FasterXML Jackson bug can crash services
FasterXML Jackson has a CERT-Bund advisory for 8 vulnerabilities in versions before 2.21.4. A remote, anonymous attacker can exploit multiple vulnerabilities in FasterXML Jackson to bypass protection mechanisms and authorization rules, manipulate data, disclose information, or cause a denial of service.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 2.21.4Fix recorded today
- Affected versions
- before 2.21.4
- Affects
- FasterXML Jackson+4 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
A remote, anonymous attacker can exploit multiple vulnerabilities in FasterXML Jackson to bypass protection mechanisms and authorization rules, manipulate data, disclose information, or cause a denial of service.
What to do
Check your FasterXML Jackson version. If it is before 2.21.4, this advisory applies.
Update FasterXML Jackson to 2.21.4 or newer.
Technical details
Affected software: FasterXML Jackson, Linux, Sonstiges, UNIX, Windows
A remote, anonymous attacker can exploit multiple vulnerabilities in FasterXML Jackson to bypass protection mechanisms and authorization rules, manipulate data, disclose information, or cause a denial of service. The advisory tracks CVE-2026-50193, CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515, CVE-2026-54516, CVE-2026-54517, CVE-2026-54518. In CERT-Bund's CSAF data, affected versions are before 2.21.4, before 3.1.4, before 2.14.0, before 2.18.8, and the fixed version is 2.21.4, 3.1.4, 2.14.0, 2.18.8. Affected operating systems listed by CERT-Bund: Linux, Sonstiges, UNIX, Windows.
References
- wid.cert-bund.de · wid-sec-w-2026-2058.json technical description
- github.com · GHSA-RCQC-6CW3-H962 third party advisory
- github.com · GHSA-3WRR-7QPF-2PRH third party advisory
- github.com · GHSA-RMJ7-2VXQ-3G9F third party advisory
- github.com · GHSA-J3RV-43J4-C7QM third party advisory
- github.com · GHSA-HGJ6-7826-R7M5 third party advisory
- github.com · GHSA-5JMJ-H7XM-6Q6V third party advisory
- github.com · GHSA-9FXM-VC8V-HJ55 third party advisory
- github.com · GHSA-5HH8-Q8HV-FR38 third party advisory
- lists.opensuse.org · LHWTHNHNCSM4ZEEBVPVPRPWKH5IXSVE2 third party advisory
- lists.opensuse.org · MFGZCADO45NXHW7I5ZRLJ3RXG5TJ2JPO third party advisory
- lists.suse.com · 027297.html third party advisory
- ibm.com · 7279257 third party advisory
- access.redhat.com · RHSA-2026:36839 third party advisory
- access.redhat.com · RHSA-2026:36013 third party advisory
- access.redhat.com · RHSA-2026:36002 third party advisory
- lists.suse.com · 027332.html third party advisory
- ibm.com · 7279718 third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-ddde3cf003 third party advisory
- access.redhat.com · RHSA-2026:40895 third party advisory
- errata.build.resf.org · RLSA-2026:40895 third party advisory
- access.redhat.com · RHSA-2026:41951 third party advisory
- access.redhat.com · RHSA-2026:43218 third party advisory
- access.redhat.com · RHSA-2026:43400 third party advisory
- errata.build.resf.org · RLSA-2026:43218 third party advisory
- access.redhat.com · RHSA-2026:44065 third party advisory
- access.redhat.com · RHSA-2026:44066 third party advisory
- errata.build.resf.org · RLSA-2026:43400 third party advisory
- access.redhat.com · RHSA-2026:44271 third party advisory
- access.redhat.com · RHSA-2026:44064 third party advisory
- access.redhat.com · RHSA-2026:44063 third party advisory
- access.redhat.com · RHSA-2026:44062 third party advisory
- access.redhat.com · RHSA-2026:44061 third party advisory
- linux.oracle.com · ELSA-2026-40895.html third party advisory
- linux.oracle.com · ELSA-2026-43400.html third party advisory
- lists.suse.com · 027929.html third party advisory
- lists.suse.com · 027920.html third party advisory
- access.redhat.com · RHSA-2026:48124 third party advisory
- access.redhat.com · RHSA-2026:48151 third party advisory
- access.redhat.com · RHSA-2026:48095 third party advisory
- linux.oracle.com · ELSA-2026-43218.html third party advisory
- access.redhat.com · RHSA-2026:50848 third party advisory
- access.redhat.com · RHSA-2026:50847 third party advisory
- access.redhat.com · RHSA-2026:50849 third party advisory
- ibm.com · 7283059 third party advisory
- access.redhat.com · RHSA-2026:54435 third party advisory
- access.redhat.com · RHSA-2026:54440 third party advisory
- access.redhat.com · RHSA-2026:54622 third party advisory
- access.redhat.com · RHSA-2026:60256 third party advisory
- access.redhat.com · RHSA-2026:60254 third party advisory
- access.redhat.com · RHSA-2026:60251 third party advisory
- access.redhat.com · RHSA-2026:60246 third party advisory
- access.redhat.com · RHSA-2026:60247 third party advisory
- access.redhat.com · RHSA-2026:60248 third party advisory
- access.redhat.com · RHSA-2026:60249 third party advisory
- access.redhat.com · RHSA-2026:60250 third party advisory
- access.redhat.com · RHSA-2026:60252 third party advisory
- access.redhat.com · RHSA-2026:60239 third party advisory
- access.redhat.com · RHSA-2026:60259 third party advisory
- dell.com · dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities third party advisory
- access.redhat.com · RHSA-2026:61627 third party advisory
- ibm.com · 7285930 third party advisory
- access.redhat.com · RHSA-2026:62260 third party advisory
- ibm.com · 7286196 third party advisory
- access.redhat.com · RHSA-2026:63327 third party advisory
- access.redhat.com · RHSA-2026:63386 third party advisory
- access.redhat.com · RHSA-2026:63385 third party advisory
- access.redhat.com · RHSA-2026:63387 third party advisory
- access.redhat.com · RHSA-2026:66488 third party advisory
- access.redhat.com · RHSA-2026:66545 third party advisory