CVE-2026-54513 | FasterXML jackson-databind up to 2.18.7/2.21.3/3.1.3 EvilType[] incomplete blacklist (ID 5981 / EUVD-2026-38593)
A vulnerability marked as critical has been reported in FasterXML jackson-databind up to 2.18.7/2.21.3/3.1.3. This vulnerability affects the function BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray. The manipulation of the argument EvilType[] leads to incomplete blacklist.
This vulnerability is listed as CVE-2026-54513. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.