<div class="container">
<h1>Security update for jackson-annotations, jackson-core, jackson-databind</h1>
<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2026:22504-1</td>
</tr>
<tr>
<th>Release Date:</th>
<td>2026-07-01T09:06:57Z</td>
</tr>
<tr>
<th>Rating:</th>
<td>important</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268603">bsc#1268603</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268897">bsc#1268897</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268898">bsc#1268898</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268899">bsc#1268899</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268902">bsc#1268902</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>
Cross-References:
</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-54512.html">CVE-2026-54512</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-54513.html">CVE-2026-54513</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-54514.html">CVE-2026-54514</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-54515.html">CVE-2026-54515</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54512</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54512</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54513</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54513</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54513</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54514</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">5.3</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54514</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">5.3</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54515</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">5.3</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-54515</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">5.3</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</span>
</li>
</ul>
</td>
</tr>
<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">
<li class="list-group-item">SUSE Linux Enterprise Server 16.0</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP applications 16.0</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>An update that solves four vulnerabilities and has one fix can now be installed.</p>
<h2>Description:</h2>
<p>This update for jackson-annotations, jackson-core, jackson-databind fixes the following issues</p>
<ul>
<li>CVE-2026-54512: jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows
arbitrary class instantiation (bsc#1268897).</li>
<li>CVE-2026-54513: jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (bsc#1268898).</li>
<li>CVE-2026-54514: InetSocketAddress deserialization triggers eager DNS resolution (bsc#1268899).</li>
<li>CVE-2026-54515: jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
(bsc#1268902).</li>
<li>document length constraint bypass in blocking, async, and DataInput parsers (bsc#1268603).</li>
</ul>
<p>Changes for jackson-annotations:</p>
<ul>
<li>Update to 2.18.8</li>
<li>No changes since 2.17.3</li>
</ul>
<p>Changes for jackson-core:</p>
<ul>
<li>Update to 2.18.8</li>
<li>Changes of 2.18.8</li>
<li>
<h1>1611: Apply number-length validator on streaming integer path</h1>
of async parser</li>
<li>Changes of 2.18.7</li>
<li>
<h1>1570: Fail parsing from 'DataInput' if 'StreamReadConstraints</h1>
.getMaxDocumentLength()' set
(bsc#1268603, GHSA-2m67-wjpj-xhg9)</li>
<li>
<h1>1600: Rework 3rd party licenses in jar</h1>
</li>
<li>
<h1>1602: 'UTF8DataInputJsonParser' needs to enforce</h1>
'StreamReadConstraints.maxNameLength' limit</li>
<li>Changes of 2.18.6</li>
<li>
<h1>1512: Number-parsing fix for 'UTF8DataInputJsonParser'</h1>
</li>
<li>
<h1>1548: 'StreamReadConstraints.maxDocumentLength' not checked</h1>
when creating parser with fixed buffer</li>
<li>
<h1>1555: Enforce 'StreamReadConstraints.maxNumberLength' for</h1>
non-blocking (async) parser</li>
<li>Changes of 2.18.5</li>
<li>
<h1>1433: 'JsonParser#getNumberType()' throws</h1>
'JsonParseException' when the current token is non-numeric
