CVE-2026-54512 | FasterXML jackson-databind up to 2.18.7/2.21.3/3.1.3 incomplete blacklist (ID 5988 / EUVD-2026-38595)
A vulnerability described as critical has been identified in FasterXML jackson-databind up to 2.18.7/2.21.3/3.1.3. Affected is an unknown function. Executing a manipulation can lead to incomplete blacklist.
This vulnerability is tracked as CVE-2026-54512. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.