tejinfobelt opened a new issue, #3668:
URL: https://github.com/apache/parquet-java/issues/3668

   ### Describe the bug, including details regarding any error messages, 
version, and platform.
   
   Looking for the release with the fix of 
   
   CVE-2026-54513
   jackson-databind contains the general-purpose data-binding functionality and 
tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 
3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists 
any array type based only on clazz.isArray(), without validating the array's 
component (element) type against the configured allowlist. A PTV built with 
allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore 
still permits EvilType[] even though EvilType is not allowlisted. When Jackson 
deserializes the elements and no per-element type IDs are present, it 
instantiates the component type directly with no further PTV check, bypassing 
the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
   CVE-2026-54512
   jackson-databind contains the general-purpose data-binding functionality and 
tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 
3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety 
mechanism guarding polymorphic deserialization. When polymorphic typing is 
enabled and a type identifier contains generic parameters (i.e. the type ID 
string contains <), DatabindContext._resolveAndValidateGeneric() validates only 
the raw container class name (the substring before <) against the configured 
PTV. If the container type is approved, the method parses the full canonical 
type string via TypeFactory.constructFromCanonical() and returns the fully 
parameterized type without ever validating the nested type arguments against 
the PTV. The nested type arguments are then resolved, instantiated, and 
populated as beans during deserialization. An attacker who controls the type ID 
can therefore place a denied class as a generic type parameter of an allo
 wed container — for example java.util.ArrayList<com.evil.Gadget> when only 
java.util.ArrayList is allow-listed. The container passes the PTV check; 
com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, 
and its properties are set from attacker-controlled JSON. This completely 
bypasses an explicitly configured PTV allow-list. This vulnerability is fixed 
in 2.18.8, 2.21.4, and 3.1.4.
   
   any tentetive timeline?
   
   
   ### Component(s)
   
   Build


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to