Red Hat Product Errata RHSA-2026:44061 - Security Advisory Issued: 2026-07-23 Updated: 2026-07-23 RHSA-2026:44061 - Security Advisory Overview Updated Packages Synopsis Important: pki-deps:10.6 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the pki-deps:10.6 module is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System. Security Fix(es): jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513) jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2492010 - CVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution BZ - 2492015 - CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass CVEs CVE-2026-54512 CVE-2026-54513 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 SRPM apache-commons-collections-3.2.2-10.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 8808d86cf51fbacb8385c8ab63619325a63a5b9c01d511b20f8116963d3ecd25 apache-commons-lang-2.6-21.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 8d21f5d5b04d5f6115278eb5610c074914188e978c7f3e4ba4efa9af9a90552a apache-commons-net-3.6-3.module+el8.3.0+6805+72837426.src.rpm SHA-256: b107a38acb94ca4c07b39a0ebd9cb78cc98b96a860b9d90f6d1ae2d6557d3d62 bea-stax-1.2.0-16.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 6df5604c39f96f7bc1f72c2704d8af3e910773675f41751eeab3e92844c4f266 fasterxml-oss-parent-75-1.module+el8.6.0+24530+83fbd25a.src.rpm SHA-256: 12830e9d130ee150904f4d600579120590364d4d479b9e5940691143d72e85f0 glassfish-fastinfoset-1.2.13-9.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 54904a53c89d2e4c6b4500e3ccfbb15a21d01087d651f36f01c155ed88637934 glassfish-jaxb-2.2.11-11.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: fefd1ddbf106bf9e6c091f61a4215030c4db3c53068ef29f60f05abe36c4e4ac glassfish-jaxb-api-2.2.12-8.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 4533ff42e7e841e1e1103d65a11509cc85a119c839109af0ff6df0c07b3a3e56 jackson-annotations-2.21-1.module+el8.6.0+24530+83fbd25a.src.rpm SHA-256: 01cc840d718ae7fe7e98fbc224cd5b78cfb3be52ac55a5c40637f4aa9fa4aad4 jackson-bom-2.21.4-1.module+el8.6.0+24530+83fbd25a.src.rpm SHA-256: 3657c4e239a4edee0ef84fb0e58dc7bec2c1182080e2bb76731bdb2750f4f9fb jackson-core-2.21.4-1.module+el8.6.0+24530+83fbd25a.src.rpm SHA-256: 55c35e1ba9d47f3f17372f5d00e4a96499c8b45bf0cb577cb1b4f9863fea4fe3 jackson-databind-2.21.4-1.module+el8.6.0+24530+83fbd25a.src.rpm SHA-256: 7a614c576df64867399698f7861f5b504feabf5a95e1fe37e62ecc68491ed919 jackson-jaxrs-providers-2.21.4-1.module+el8.6.0+24530+83fbd25a.src.rpm SHA-256: 80fc901c85c7c06ca97d1587304f7c620db787821ca2857c6ee0a6f91f1cb0c9 jackson-modules-base-2.21.4-1.module+el8.6.0+24530+83fbd25a.src.rpm SHA-256: c1aff7931e20d9f313253655e92fe759d250435924b16e660d7d872c70b74bfe jackson-parent-2.21-1.module+el8.6.0+24530+83fbd25a.src.rpm SHA-256: 52968972a285eba7b2af25327d4ed9ecefa839ec16936e26b58392b2b80c4001 jakarta-commons-httpclient-3.1-28.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 50276786098d4b9f278949f2d29cc3f9c803519053acfd5446289741d61fa9be javassist-3.18.1-8.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: f7758844e90881da0ab7cf51f23766930102407063cb133056781b8ec7cdd328 pki-servlet-engine-9.0.30-3.module+el8.6.0+23938+b3b8726f.3.src.rpm SHA-256: bd5359514bc3c09ddb1ebcca707c9b39fcf2cd63439d4446bbdb666b4b54209e python-nss-1.0.1-10.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 78de9422d12b295fa42e145dd6b9ba8fd9394ca98976199c70f4f03656242170 relaxngDatatype-2011.1-7.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 56290e8587b6a8a88ba2f7e05c7e629562889565430cd7d45622515ac3e7a1e0 resteasy-3.0.26-6.module+el8.6.0+23400+aafc0b27.src.rpm SHA-256: 37b890c5c6205a1e65d8b67dce5918a3e31f485057f24cd74b63f9b7226120a8 slf4j-1.7.25-4.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 9658c2a5e83e3db3e37c4bc43de7cb3ccac3e07d814c64d8fd872e5cb3cdc0a2 stax-ex-1.7.7-8.module+el8.2.0+5723+4574fbff.src.rpm SHA-256: b1f9e5823d9629fb58bbb3722d40015b5e9c4a1acde507bdcb60fcd24f9ac806 velocity-1.7-24.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 2d66b2fc4920e5c656bc6b0cf0669634ae0854f3f5fbce481ba6b73c8fcba83f xalan-j2-2.7.1-38.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: ebd234a3e289cbc121b7224bde246ae06348d0d1b5c763c54aa22b13389d93e3 xerces-j2-2.11.0-34.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 1e8befbd26490fbd854478e1ec42345ac6fbe56299797abcd0bc847536ba7c20 xml-commons-apis-1.4.01-25.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 13c235e3991694ed5d0b937514da067bc7ef249e5d3cd0b875e7468ec422688d xml-commons-resolver-1.2-26.