RHSA-2026:44066: Important: pki-deps:10.6 security update
Important: pki-deps:10.6 security update
Other sources
The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System.Security Fix(es): jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513) jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/apache-commons-collectionsto a version that resolves this vulnerability.Fixed in 3.2.2-10.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/apache-commons-langto a version that resolves this vulnerability.Fixed in 2.6-21.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/apache-commons-netto a version that resolves this vulnerability.Fixed in 3.6-3.module+el8.3.0+6805+72837426 - Upgrade
Upgrade
redhat/bea-staxto a version that resolves this vulnerability.Fixed in 1.2.0-16.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/fasterxml-oss-parentto a version that resolves this vulnerability.Fixed in 75-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/glassfish-fastinfosetto a version that resolves this vulnerability.Fixed in 1.2.13-9.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/glassfish-jaxbto a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/glassfish-jaxb-apito a version that resolves this vulnerability.Fixed in 2.2.12-8.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/jackson-annotationsto a version that resolves this vulnerability.Fixed in 2.21-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/jackson-bomto a version that resolves this vulnerability.Fixed in 2.21.4-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/jackson-coreto a version that resolves this vulnerability.Fixed in 2.21.4-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.21.4-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/jackson-jaxrs-providersto a version that resolves this vulnerability.Fixed in 2.21.4-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/jackson-modules-baseto a version that resolves this vulnerability.Fixed in 2.21.4-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/jackson-parentto a version that resolves this vulnerability.Fixed in 2.21-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/jakarta-commons-httpclientto a version that resolves this vulnerability.Fixed in 3.1-28.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/javassistto a version that resolves this vulnerability.Fixed in 3.18.1-8.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/pki-servlet-engineto a version that resolves this vulnerability.Fixed in 9.0.62-1.module+el8.8.0+22367+4894538d - Upgrade
Upgrade
redhat/python-nssto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/resteasyto a version that resolves this vulnerability.Fixed in 3.0.26-7.module+el8.8.0+22365+b433a336 - Upgrade
Upgrade
redhat/slf4jto a version that resolves this vulnerability.Fixed in 1.7.25-4.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/stax-exto a version that resolves this vulnerability.Fixed in 1.7.7-8.module+el8.2.0+5723+4574fbff - Upgrade
Upgrade
redhat/velocityto a version that resolves this vulnerability.Fixed in 1.7-24.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/xalan-j2to a version that resolves this vulnerability.Fixed in 2.7.1-38.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/xerces-j2to a version that resolves this vulnerability.Fixed in 2.11.0-34.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/xml-commons-apisto a version that resolves this vulnerability.Fixed in 1.4.01-25.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/xml-commons-resolverto a version that resolves this vulnerability.Fixed in 1.2-26.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/xmlstreambufferto a version that resolves this vulnerability.Fixed in 1.5.4-8.module+el8.2.0+5723+4574fbff - Upgrade
Upgrade
redhat/xsomto a version that resolves this vulnerability.Fixed in 0-19.20110809svn.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/bea-stax-apito a version that resolves this vulnerability.Fixed in 1.2.0-16.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/glassfish-jaxb-coreto a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/glassfish-jaxb-runtimeto a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/glassfish-jaxb-txw2to a version that resolves this vulnerability.Fixed in 2.2.11-11.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/jackson-jaxrs-json-providerto a version that resolves this vulnerability.Fixed in 2.21.4-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/jackson-module-jaxb-annotationsto a version that resolves this vulnerability.Fixed in 2.21.4-1.module+el8.8.0+24520+bae56b06 - Upgrade
Upgrade
redhat/javassist-javadocto a version that resolves this vulnerability.Fixed in 3.18.1-8.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/python-nss-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/python-nss-docto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/python3-nssto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/python3-nss-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.1-10.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
redhat/slf4j-jdk14to a version that resolves this vulnerability.Fixed in 1.7.25-4.module+el8.1.0+3366+6dfb954c - Upgrade
Upgrade
jackson-databindto a version that resolves this vulnerability.Patch CVE-2026-54512 - Upgrade
Upgrade
jackson-databindto a version that resolves this vulnerability.Patch CVE-2026-54513 - Upgrade
Upgrade
pki-depsto a version that resolves this vulnerability.Fixed in 10.6
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:44066?
The severity of RHSA-2026:44066 is classified as high with a score of 7.
What is the description of RHSA-2026:44066?
RHSA-2026:44066 is an important security update related to pki-deps:10.6.
Which software is affected by RHSA-2026:44066?
RHSA-2026:44066 affects several Red Hat Enterprise Linux variants including x86_64 and Power LE for various services.
How do I fix RHSA-2026:44066?
To fix RHSA-2026:44066, you should apply the security update available for your version of Red Hat Enterprise Linux.
When was RHSA-2026:44066 published?
RHSA-2026:44066 was published on July 23, 2026.