openSUSE-SU-2026:21375-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21375-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21375-1
Upstream
CVE (3)
Related
Published
2026-07-18T12:43:11Z
Modified
2026-07-22T18:24:11Z
Summary
Security update for jackson-annotations, jackson-core, jackson-databind
Details

This update for jackson-annotations, jackson-core, jackson-databind fixes the following issues:

  • CVE-2026-54515: rebuilding the property map from unfiltered bean properties could permit a bypass of @JsonIgnoreProperties exclusions (bsc#1268902).
  • CVE-2026-59889: missing view guard when deserializing @JsonUnwrapped properties could allow unauthorized writes to @JsonView restricted fields (bsc#1271440).
  • CVE-2026-59888: mismatch between property renaming and ignore-filtering on Java Records could allow a bypass of @JsonIgnore restrictions (bsc#1271442).

Changes for jackson-annotations:

  • Update to 2.18.9.

Changes for jackson-core:

  • Update to 2.18.9.

Changes for jackson-databind:

  • Update to 2.18.9:
  • honor @JsonView for external-type-id (EXTERNAL_PROPERTY) properties (GHSA-mhm7-754m-9p8w).
References

Affected packages

openSUSE:Leap 16.0 / jackson-annotations

Package

Name
jackson-annotations
Purl
pkg:rpm/opensuse/jackson-annotations&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.18.9-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "jackson-annotations":  "2.18.9-160000.1.1",
            "jackson-annotations-javadoc":  "2.18.9-160000.1.1",
            "jackson-core":  "2.18.9-160000.1.1",
            "jackson-core-javadoc":  "2.18.9-160000.1.1",
            "jackson-databind":  "2.18.9-160000.1.1",
            "jackson-databind-javadoc":  "2.18.9-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21375-1.json"

openSUSE:Leap 16.0 / jackson-core

Package

Name
jackson-core
Purl
pkg:rpm/opensuse/jackson-core&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.18.9-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "jackson-annotations":  "2.18.9-160000.1.1",
            "jackson-annotations-javadoc":  "2.18.9-160000.1.1",
            "jackson-core":  "2.18.9-160000.1.1",
            "jackson-core-javadoc":  "2.18.9-160000.1.1",
            "jackson-databind":  "2.18.9-160000.1.1",
            "jackson-databind-javadoc":  "2.18.9-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21375-1.json"

openSUSE:Leap 16.0 / jackson-databind

Package

Name
jackson-databind
Purl
pkg:rpm/opensuse/jackson-databind&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.18.9-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "jackson-annotations":  "2.18.9-160000.1.1",
            "jackson-annotations-javadoc":  "2.18.9-160000.1.1",
            "jackson-core":  "2.18.9-160000.1.1",
            "jackson-core-javadoc":  "2.18.9-160000.1.1",
            "jackson-databind":  "2.18.9-160000.1.1",
            "jackson-databind-javadoc":  "2.18.9-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21375-1.json"