RHSA-2026:54440: Red Hat Lightspeed (formerly Insights) for Runtimes security update
An update is now available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9.Security fix(es): jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) jackson-databind: @JsonIgnore bypass in Java Records (CVE-2026-59888) jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193) jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Red Hat Lightspeed (formerly Insights) for Runtimes security update
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54440?
The severity of RHSA-2026:54440 is rated as high with a score of 7.
What vulnerabilities are addressed in RHSA-2026:54440?
RHSA-2026:54440 addresses vulnerabilities including CVE-2026-68494 and CVE-2026-59888.
How do I fix RHSA-2026:54440?
To fix RHSA-2026:54440, you should apply the latest security update available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9.
What product does RHSA-2026:54440 pertain to?
RHSA-2026:54440 pertains to Red Hat Lightspeed (formerly Insights) for Runtimes.
When was RHSA-2026:54440 published?
RHSA-2026:54440 was published on August 12, 2026.