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 9be8f11924dfb904c88ca012ccd8ca45bbca025b54cfecf6f894a16385dee090 xmlstreambuffer-1.5.4-8.module+el8.2.0+5723+4574fbff.src.rpm SHA-256: 94083d7550925a1eecd68c53c168432d55afeb67d9bc0eae4a9545060b57df13 xsom-0-19.20110809svn.module+el8.1.0+3366+6dfb954c.src.rpm SHA-256: 5c5c569ee17f3b125d907202af3940d3b870f49e205e6e3af7eca3b90357b1fd x86_64 apache-commons-collections-3.2.2-10.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 61032ccfc3d125b1882c55dfc06101098b149aaaf78261f4d78104819b67e654 apache-commons-lang-2.6-21.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 324413ffde38b0e68fb4633ae751e74f06dd29d9845cc394dd75234a1c67534c apache-commons-net-3.6-3.module+el8.3.0+6805+72837426.noarch.rpm SHA-256: 44fa1e0d3a22e9e6e72cedb8a7104441ad780d2cd1fe4e7fc9832634a9297700 bea-stax-api-1.2.0-16.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 5698297dddd2ffe6cb398bf43338f3153040c3e47c40e7cd271fa88076240e11 fasterxml-oss-parent-75-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: e0738cad4708a00b630fa2ad58fd8e7a5f75092127e91319c2b3549edb425278 glassfish-fastinfoset-1.2.13-9.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 59b0c5aee838fc3f60c471fd22a62c7bf7b3e7be3bc1e90f438d93652edae755 glassfish-jaxb-api-2.2.12-8.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 230eccdbf84113f5dce6f26c5da178a7234b43620e779f4a6c71a18aa3ded1aa glassfish-jaxb-core-2.2.11-11.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: bf8be858f41d6742b74511b5f9ebacd9749a35c42c715c0d49ce7325de025926 glassfish-jaxb-runtime-2.2.11-11.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: ed75a05cd326da7ab45df8f813c9ee87e68b3633462ec01a5bd31ae362f9efce glassfish-jaxb-txw2-2.2.11-11.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: ff5a17869359c38652f645729e2051008f7df309dfdb9d4546c054bcee255d44 jackson-annotations-2.21-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: 2692ec7259e58c9067236498892289dc9189c0167050dd9a9c867ac6347406ae jackson-bom-2.21.4-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: 48acd47b092184fee925287981f7958584e5880d91da4f90d59cdcbbe7d9e4eb jackson-core-2.21.4-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: 8065eef1bc5a985dc7a35ca404e393ee9f6ad2463005149baa11eaa52b5ea188 jackson-databind-2.21.4-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: cfcfcda7b415367b4533390e390be1db8d6a7d5ac1b72843a7e5aaff4fd3267a jackson-jaxrs-json-provider-2.21.4-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: 95671b9ceeb301a3d72372bfee57e18bcb38662df5ccd829974a0db751e88d12 jackson-jaxrs-providers-2.21.4-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: dee6b73685750bf0c197e03117f63dc463d18744378d214f54977049b298f77a jackson-module-jaxb-annotations-2.21.4-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: 29487fd559a262a84ec06736cc421d16e0641be46c97967061bce5afd395b0c6 jackson-modules-base-2.21.4-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: 9bd9686fafe26c4c7f60b17e72118cd149624fa67f6b20a2f8931974d6ca16ce jackson-parent-2.21-1.module+el8.6.0+24530+83fbd25a.noarch.rpm SHA-256: 2424d7e6d94fa9b4a7751654f41e623762eac88bc218e8b1e21e46d3f3a3958a jakarta-commons-httpclient-3.1-28.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 8086eed8f36137ac5f481057e0bcd04d0bf57f2c9bccc2bb0fc3feb06f574061 javassist-3.18.1-8.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: 1e7af30426ec8abe97a466764f13ea870b51198b89ae774c1b61f4ac0cc3de72 javassist-javadoc-3.18.1-8.module+el8.1.0+3366+6dfb954c.noarch.rpm SHA-256: e740b18bb372f1986a598c5c04f0e7a2c985feca0d8178136870a6b838367cd5 pki-servlet-4.0-api-9.0.30-3.module+el8.6.0+23938+b3b8726f.3.noarch.rpm SHA-256: 989b71ef7fd0cf951f17b246a3e33f03bb31b13018cce675638d522557106545 pki-servlet-engine-9.0.30-3.module+el8.6.0+23938+b3b8726f.3.noarch.rpm SHA-256: abd720a00c9b131fb4abc1c8c459a317f84ed5fc181bce2b81228f1032db5cb4 python-nss-debugsource-1.0.1-10.module+el8.1.0+3366+6dfb954c.x86_64.rpm SHA-256: ca0fa12ad8c1c6931da5b67d2b85689244608021d7225c979c99476179e4a351 python-nss-doc-1.0.1-10.module+el8.1.0+3366+6dfb954c.x86_64.rpm SHA-256: c935d1b335fd1e997012840c5b6a4266f
Two vulnerabilities (CVE-2026-54512 and CVE-2026-54513, both CVSS 8.1 High) in the jackson-databind library allow for arbitrary code execution via a security bypass and a PolymorphicTypeValidator bypass. Affected versions are fasterxml jackson-databind 2.10.0 to 2.18.7, 2.19.0 to 2.21.3, and 3.0.0 to 3.1.3. The fixed versions are 2.18.8, 2.21.4, and 3.1.4, delivered via the Red Hat pki-deps:10.6 module update for RHEL 8.6.