StackRadar

CVE-2026-18401

Medium

Advisory

Published 28 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
314
deployed by those charts
Fix available
1 of 1
affected package

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 314 images.

Affected packageAffected versionsFixed inImages
jackson-coremaven2.15.0, 2.15.2, 2.15.3, 2.15.4+21 more2.18.6, 2.21.1, 3.1.0314
OSV records
GHSA-72hv-8253-57qq

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
hazelcastwenerme5.10.22 of 2See more

hazelcast wenerme 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
jackson-core@2.17.2
2.18.6
hazelcast/management-center:5.5.2991ddb27c251
jackson-core@2.17.2
2.18.6

Open the chart page →

2,634
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
jackson-core@2.15.0
2.18.6

Open the chart page →

2,191
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
jackson-core@2.19.2
2.21.1

Open the chart page →

7,624
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-core@2.15.3
2.18.6

Open the chart page →

11,577
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-core@2.17.2
2.18.6

Open the chart page →

9,381
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
jackson-core@2.15.2
2.18.6

Open the chart page →

3,480
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
jackson-core@2.18.0
2.18.6

Open the chart page →

1,571

Container images carrying it

314 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
featurehub/edge:1.9.198ad426737f6
jackson-core@2.17.2
2.18.6
1
featurehub/mr:1.9.1477d8bf771a9
jackson-core@2.17.2
2.18.6
1
flowable/flowable-rest:7.1.0b7ae287502cd
jackson-core@2.17.2
2.18.6
1
folioci/edge-connexion:latestb4863d135524
jackson-core@2.18.2
2.18.6
1
folioci/edge-ncip:lateste760dbb81d1a
jackson-core@2.18.2
2.18.6
1
folioci/edge-oai-pmh:latesteedfcbc29792
jackson-core@2.18.2
2.18.6
1
folioci/edge-patron:latest682b852e056d
jackson-core@2.18.2
2.18.6
1
folioci/edge-rtac:latest15ef73b1abd0
jackson-core@3.0.4
3.1.0
1
folioci/mod-authtoken:latest995a25a33133
jackson-core@2.16.1
2.18.6
1
folioci/mod-courses:latest68ca414f5596
jackson-core@2.18.2
2.18.6
1
folioci/mod-data-export:latest0cc86bf09755
jackson-core@3.0.4
3.1.0
1
folioci/mod-data-export-spring:latestf1d7caf4544b
jackson-core@3.0.4
3.1.0
1
folioci/mod-data-export-worker:latest1ad1811c9b37
jackson-core@2.20.2
2.21.1
1
folioci/mod-ebsconet:latest3ae8cb99daa3
jackson-core@2.20.2
2.21.1
1
folioci/mod-email:latest79ea8e2e7ebf
jackson-core@2.18.2
2.18.6
1
folioci/mod-eusage-reports:latest15de67587091
jackson-core@2.18.2
2.18.6
1
folioci/mod-feesfines:latestfe3a7049f2fb
jackson-core@2.18.2
2.18.6
1
folioci/mod-gobi:latestc58c989dac44
jackson-core@2.20.1
2.21.1
1
folioci/mod-inventory-update:latestba84812b4d58
jackson-core@2.18.2
2.18.6
1
folioci/mod-ldp:latestb55696fd9065
jackson-core@2.15.4
2.18.6
1
folioci/mod-login:latest88de493f86db
jackson-core@2.16.1
2.18.6
1
folioci/mod-ncip:latest8ed83674352b
jackson-core@2.18.2
2.18.6
1
folioci/mod-oai-pmh:latest5cd5ef063f2a
jackson-core@2.18.2
2.18.6
1
folioci/mod-patron:latest5f213acfe2f8
jackson-core@2.18.2
2.18.6
1
folioci/mod-remote-storage:latest4f12177123dc
jackson-core@2.17.2
2.18.6
1
folioci/mod-rtac:latestc959b2d6142f
jackson-core@2.18.2
2.18.6
1
folioci/mod-sender:latestd88a675dddf0
jackson-core@2.18.2
2.18.6
1
folioci/mod-template-engine:latestd105c585da30
jackson-core@2.18.2
2.18.6
1
folioci/mod-users-bl:latest4e2d96c9340d
jackson-core@2.18.2
2.18.6
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
jackson-core@2.15.3
2.18.6
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
jackson-core@2.21.0
2.21.1
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
jackson-core@2.21.0
2.21.1
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
jackson-core@2.21.0
2.21.1
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
jackson-core@2.21.0
2.21.1
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
jackson-core@2.21.0
2.21.1
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
jackson-core@2.21.0
2.21.1
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
jackson-core@2.21.0
2.21.1
1
glasskube/operator:0.12.2be5133100d63
jackson-core@2.15.2
2.18.6
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
jackson-core@2.17.2
2.18.6
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
jackson-core@2.17.2
2.18.6
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
jackson-core@2.17.2
2.18.6
1
gotson/komga:1.22.0ba892ab3e082
jackson-core@2.18.1
2.18.6
1
graviteeio/ae-engine:3.0.24140932887e0
jackson-core@2.18.3
2.18.6
1
graylog/graylog:6.1.1019de1aff48c2
jackson-core@2.17.2
2.18.6
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
jackson-core@2.19.2
2.21.1
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
jackson-core@2.19.4
2.21.1
1
gridgain/community:8.9.11d32d182a0e6a
jackson-core@2.16.0
2.18.6
1
gridgain/gridgain9:9.1.1895018390077b
jackson-core@2.19.2
2.21.1
1
guacamole/guacamole:1.5.50f62f6d17ab3
jackson-core@2.17.0
2.18.6
1
hazelcast/hazelcast:5.3.18fe26efde8e1
jackson-core@2.15.2
2.18.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.