Skip to main content

Threats Tagged 'cve-2026-54513'

View all threats tagged with 'cve-2026-54513'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-54513

Threats Tagged 'cve-2026-54513'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat OpenShift Dev Spaces provides a cloud developer workspace server and a browser-based IDE built for teams and organizations. Dev Spaces runs in OpenShift and is well-suited for container-based development. The 3.30 release is based on Eclipse Che 7.121 and uses the DevWorkspace engine to provide support for workspaces based on devfile v2.1 and v2.2. Users still using the v1 standard should migrate as soon as possible. https://devfile.io/docs/2.2.0/migrating-to-devfile-v2 Dev Spaces supports OpenShift EUS releases v4.16 and higher. Users are expected to update to supported OpenShift releases in order to continue to get Dev Spaces updates. https://access.redhat.com/support/policy/updates/openshift#crw

Join the discussion

Red Hat Streams for Apache Kafka, based on the Apache Kafka project, offers a distributed backbone that allows microservices and other applications to share data with extremely high throughput and extremely low latency. This release of Red Hat Streams for Apache Kafka 3.2.1 serves as a replacement for Red Hat Streams for Apache Kafka 3.2.0, and includes security and bug fixes, and enhancements. Security Fix(es): * golang-github-danielqsj-kafka_exporter: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) * quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests (CVE-2026-39852) * kafka-clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management (CVE-2026-35554) * log4j-layout-template-json: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output (CVE-2026-34481) * log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging (CVE-2026-34480) * log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames (CVE-2026-34478) * netty-codec-dns: Netty: High integrity impact due to improper DNS domain name constraint enforcement (CVE-2026-42579) * netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion (CVE-2026-42584) * netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers (CVE-2026-42581) * netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation (CVE-2026-42578) * netty-codec-http: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) * netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) * netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder (CVE-2026-42583) * netty-codec-compression: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder (CVE-2026-42583) * next: Next.js: Authorization bypass via crafted query parameters (CVE-2026-44574) * next: Next.js: Denial of Service via crafted POST requests to server actions (CVE-2026-44579) * next: Next.js: Denial of Service via Image Optimization API (CVE-2026-44577) * next: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n (CVE-2026-44573) * next: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests (CVE-2026-44578) * next: Next.js: Information disclosure via security fix bypass in middleware with Turbopack (CVE-2026-45109) * next: Next.js: Unauthorized access to protected content via middleware bypass (CVE-2026-44575) * quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters (CVE-2026-50559) * golang-github-danielqsj-kafka_exporter: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * vertx-core: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name (CVE-2026-6860) * netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation (CVE-2026-44249) * netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message (CVE-2026-44893) * netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak (CVE-2026-48043) * netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers (CVE-2026-48059) * netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records (CVE-2026-47691) * netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation (CVE-2026-45674) * netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake (CVE-2026-45416) * golang-github-danielqsj-kafka_exporter: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * cluster-operator: Cross-namespace privilege escalation via Kafka.spec.entityOperator.watchedNamespace in Strimzi (CVE-2026-55225) * micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests (CVE-2026-40984) * micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests (CVE-2026-40983) * golang-github-danielqsj-kafka_exporter: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193) * golang-github-danielqsj-kafka_exporter: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * jacks

Join the discussion

Red Hat build of Keycloak is an integrated sign-on solution, available as a Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat build of Keycloak for OpenShift image provides an authentication server that you can use to log in centrally, log out, and register. You can also manage user accounts for web applications, mobile applications, and RESTful web services. Red Hat build of Keycloak Operator for OpenShift simplifies deployment and management of Keycloak 26.6.5 clusters. This erratum releases new images for Red Hat build of Keycloak 26.6.5 for use within the OpenShift Container Platform cloud computing Platform-as-a-Service (PaaS) for on-premise or private cloud deployments, aligning with the standalone product release. Security fixes: * Authorization Bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of Keycloak (CVE-2026-11986) * Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209) * FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614) * FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615) * DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572) * Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573) * LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071) * Unbounded metric cardinality in user event metrics via request-controlled error text (CVE-2026-16100) * Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102) * Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) * SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442) * SAML broker metadata import disables response signature validation (CVE-2026-16443) * Denial of Service via specially crafted gRPC requests (CVE-2026-40983) * Denial of Service via specially crafted HTTP requests (CVE-2026-40984) * Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * Security bypass allows arbitrary code execution (CVE-2026-54513) * HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689) * Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793) * Brute-force protection bypass in CIBA flow (CVE-2026-9798)

Join the discussion

Red Hat build of Keycloak is an integrated sign-on solution, available as a Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat build of Keycloak for OpenShift image provides an authentication server that you can use to log in centrally, log out, and register. You can also manage user accounts for web applications, mobile applications, and RESTful web services. Red Hat build of Keycloak Operator for OpenShift simplifies deployment and management of Keycloak 26.4.14 clusters. This erratum releases new images for Red Hat build of Keycloak 26.4.14 for use within the OpenShift Container Platform cloud computing Platform-as-a-Service (PaaS) for on-premise or private cloud deployments, aligning with the standalone product release. Security fixes: * Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209) * FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614) * FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615) * DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572) * Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573) * LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071) * Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102) * Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) * SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442) * SAML broker metadata import disables response signature validation (CVE-2026-16443) * Privilege escalation through hardcoded role mapper injection (CVE-2026-4629) * Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * Security bypass allows arbitrary code execution (CVE-2026-54513) * HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689) * Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793) * Brute-force protection bypass in CIBA flow (CVE-2026-9798) * Authorization bypass via incorrect URI comparison (CVE-2026-9800) * Brute-force protection bypass in CIBA flow (CVE-2026-9798)