instead of returning null</li>
<li>
<h1>1446: Invalid package reference to "java.lang.foreign" from</h1>
'com.fasterxml.jackson.core:jackson-core' (from
'FastDoubleParser')</li>
<li>Changes of 2.18.3</li>
<li>
<h1>1391: Fix issue where the parser can read back old number</h1>
state when parsing later numbers</li>
<li>
<h1>1397: Jackson changes additional values to infinite in case</h1>
of special JSON structures and existing infinite values</li>
<li>
<h1>1398: Fix issue that feature</h1>
COMBINE_UNICODE_SURROGATES_IN_UTF8 doesn't work when custom
characterEscape is used</li>
<li>Changes of 2.18.2</li>
<li>
<h1>1359: Non-surrogate characters being incorrectly combined</h1>
when 'JsonWriteFeature.COMBINE_UNICODE_SURROGATES_IN_UTF8' is
enabled</li>
<li>Changes of 2.18.1</li>
<li>
<h1>1353: Use fastdoubleparser 1.0.90</h1>
</li>
<li>Changes of 2.18.</li>
<li>
<h1>223: 'UTF8JsonGenerator' writes supplementary characters as a</h1>
surrogate pair: should use 4-byte encoding</li>
<li>
<h1>1230: Improve performance of 'float' and 'double' parsing</h1>
from 'TextBuffer'</li>
<li>
<h1>1251: 'InternCache' replace synchronized with 'ReentrantLock'</h1>
</li>
<li>the cache size limit is no longer strictly enforced for
performance reasons but we should never go far about the limit</li>
<li>
<h1>1252: 'ThreadLocalBufferManager' replace synchronized with</h1>
'ReentrantLock'</li>
<li>
<h1>1257: Increase InternCache default max size from 100 to 200</h1>
</li>
<li>
<h1>1262: Add diagnostic method 'pooledCount()' in 'RecyclerPool'</h1>
</li>
<li>
<h1>1264: Rename shaded 'ch.randelshofer:fastdoubleparser'</h1>
classes to prevent use by downstream consumers</li>
<li>
<h1>1271: Deprecate 'LockFreePool' implementation in 2.18 (remove</h1>
from 3.0)</li>
<li>
<h1>1274: 'NUL'-corrupted keys, values on JSON serialization</h1>
</li>
<li>
<h1>1277: Add back Java 22 optimisation in FastDoubleParser</h1>
</li>
<li>
<h1>1284: Optimize 'JsonParser.getDoubleValue()/getFloatValue()</h1>
/getDecimalValue()' to avoid String allocation</li>
<li>
<h1>1305: Make helper methods of 'WriterBasedJsonGenerator'</h1>
non-final to allow overriding</li>
<li>
<h1>1310: Add new 'StreamReadConstraints' ('maxTokenCount') to</h1>
limit maximum number of Tokens allowed per document#</li>
<li>
<h1>1331: Update to FastDoubleParser v1.0.1 to fix 'BigDecimal'</h1>
decoding proble</li>
</ul>
<p>Changes for jackson-databind:</p>
<ul>
<li>Update to 2.18.8</li>
<li>Changes of 2.18.8</li>
<li>
<h1>5950: Improve 'UUIDeserializer' error handling</h1>
</li>
<li>
<h1>5951: Improve 'InetSocketAddress' deserialization</h1>
(bsc#1268899, CVE-2026-54514)</li>
<li>
<h1>5969: '@JsonView' by-passed for some "setterless" creator</h1>
properties</li>
<li>
<h1>5971: '@JsonView' by-passed for unwrapped creator parameters</h1>
</li>
<li>
<h1>5974: '@JsonIgnore' on Record property ignored with</h1>
'PropertyNamingStrategy'</li>
<li>
<h1>5981: 'BasicPolymorphicTypeValidator' setting</h1>
'allowIfSubTypeIsArray()' should validate element type
(bsc#1268898, CVE-2026-54513)</li>
<li>
<h1>5988: 'PolymorphicTypeValidator' needs to validate generic</h1>
type parameters too (bsc#1268897, CVE-2026-54512)</li>
<li>
<h1>5993: 'UPPER_SNAKE_CASE' / 'LOWER_CASE' 'NamingStrategyImpls'</h1>
fold case using JVM default locale (Turkish-I bug)</li>
<li>Changes of 2.18.4</li>
<li>
<h1>4628: '@JsonIgnore' and '@JsonProperty.access=READ_ONLY' on</h1>
Record property ignored for deserialization</li>
<li>
<h1>5049: Duplicate creator property "b" (index 0 vs 1) on simple</h1>
java record</li>
<li>Changes of 2.18.3</li>
<li>
<h1>4444: The 'KeyDeserializer' specified in the class with</h1>
'@JsonDeserialize(keyUsing = ...)' is overwritten by the
'KeyDeserializer' specified in the 'ObjectMapper'.</li>
<li>
<h1>4827: Subclassed Throwable deserialization fails since</h1>
v2.18.0 - no creator index for property 'cause'</li>
<li>
<h1>4844: Fix wrapped array handling wrt 'null' by</h1>
'StdDeserializer'</li>
<li>
<h1>4848: Avoid type pollution in 'StringCollectionDeserializer'</h1>
</li>
