StackRadar

CVE-2020-26945

High

Advisory

Published 22 Apr 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

"Deserialization errors in MyBatis"

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
mybatismaven3.4.0, 3.4.2, 3.4.4, 3.4.5+4 more3.5.611
OSV records
GHSA-qq48-m4jx-xqh8

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
guacamolehalkeye0.2.11 of 3See more

guacamole halkeye 0.2.1

1 of the 3 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
guacamole/guacamole:1.1.0333a7f40c145
mybatis@3.4.6
3.5.6

Open the chart page →

4,839
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
mybatis@3.4.2
3.5.6

Open the chart page →

9,808
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
mybatis@3.4.6
3.5.6

Open the chart page →

9,144
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
mybatis@3.4.6
3.5.6

Open the chart page →

16,860
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
mybatis@3.4.0
3.5.6

Open the chart page →

12,513
mod-marccatfolio-org0.1.301 of 1See more

mod-marccat folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
folioci/mod-marccat:latest1b57d690d568
mybatis@3.4.5
3.5.6

Open the chart page →

6,988
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
guacamole/guacamole:1.3.0739cb6820ae8
mybatis@3.4.6
3.5.6

Open the chart page →

6,412
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
mybatis@3.5.5
3.5.6

Open the chart page →

12,856
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
mybatis@3.5.4
3.5.6

Open the chart page →

26,356
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
mybatis@3.4.6
3.5.6

Open the chart page →

15,855
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
mybatis@3.4.0
3.5.6

Open the chart page →

12,513
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
mybatis@3.4.4
3.5.6

Open the chart page →

11,841
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
mybatis@3.4.0
3.5.6

Open the chart page →

12,513
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2020-26945.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
mybatis@3.5.3
3.5.6

Open the chart page →

5,460

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-admin:2.4.2e8b7c4ddd069
mybatis@3.4.0
3.5.6
3
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
mybatis@3.4.6
3.5.6
2
choerodon/event-store-service:0.8.03c94c97f6f69
mybatis@3.4.2
3.5.6
1
folioci/mod-marccat:latest1b57d690d568
mybatis@3.4.5
3.5.6
1
gocd/gocd-server:v19.3.02da45cb09d57
mybatis@3.4.6
3.5.6
1
guacamole/guacamole:1.1.0333a7f40c145
mybatis@3.4.6
3.5.6
1
guacamole/guacamole:1.3.0739cb6820ae8
mybatis@3.4.6
3.5.6
1
ladeit/ladeit:latest962b665ffe82
mybatis@3.5.4
3.5.6
1
library/sonarqube:6.7.6-community0ae5169e3d0f
mybatis@3.4.4
3.5.6
1
library/sonarqube:8.2-communitya246bc64207e
mybatis@3.5.3
3.5.6
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
mybatis@3.5.5
3.5.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.