CVE-2026-54513

Red Hat Security Advisory: Streams for Apache Kafka 3.2.1 release and security update

Description

A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the system to process untrusted data, which may lead to the execution of malicious code. This could result in a complete compromise of the affected system, impacting its confidentiality, integrity, and availability.

Metrics

Severity
high
no public PoC known
8.1
Source: nvd-v3
57.3 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.9 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-12 19:35 UTC
CWE-184

Weakness classes (CWE)

  • CWE-184Base

    Incomplete List of Disallowed Inputs

    The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-06 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:50846
    • Reference: https://access.redhat.com/errata/RHSA-2026:50847
    • Reference: https://access.redhat.com/errata/RHSA-2026:50848
    • Reference: https://access.redhat.com/errata/RHSA-2026:50849
  2. CVE Modified2026-07-30 12:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:48095
    • Reference: https://access.redhat.com/errata/RHSA-2026:48151
  3. CVE Modified2026-07-23 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:43400
    • Reference: https://access.redhat.com/errata/RHSA-2026:44061
    • Reference: https://access.redhat.com/errata/RHSA-2026:44062
    • Reference: https://access.redhat.com/errata/RHSA-2026:44063
  4. CVE Modified2026-07-22 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:43218
    • Affected: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux 9 (+85)Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux 8 (+85)
  5. CVE Modified2026-07-21 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:41951
    • Affected: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat Enterprise Linux 9, Cryostat 4 (+85)Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux 9 (+85)

Affected operating systems

  • linux

    ubuntu / nettynoble

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apache

    kafka2.8.0 – 3.9.2

  • apache

    kafka4.0.0 – 4.0.2

  • apache

    kafka4.1.0 – 4.1.2

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    golang1.26.0-0

  • eclipse

    vert.x4.0.0 – 4.5.29

  • eclipse

    vert.x5.0.0 – 5.1.4

  • go

    stdlib1.26.0-0

  • golang

    go1.26.0 – 1.26.2

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    go1.25.9

  • golang

    net0.55.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

References & sources

Linked CVEs

Show 33 more CVEs
IDCVE-2026-54513