BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist.
Applications using BasicPolymorphicTypeValidator with allowIfSubTypeIsArray() as a safeguard get no protection for concrete array component types; an attacker controlling JSON can instantiate non-allowlisted types via an array wrapper, re-opening the gadget-instantiation risk PTV is meant to prevent.
git tag --contains)>= 2.10.0, < 2.18.8 -> fixed in 2.18.8>= 2.19.0, < 2.21.4 -> fixed in 2.21.4>= 3.0.0, < 3.1.4 -> fixed in 3.1.4PolymorphicTypeValidator was added in 2.10.0 so vulnerability N/A for versions prior to that.
Maintainer: significant. Reporter: HIGH. CWE-184 (Incomplete List of Disallowed Inputs); related CWE-502.
FasterXML/jackson-databind#5981; fix PR #5983 (24529da), 2.18 backport PR #5984 (01d1692). Released 2026-06-04 in 2.18.8 / 2.21.4 / 3.1.4.
Omkhar Arasaratnam (@omkhar) - finder.
| Score | Percentile |
|---|---|
| 0.60% | 43.97% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 8.1 | 3.1 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-rmj7-2vxq-3g9f ↗ |
| CVE | CVE-2026-54513 ↗ |
| CWE id | Name |
|---|---|
| CWE-184 | Incomplete List of Disallowed Inputs |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| maven | com.fasterxml.jackson.core:jackson-databind | >= 2.10.0, < 2.18.8 | 2.18.8 | — |
| maven | com.fasterxml.jackson.core:jackson-databind | >= 2.19.0, < 2.21.4 | 2.21.4 | — |
| maven | com.fasterxml.jackson.core:jackson-databind | >= 3.0.0, < 3.1.4 | 3.1.4 | — |
| maven | tools.jackson.core:jackson-databind | >= 3.0.0, < 3.1.4 | 3.1.4 | — |