Join the discussion

An update for Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.2.SP2). The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products: * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution [rhboac-camel-quarkus-3] (CVE-2026-54513) * jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass [rhboac-camel-quarkus-3] (CVE-2026-54512) * micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests [rhboac-camel-quarkus-3] (CVE-2026-40983) * micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests [rhboac-camel-quarkus-3] (CVE-2026-40984) * cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening [rhboac-camel-quarkus-3] (CVE-2026-49875)

Join the discussion

This update for jackson-annotations, jackson-core, jackson-databind fixes the following issues - CVE-2026-54512: jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation (bsc#1268897). - CVE-2026-54513: jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (bsc#1268898). - CVE-2026-54514: InetSocketAddress deserialization triggers eager DNS resolution (bsc#1268899). - CVE-2026-54515: jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties (bsc#1268902). - document length constraint bypass in blocking, async, and DataInput parsers (bsc#1268603). Changes for jackson-annotations: - Update to 2.18.8 * No changes since 2.17.3 Changes for jackson-core: - Update to 2.18.8 * Changes of 2.18.8 + #1611: Apply number-length validator on streaming integer path of async parser * Changes of 2.18.7 + #1570: Fail parsing from 'DataInput' if 'StreamReadConstraints .getMaxDocumentLength()' set (bsc#1268603, GHSA-2m67-wjpj-xhg9) + #1600: Rework 3rd party licenses in jar + #1602: 'UTF8DataInputJsonParser' needs to enforce 'StreamReadConstraints.maxNameLength' limit * Changes of 2.18.6 + #1512: Number-parsing fix for 'UTF8DataInputJsonParser' + #1548: 'StreamReadConstraints.maxDocumentLength' not checked when creating parser with fixed buffer + #1555: Enforce 'StreamReadConstraints.maxNumberLength' for non-blocking (async) parser * Changes of 2.18.5 + #1433: 'JsonParser#getNumberType()' throws 'JsonParseException' when the current token is non-numeric instead of returning null + #1446: Invalid package reference to "java.lang.foreign" from 'com.fasterxml.jackson.core:jackson-core' (from 'FastDoubleParser') * Changes of 2.18.3 + #1391: Fix issue where the parser can read back old number state when parsing later numbers + #1397: Jackson changes additional values to infinite in case of special JSON structures and existing infinite values + #1398: Fix issue that feature COMBINE_UNICODE_SURROGATES_IN_UTF8 doesn't work when custom characterEscape is used * Changes of 2.18.2 + #1359: Non-surrogate characters being incorrectly combined when 'JsonWriteFeature.COMBINE_UNICODE_SURROGATES_IN_UTF8' is enabled * Changes of 2.18.1 + #1353: Use fastdoubleparser 1.0.90 * Changes of 2.18. + #223: 'UTF8JsonGenerator' writes supplementary characters as a surrogate pair: should use 4-byte encoding + #1230: Improve performance of 'float' and 'double' parsing from 'TextBuffer' + #1251: 'InternCache' replace synchronized with 'ReentrantLock' - the cache size limit is no longer strictly enforced for performance reasons but we should never go far about the limit + #1252: 'ThreadLocalBufferManager' replace synchronized with 'ReentrantLock' + #1257: Increase InternCache default max size from 100 to 200 + #1262: Add diagnostic method 'pooledCount()' in 'RecyclerPool' + #1264: Rename shaded 'ch.randelshofer:fastdoubleparser' classes to prevent use by downstream consumers + #1271: Deprecate 'LockFreePool' implementation in 2.18 (remove from 3.0) + #1274: 'NUL'-corrupted keys, values on JSON serialization + #1277: Add back Java 22 optimisation in FastDoubleParser + #1284: Optimize 'JsonParser.getDoubleValue()/getFloatValue() /getDecimalValue()' to avoid String allocation + #1305: Make helper methods of 'WriterBasedJsonGenerator' non-final to allow overriding + #1310: Add new 'StreamReadConstraints' ('maxTokenCount') to limit maximum number of Tokens allowed per document# + #1331: Update to FastDoubleParser v1.0.1 to fix 'BigDecimal' decoding proble Changes for jackson-databind: - Update to 2.18.8 * Changes of 2.18.8 + #5950: Improve 'UUIDeserializer' error handling + #5951: Improve 'InetSocketAddress' deserialization (bsc#1268899, CVE-2026-54514) + #5969: '@JsonView' by-passed for some "setterless" creator properties + #5971: '@JsonView' by-passed for unwrapped creator parameters + #5974: '@JsonIgnore' on Record property ignored with 'PropertyNamingStrategy' + #5981: 'BasicPolymorphicTypeValidator' setting 'allowIfSubTypeIsArray()' should validate element type (bsc#1268898, CVE-2026-54513) + #5988: 'PolymorphicTypeValidator' needs to validate generic type parameters too (bsc#1268897, CVE-2026-54512) + #5993: 'UPPER_SNAKE_CASE' / 'LOWER_CASE' 'NamingStrategyImpls' fold case using JVM default locale (Turkish-I bug) * Changes of 2.18.4 + #4628: '@JsonIgnore' and '@JsonProperty.access=READ_ONLY' on Record property ignored for deserialization + #5049: Duplicate creator property "b" (index 0 vs 1) on simple java record * Changes of 2.18.3 + #4444: The 'KeyDeserializer' specified in the class with '@JsonDeserialize(keyUsing = ...)' is overwritten by the 'KeyDeserializer' specified in the 'ObjectMapper'. + #4827: Subclassed Throwable deserialization fails since v2.18.0 - no creator index for property 'cause' + #4844: Fix wrap

Join the discussion
0

These are all security issues fixed in the jackson-databind-2.18.8-1.1 package on the GA media of openSUSE Tumbleweed.

Join the discussion

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: cve-2026-54513
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses