https://bugzilla.redhat.com/show_bug.cgi?id=2494757
Bug ID: 2494757
Summary: CVE-2026-13503 antlr3: antlr ANTLR4: Path traversal
via manipulation of getImportedVocabFile function
[fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["b60b9e3c-a459-4271-9161-9985b7197ae3"]}
Component: antlr3
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: loganjerry(a)gmail.com
Reporter: gnaik(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: dchen(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
java-sig-commits(a)lists.fedoraproject.org,
loganjerry(a)gmail.com, michel(a)michel-slm.name,
mizdebsk(a)redhat.com, mkoncek(a)redhat.com,
walters(a)redhat.com
Blocks: 2493994
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this
issue is the function getImportedVocabFile of the file
tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab
Grammar Option Handler. The manipulation results in path traversal. The attack
can be executed remotely. The exploit is now public and may be used. The vendor
was contacted early about this disclosure but did not respond in any way.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2494757
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2232716
Bug ID: 2232716
Summary: pdfbox-3.0.0 is available
Product: Fedora
Version: rawhide
Status: NEW
Component: pdfbox
Keywords: FutureFeature, Triaged
Assignee: jvanek(a)redhat.com
Reporter: upstream-release-monitoring(a)fedoraproject.org
QA Contact: extras-qa(a)fedoraproject.org
CC: didiksupriadi41(a)gmail.com,
java-sig-commits(a)lists.fedoraproject.org,
jvanek(a)redhat.com, puntogil(a)libero.it,
sergio(a)serjux.com
Target Milestone: ---
Classification: Fedora
Releases retrieved: 3.0.0
Upstream release that is considered latest: 3.0.0
Current version/release in rawhide: 2.0.29-2.fc39
URL: http://pdfbox.apache.org/
Please consult the package updates policy before you issue an update to a
stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/
More information about the service that created this bug can be found at:
https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_M…
Please keep in mind that with any upstream change, there may also be packaging
changes that need to be made. Specifically, please remember that it is your
responsibility to review the new version to ensure that the licensing is still
correct and that no non-free or legally problematic items have been added
upstream.
Based on the information from Anitya:
https://release-monitoring.org/project/9648/
To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/pdfbox
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2232716
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2495370
Bug ID: 2495370
Summary: CVE-2026-54517 jackson-jaxrs-providers:
jackson-databind: Information disclosure via improper
JsonView filter application [fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["58bc411d-77cc-4633-aa65-e689e4e1d0eb"]}
Component: jackson-jaxrs-providers
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: edewata(a)redhat.com
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: ckelley(a)redhat.com, edewata(a)redhat.com,
java-sig-commits(a)lists.fedoraproject.org,
mfargett(a)redhat.com
Blocks: 2492002
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
jackson-databind contains the general-purpose data-binding functionality and
tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in
BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView)
filter was applied only to creator properties; the regular property-buffering
branch performed no prop.visibleInView(activeView) check. A change making
SetterlessProperty.isMerging() return true routed setterless Collection/Map
properties through this unguarded path, so a setterless collection annotated
with a restricted @JsonView is populated from attacker JSON even when the
active view excludes it. This vulnerability is fixed in 2.21.4 and 3.1.4.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2495370
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2495368
Bug ID: 2495368
Summary: CVE-2026-54517 jackson-modules-base: jackson-databind:
Information disclosure via improper JsonView filter
application [fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["58bc411d-77cc-4633-aa65-e689e4e1d0eb"]}
Component: jackson-modules-base
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: mfargett(a)redhat.com
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: ckelley(a)redhat.com, edewata(a)redhat.com,
java-sig-commits(a)lists.fedoraproject.org,
mfargett(a)redhat.com
Blocks: 2492002
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
jackson-databind contains the general-purpose data-binding functionality and
tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in
BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView)
filter was applied only to creator properties; the regular property-buffering
branch performed no prop.visibleInView(activeView) check. A change making
SetterlessProperty.isMerging() return true routed setterless Collection/Map
properties through this unguarded path, so a setterless collection annotated
with a restricted @JsonView is populated from attacker JSON even when the
active view excludes it. This vulnerability is fixed in 2.21.4 and 3.1.4.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2495368
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2495343
Bug ID: 2495343
Summary: CVE-2026-54516 jackson-modules-base: jackson-databind:
Security bypass due to improper handling of renamed
properties [fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["0185daed-f569-4b79-b279-714d180861fb"]}
Component: jackson-modules-base
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: mfargett(a)redhat.com
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: ckelley(a)redhat.com, edewata(a)redhat.com,
java-sig-commits(a)lists.fedoraproject.org,
mfargett(a)redhat.com
Blocks: 2491996
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
jackson-databind contains the general-purpose data-binding functionality and
tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4,
POJOPropertiesCollector._renameProperties() allows a property with
@JsonProperty("renamed") on the getter and @JsonIgnore on the setter to be
renamed rather than dropped. With MapperFeature.INFER_PROPERTY_MUTATORS enabled
(default), the private backing field is retained; during deserialization
BeanDeserializerFactory.addBeanProps() sees hasField()==true, builds a
FieldProperty, and makes the backing field writable. An attacker supplying the
renamed JSON key writes the backing field directly, bypassing the @JsonIgnore
on the setter. This vulnerability is fixed in 3.1.4.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2495343
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2495336
Bug ID: 2495336
Summary: CVE-2026-54518 jackson-modules-base: jackson-databind:
Information disclosure and data manipulation via
view-based access control bypass [fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["6882c43b-5c82-46aa-9021-3fd62ec0f231"]}
Component: jackson-modules-base
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: mfargett(a)redhat.com
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: ckelley(a)redhat.com, edewata(a)redhat.com,
java-sig-commits(a)lists.fedoraproject.org,
mfargett(a)redhat.com
Blocks: 2492014
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
jackson-databind contains the general-purpose data-binding functionality and
tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4,
UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered
JSON into creator parameters but never consults prop.visibleInView(activeView).