<li>
<h1>4860: 'ConstructorDetector.USE_PROPERTIES_BASED' does not</h1>
work with multiple constructors since 2.18</li>
<li>
<h1>4878: When serializing a Map via</h1>
Converter(StdDelegatingSerializer), a NullPointerException is
thrown due to missing key serializer</li>
<li>
<h1>4908: Deserialization behavior change with @JsonCreator and</h1>
@ConstructorProperties between 2.17 and 2.18</li>
<li>
<h1>4917: 'BigDecimal' deserialization issue when using</h1>
'@JsonCreator'</li>
<li>
<h1>4920: Creator properties are ignored on abstract types when</h1>
collecting bean properties, breaking AsExternalTypeDeserializer</li>
<li>
<h1>4922: Failing '@JsonMerge' with a custom Map</h1>
</li>
<li>
<h1>4932: Conversion of 'MissingNode' throws</h1>
'JsonProcessingException'</li>
<li>Changes of 2.18.2</li>
<li>
<h1>4733: Wrong serialization of Type Ids for certain types of</h1>
Enum values</li>
<li>
<h1>4742: Deserialization with Builder, External type id,</h1>
'@JsonCreator' failing</li>
<li>
<h1>4777: 'StdValueInstantiator.withArgsCreator' is now set for</h1>
creators with no arguments</li>
<li>
<h1>4783 Possibly wrong behavior of @JsonMerge</h1>
</li>
<li>
<h1>4787: Wrong 'String.format()' in 'StdDelegatingDeserializer'</h1>
hides actual error</li>
<li>
<h1>4788: 'EnumFeature.WRITE_ENUMS_TO_LOWERCASE' overrides</h1>
'@JsonProperty' values</li>
<li>
<h1>4790: Fix '@JsonAnySetter' issue with "setter" method</h1>
(related to #4639)</li>
<li>
<h1>4807: Improve 'FactoryBasedEnumDeserializer' to work better</h1>
with XML module</li>
<li>
<h1>4810: Deserialization using '@JsonCreator' with renamed</h1>
property failing (since 2.18)</li>
<li>Changes of 2.18.1</li>
<li>
<h1>4508: Deserialized JsonAnySetter field in Kotlin data class</h1>
is null</li>
<li>
<h1>4639: @JsonAnySetter on field ignoring unrecognized</h1>
properties if they are declared before the last recognized
properties in JSON</li>
<li>
<h1>4718: Should not fail on trying to serialize</h1>
'java.time.DateTimeException'</li>
<li>
<h1>4724: Deserialization behavior change with Records,</h1>
'@JsonCreator' and '@JsonValue' between 2.17 and 2.18</li>
<li>
<h1>4727: Eclipse having issues due'module-info' class "lost" on</h1>
2.18.0 jars</li>
<li>
<h1>4741: When 'Include.NON_DEFAULT' setting is used on POJO,</h1>
empty values are not included in json if default is 'null'</li>
<li>
<h1>4749: Fixed a problem with</h1>
'StdDelegatingSerializer#serializeWithType' looking up the
serializer with the wrong argument</li>
<li>Changes of 2.18.0</li>
<li>
<h1>562: Allow '@JsonAnySetter' to flow through Creators</h1>
</li>
<li>
<h1>806: Problem with 'NamingStrategy', creator methods with</h1>
implicit names</li>
<li>
<h1>2977: Incompatible 'FAIL_ON_MISSING_PRIMITIVE_PROPERTIES' and</h1>
field level '@JsonProperty'</li>
<li>
<h1>3120: Return 'ListIterator' from 'ArrayNode.elements()'</h1>
</li>
<li>
<h1>3241: 'constructorDetector' seems to invalidate</h1>
'defaultSetterInfo' for nullability</li>
<li>
<h1>3439: Java Record '@JsonAnySetter' value is null after</h1>
deserialization</li>
<li>
<h1>4085: '@JsonView' does not work on class-level for records</h1>
</li>
<li>
<h1>4119: Exception when deserialization uses a record with a</h1>
constructor property with 'access=READ_ONLY'</li>
<li>
<h1>4356: 'BeanDeserializerModifier::updateBuilder()' doesn't</h1>
work for beans with Creator methods</li>
<li>
<h1>4407: 'null' type id handling does not work with</h1>
'writeTypePrefix()'</li>
<li>
<h1>4452: '@JsonProperty' not serializing field names properly on</h1>
'@JsonCreator' in Record</li>
<li>
<h1>4453: Allow JSON Integer to deserialize into a single-arg</h1>
constructor of parameter type 'double'</li>
<li>
<h1>4456: Rework locking in 'DeserializerCache'</h1>
</li>
<li>
<h1>4458: Rework synchronized block from 'BeanDeserializerBase'</h1>
</li>
<li>
<h1>4464: When 'Include.NON_DEFAULT' setting is used, 'isEmpty()'</h1>
method is not called on the serializer</li>
<li>
<h1>4472: Rework synchronized block in 'TypeDeserializerBase'</h1>
</li>
