{"id":"RHSA-2026:40895","summary":"Red Hat Security Advisory: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update","modified":"2026-07-17T10:16:59.977530791Z","published":"2026-07-17T10:09:48Z","upstream":["CVE-2026-54512","CVE-2026-54513"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:40895"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492010"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492015"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40895.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-54512"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-54512"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/issues/5988"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-54513"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-54513"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/issues/5981"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/issues/5983"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/pull/5984"},{"type":"ARTICLE","url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f"}],"affected":[{"package":{"name":"jackson-databind","ecosystem":"Red Hat:enterprise_linux:9::appstream","purl":"pkg:rpm/redhat/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.21.4-1.el9_8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:40895.json"}},{"package":{"name":"pki-jackson-databind","ecosystem":"Red Hat:enterprise_linux:9::appstream","purl":"pkg:rpm/redhat/pki-jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.21.4-1.el9_8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:40895.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}