-50193, CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515, CVE-2026-54516, CVE-2026-54517, CVE-2026-54518. In CERT-Bund's CSAF data, affected versions are before 2.21.4, before 3.1.4, before 2.14.0, before 2.18.8, and the fixed version is 2.21.4, 3.1.4, 2.14.0, 2.18.8. Affected operating systems listed by CERT-Bund: Linux, Sonstiges, UNIX, Windows.

References