Skip to content
Moderate Security Updates for Jackson Libraries Address Multiple Vulnerabilities

Moderate Security Updates for Jackson Libraries Address Multiple Vulnerabilities

First seen 28 Jul 2026, 10:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 29, 2026 at 05:12 UTC
  • SUSE released moderate updates for Jackson libraries addressing three CVEs.
  • CVE-2026-54515 could allow unauthorized access by bypassing @JsonIgnoreProperties.
  • Users are urged to audit Linux privileges to limit potential exploitation.

SUSE has released two moderate security updates addressing vulnerabilities in the Jackson libraries, specifically jackson-annotations, jackson-core, and jackson-databind. The updates fix three CVEs: CVE-2026-54515, CVE-2026-59889, and CVE-2026-59888, which could lead to unauthorized access and data manipulation. CVE-2026-54515 allows bypassing @JsonIgnoreProperties exclusions, while CVE-2026-59889 and CVE-2026-59888 involve issues with property deserialization and renaming. The updates are applicable to various SUSE products, including SUSE 15 SP7. The vulnerabilities were published between June 23 and July 14, 2026. Users are advised to audit Linux privileges to mitigate potential risks. The updates are available as of July 27, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-06-23
CVE-2026-54515 published
This vulnerability allows bypassing @JsonIgnoreProperties exclusions, posing a risk to data security.
Linuxsecurity
2026-07-14
CVE-2026-59889 published
This vulnerability involves a missing view guard when deserializing @JsonUnwrapped properties, allowing unauthorized writes.
Linuxsecurity
2026-07-14
CVE-2026-59888 published
This vulnerability allows a mismatch between property renaming and ignore-filtering on Java Records, leading to potential data exposure.
Linuxsecurity
2026-07-27
SUSE releases updates for Jackson libraries
Moderate security updates were released to address the identified vulnerabilities in the Jackson libraries.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track SuSE and CVE-2026-54515 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed