<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:12:00.717391+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:40895</id>
    <title>ALSA-2026:40895 — Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base secur…</title>
    <updated>2026-10-03T03:12:01.869397+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: pki-jackson-annotations, AlmaLinux:9: pki-jackson-core, AlmaLinux:9: pki-jackson-databind, AlmaLinux:9: pki-jackson-jaxrs-json-provider, AlmaLinux:9: pki-jackson-jaxrs-providers, AlmaLinux:9: pki-jackson-module-jaxb-annotations</p>
<p>The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.</p>
<p>Security Fix(es):</p>
<p>* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
  * jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:40895"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0914</id>
    <title>certfr-2026-avi-0914 — De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-03T03:12:01.869510+00:00</updated>
    <content>certfr-2026-avi-0914</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668</id>
    <title>Withdrawn: CLEANSTART-2026-AM39668 — yawkat LZ4 Java provides LZ4 compression for Java</title>
    <updated>2026-10-03T03:12:01.869532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-nifi</p>
<p>Multiple security vulnerabilities affect the apache-nifi package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-am39668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329884</id>
    <title>EUVD-2026-329884</title>
    <updated>2026-10-03T03:12:01.869555+00:00</updated>
    <content>EUVD-2026-329884</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329884"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54512</id>
    <title>fkie_cve-2026-54512</title>
    <updated>2026-10-03T03:12:01.869568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains &lt;), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before &lt;) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList&lt;com.evil.Gadget&gt; when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54512"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j3rv-43j4-c7qm</id>
    <title>GHSA-j3rv-43j4-c7qm — jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instanti…</title>
    <updated>2026-10-03T03:12:01.869604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.fasterxml.jackson.core:jackson-databind, Maven: tools.jackson.core:jackson-databind</p>
<p>`jackson-databind`'s `PolymorphicTypeValidator` (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains `&lt;`), `DatabindContext._resolveAndValidateGeneric()` validates **only the raw container class name** (the substring before `&lt;`) against the configured PTV.</p>
<p>If the container type is approved, the method parses the full canonical type string via `TypeFactory.constructFromCanonical()` and returns the fully parameterized type **without ever validating the nested type arguments** against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization.</p>
<p>An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example `java.util.ArrayList&lt;com.evil.Gadget&gt;` when only `java.util.ArrayList` is allow-listed. The container passes the PTV check; `com.evil.Gadget` is loaded via `Class.forName(name, true, loader)`, instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list.</p>
<p>This is the same vulnerability class responsible for the historical sequence of jackson-databind deserialization CVEs; here it manifests as a validator bypass rather than a missing deny-list entry.</p>
<p>## Impact</p>
<p>- **Bypass of the PTV allow-list**, including the recommended `BasicPoly…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j3rv-43j4-c7qm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-03T03:12:01.869659+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11132-1</id>
    <title>openSUSE-SU-2026:11132-1 — jackson-databind-2.18.8-2.1 on GA media</title>
    <updated>2026-10-03T03:12:01.869810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-databind-2.18.8-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11132-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:41951</id>
    <title>RHSA-2026:41951 — Red Hat Security Advisory: Red Hat Data Grid 8.6.2 security update</title>
    <updated>2026-10-03T03:12:01.869828+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-uri: fast-uri: URI authority bypass due to improper delimiter handling webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration form-data: form-data: Form field override via CRLF injection react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode axios: Axios: Prototype pollution allows information disclosure and request manipulation react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 he…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:41951"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:40895</id>
    <title>RLSA-2026:40895 — Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base secur…</title>
    <updated>2026-10-03T03:12:01.869902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: jackson-annotations, Rocky Linux:9: jackson-core, Rocky Linux:9: jackson-databind, Rocky Linux:9: jackson-jaxrs-providers, Rocky Linux:9: jackson-modules-base</p>
<p>The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.</p>
<p>Security Fix(es):</p>
<p>* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)</p>
<p>* jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:40895"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22504-1</id>
    <title>SUSE-SU-2026:22504-1 — Security update for jackson-annotations, jackson-core, jackson-databind</title>
    <updated>2026-10-03T03:12:01.869936+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jackson-annotations, jackson-core, jackson-databind</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22504-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54512</id>
    <title>UBUNTU-CVE-2026-54512</title>
    <updated>2026-10-03T03:12:01.869955+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jackson-databind, Ubuntu:Pro:16.04:LTS: jackson-databind, Ubuntu:18.04:LTS: jackson-databind, Ubuntu:20.04:LTS: jackson-databind, Ubuntu:22.04:LTS: jackson-databind, Ubuntu:24.04:LTS: jackson-databind, Ubuntu:25.10: jackson-databind, Ubuntu:26.04:LTS: jackson-databind</p>
<p>jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains &lt;), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before &lt;) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList&lt;com.evil.Gadget&gt; when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54512"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2058</id>
    <title>WID-SEC-W-2026-2058 — FasterXML Jackson: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:12:01.869995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um  Schutzmechanismen und Autorisierungsregeln zu umgehen, Daten zu manipulieren, Informationen offenzulegen oder einen Denial-of-Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2058"/>
  </entry>
</feed>