<li>
<h1>4483: Remove 'final' on method BeanSerializer.serialize()</h1>
</li>
<li>
<h1>4515: Rewrite Bean Property Introspection logic in Jackson</h1>
2.x</li>
<li>
<h1>4545: Unexpected deserialization behavior with</h1>
'@JsonCreator', '@JsonProperty' and javac '-parameters'</li>
<li>
<h1>4570: Deprecate 'ObjectMapper.canDeserialize()'/'ObjectMapper</h1>
.canSerialize()'</li>
<li>
<h1>4580: Add 'MapperFeature</h1>
.SORT_CREATOR_PROPERTIES_BY_DECLARATION_ORDER' to use Creator
properties' declaration order for sorting</li>
<li>
<h1>4584: Provide extension point for detecting "primary"</h1>
Constructor for Kotlin (and similar) data classes</li>
<li>
<h1>4602: Possible wrong use of _arrayDelegateDeserializer in</h1>
BeanDeserializerBase::deserializeFromObjectUsingNonDefault()</li>
<li>
<h1>4617: Record property serialization order not preserved</h1>
</li>
<li>
<h1>4626: '@JsonIgnore' on Record property ignored for</h1>
deserialization, if there is getter override</li>
<li>
<h1>4630: '@JsonIncludeProperties', '@JsonIgnoreProperties'</h1>
ignored when serializing Records, if there is getter override</li>
<li>
<h1>4634: '@JsonAnySetter' not working when annotated on both</h1>
constructor parameter & field</li>
<li>
<h1>4678: Java records don't serialize with 'MapperFeature</h1>
.REQUIRE_SETTERS_FOR_GETTERS'</li>
<li>
<h1>4688: Should allow deserializing with no-arg</h1>
'@JsonCreator(mode = DELEGATING)'</li>
<li>
<h1>4694: Deserializing 'BigDecimal' with large number of</h1>
decimals result in incorrect value</li>
<li>
<h1>4699: Add extra 'writeNumber()' method in 'TokenBuffer'</h1>
</li>
<li>
<h1>4709: Add 'JacksonCollectors' with 'toArrayNode()'</h1>
implementation</li>
<li>Fix #5962: Case-insensitive deserialization may use wrong
@JsonIgnoreProperties (bsc#1268902, CVE-2026-54515)</li>
</ul>
<h2>Patch Instructions:</h2>
<p>
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".<br/>
Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">
<li class="list-group-item">
SUSE Linux Enterprise Server 16.0
<br/>
<code>zypper in -t patch SUSE-SLES-16.0-1124=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Server for SAP applications 16.0
<br/>
<code>zypper in -t patch SUSE-SLES-16.0-1124=1</code>
</li>
</ul>
<h2>Package List:</h2>
<ul>
<li>
SUSE Linux Enterprise Server 16.0 (noarch)
<ul>
<li>jackson-core-2.18.8-160000.1.1</li>
<li>jackson-databind-javadoc-2.18.8-160000.1.1</li>
<li>jackson-databind-2.18.8-160000.1.1</li>
<li>jackson-annotations-2.18.8-160000.1.1</li>
<li>jackson-annotations-javadoc-2.18.8-160000.1.1</li>
<li>jackson-core-javadoc-2.18.8-160000.1.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
<ul>
<li>jackson-core-2.18.8-160000.1.1</li>
<li>jackson-databind-javadoc-2.18.8-160000.1.1</li>
<li>jackson-databind-2.18.8-160000.1.1</li>
<li>jackson-annotations-2.18.8-160000.1.1</li>
<li>jackson-annotations-javadoc-2.18.8-160000.1.1</li>
<li>jackson-core-javadoc-2.18.8-160000.1.1</li>
</ul>
</li>
</ul>
<h2>References:</h2>
<ul>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-54512.html">https://www.suse.com/security/cve/CVE-2026-54512.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-54513.html">https://www.suse.com/security/cve/CVE-2026-54513.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-54514.html">https://www.suse.com/security/cve/CVE-2026-54514.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-54515.html">https://www.suse.com/security/cve/CVE-2026-54515.html</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268603">https://bugzilla.suse.com/show_bug.cgi?id=1268603</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268897">https://bugzilla.suse.com/show_bug.cgi?id=1268897</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268898">https://bugzilla.suse.com/show_bug.cgi?id=1268898</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268899">https://bugzilla.suse.com/show_bug.cgi?id=1268899</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268902">https://bugzilla.suse.com/show_bug.cgi?id=1268902</a>
</li>
</ul>
</div>