The normal property-based creator path gates creator properties on the active
view, but this unwrapped-creator replay path bypasses that check, so a
constructor parameter annotated with both @JsonView(AdminView.class) and
@JsonUnwrapped is populated from attacker JSON even when a more restrictive
view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2495336
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2495330
Bug ID: 2495330
Summary: CVE-2026-54518 jackson-jaxrs-providers:
jackson-databind: Information disclosure and data
manipulation via view-based access control bypass
[fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["6882c43b-5c82-46aa-9021-3fd62ec0f231"]}
Component: jackson-jaxrs-providers
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: edewata(a)redhat.com
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: ckelley(a)redhat.com, edewata(a)redhat.com,
java-sig-commits(a)lists.fedoraproject.org,
mfargett(a)redhat.com
Blocks: 2492014
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
jackson-databind contains the general-purpose data-binding functionality and
tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4,
UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered
JSON into creator parameters but never consults prop.visibleInView(activeView).
The normal property-based creator path gates creator properties on the active
view, but this unwrapped-creator replay path bypasses that check, so a
constructor parameter annotated with both @JsonView(AdminView.class) and
@JsonUnwrapped is populated from attacker JSON even when a more restrictive
view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2495330
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2495207
Bug ID: 2495207
Summary: CVE-2026-54512 jackson-modules-base: jackson-databind:
Arbitrary code execution via PolymorphicTypeValidator
bypass [fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["f81b3481-0d9d-48dd-9087-c22d67b3a578"]}
Component: jackson-modules-base
Keywords: Security, SecurityTracking
Severity: high
Priority: high
Assignee: mfargett(a)redhat.com
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: ckelley(a)redhat.com, edewata(a)redhat.com,
java-sig-commits(a)lists.fedoraproject.org,
mfargett(a)redhat.com
Blocks: 2492015
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
jackson-databind contains the general-purpose data-binding functionality and
tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and
3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety
mechanism guarding polymorphic deserialization. When polymorphic typing is
enabled and a type identifier contains generic parameters (i.e. the type ID
string contains <), DatabindContext._resolveAndValidateGeneric() validates only
the raw container class name (the substring before <) against the configured
PTV. If the container type is approved, the method parses the full canonical
type string via TypeFactory.constructFromCanonical() and returns the fully
parameterized type without ever validating the nested type arguments against
the PTV. The nested type arguments are then resolved, instantiated, and
populated as beans during deserialization. An attacker who controls the type ID
can therefore place a denied class as a generic type parameter of an allowed
container — for example java.util.ArrayList<com.evil.Gadget> when only
java.util.ArrayList is allow-listed. The container passes the PTV check;
com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated,
and its properties are set from attacker-controlled JSON. This completely
bypasses an explicitly configured PTV allow-list. This vulnerability is fixed
in 2.18.8, 2.21.4, and 3.1.4.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2495207
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2495204
Bug ID: 2495204
Summary: CVE-2026-54512 jackson-jaxrs-providers:
jackson-databind: Arbitrary code execution via
PolymorphicTypeValidator bypass [fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["f81b3481-0d9d-48dd-9087-c22d67b3a578"]}
Component: jackson-jaxrs-providers
Keywords: Security, SecurityTracking
Severity: high
Priority: high
Assignee: edewata(a)redhat.com
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: ckelley(a)redhat.com, edewata(a)redhat.com,
java-sig-commits(a)lists.fedoraproject.org,
mfargett(a)redhat.com
Blocks: 2492015
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
jackson-databind contains the general-purpose data-binding functionality and
tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and
3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety
mechanism guarding polymorphic deserialization. When polymorphic typing is
enabled and a type identifier contains generic parameters (i.e. the type ID
string contains <), DatabindContext._resolveAndValidateGeneric() validates only
the raw container class name (the substring before <) against the configured
PTV. If the container type is approved, the method parses the full canonical
type string via TypeFactory.constructFromCanonical() and returns the fully
parameterized type without ever validating the nested type arguments against
the PTV. The nested type arguments are then resolved, instantiated, and
populated as beans during deserialization. An attacker who controls the type ID
can therefore place a denied class as a generic type parameter of an allowed
container — for example java.util.ArrayList<com.evil.Gadget> when only
java.util.ArrayList is allow-listed. The container passes the PTV check;
com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated,
and its properties are set from attacker-controlled JSON. This completely
bypasses an explicitly configured PTV allow-list. This vulnerability is fixed
in 2.18.8, 2.21.4, and 3.1.4.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2495204
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2495199
Bug ID: 2495199
Summary: CVE-2026-54515 jackson-jaxrs-providers:
jackson-databind: Ignored properties can be
unexpectedly modified [fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["54a6546b-41b2-4b8e-9762-ab6856caa660"]}
Component: jackson-jaxrs-providers
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: edewata(a)redhat.com
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: ckelley(a)redhat.com, edewata(a)redhat.com,
java-sig-commits(a)lists.fedoraproject.org,
mfargett(a)redhat.com
Blocks: 2492016
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
jackson-databind contains the general-purpose data-binding functionality and
tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and
3.1.4, in BeanDeserializerBase.createContextual(), per-property
@JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(),
producing a contextual deserializer whose BeanPropertyMap has the ignored
properties removed. The subsequent per-property case-insensitivity block
(triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from
this._beanProperties (the original, unfiltered map) instead of
contextual._beanProperties, then overwrites the filtered map — restoring every
property _handleByNameInclusion had just removed. The ignored property becomes
writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2495199
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…