StackRadar

CVE-2026-18401

Medium

Advisory

Published 28 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
314
deployed by those charts
Fix available
1 of 1
affected package

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 314 images.

Affected packageAffected versionsFixed inImages
jackson-coremaven2.15.0, 2.15.2, 2.15.3, 2.15.4+21 more2.18.6, 2.21.1, 3.1.0314
OSV records
GHSA-72hv-8253-57qq

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
hazelcastwenerme5.10.22 of 2See more

hazelcast wenerme 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
jackson-core@2.17.2
2.18.6
hazelcast/management-center:5.5.2991ddb27c251
jackson-core@2.17.2
2.18.6

Open the chart page →

2,634
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
jackson-core@2.15.0
2.18.6

Open the chart page →

2,191
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
jackson-core@2.19.2
2.21.1

Open the chart page →

7,624
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-core@2.15.3
2.18.6

Open the chart page →

11,577
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-core@2.17.2
2.18.6

Open the chart page →

9,381
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
jackson-core@2.15.2
2.18.6

Open the chart page →

3,480
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
jackson-core@2.18.0
2.18.6

Open the chart page →

1,571

Container images carrying it

314 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hazelcast/management-center:5.3.2f9d34300d330
jackson-core@2.15.2
2.18.6
1
hivemq/hivemq-edge:2026.13aba306d1f089
jackson-core@2.19.2
2.21.1
1
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
jackson-core@2.15.2
2.18.6
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
jackson-core@2.15.4
2.18.6
1
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
jackson-core@2.15.3
2.18.6
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
jackson-core@2.17.1
2.18.6
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
jackson-core@2.16.1
2.18.6
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
jackson-core@2.16.2
2.18.6
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
jackson-core@2.16.0
2.18.6
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
jackson-core@2.16.0
2.18.6
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
jackson-core@2.16.0
2.18.6
1
keyfactor/signserver-ce:7.3.2798fbbe00283
jackson-core@2.17.0
2.18.6
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
jackson-core@2.17.1
2.18.6
1
lavandadelpatio/tmdb:latestded9377636e9
jackson-core@2.15.3
2.18.6
1
library/cassandra:4.0093ee8ee5eb2
jackson-core@2.19.2
2.21.1
1
library/couchdb:3.4.22817ad50b5c5
jackson-core@2.17.2
2.18.6
1
library/elasticsearch:8.17.32cc40b15dff8
jackson-core@2.15.0
2.18.6
1
library/elasticsearch:8.15.0310b9fc03b06
jackson-core@2.15.0
2.18.6
1
library/elasticsearch:9.5.38d09295845fe
jackson-core@2.19.2
2.21.1
1
library/elasticsearch:9.5.19656a9ca03f8
jackson-core@2.19.2
2.21.1
1
library/logstash:9.1.233eae14f0867
jackson-core@2.16.2
2.18.6
1
library/neo4j:2026.02.25ab4ab0358cf
jackson-core@2.20.1
2.21.1
1
library/neo4j:5.18.18f01f7bb053e
jackson-core@2.16.1
2.18.6
1
library/sonarqube:10.7.0-community0842dcd4c8f8
jackson-core@2.17.1
2.18.6
1
library/zookeeper:3.8-temurin55d1e5b2e601
jackson-core@2.15.2
2.18.6
1
library/zookeeper:3.9.5cab8944a33a1
jackson-core@2.15.2
2.18.6
1
library/zookeeper:3.9.4dfa9ba46d14b
jackson-core@2.15.2
2.18.6
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
jackson-core@2.17.2
2.18.6
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
jackson-core@2.15.2
2.18.6
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
jackson-core@2.15.2
2.18.6
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
jackson-core@2.15.2
2.18.6
1
merlos/zookeeper:3.9.3a38fc7e09ed7
jackson-core@2.15.2
2.18.6
1
metabase/metabase:v0.53.4.17807bc5cad17
jackson-core@2.17.1
2.18.6
1
nacos/nacos-server:v3.0.20e951a1d07bb
jackson-core@2.18.3
2.18.6
1
nacos/nacos-server:v3.0.130a39cb0c54d
jackson-core@2.18.3
2.18.6
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
jackson-core@2.17.2
2.18.6
1
olvid/bot-daemon:2.0.1e0e6b165d879
jackson-core@2.15.2
2.18.6
1
openbas/platform:2.0.5d986d80b0a75
jackson-core@2.17.3
2.18.6
1
opensearchproject/data-prepper:2.8.057c25fa01d3c
jackson-core@2.17.0
2.18.6
1
opensearchproject/opensearch:2.15.01963b3ece46d
jackson-core@2.17.1
2.18.6
1
opensearchproject/opensearch:2.14.0466a49f379bb
jackson-core@2.17.0
2.18.6
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
jackson-core@2.18.2
2.18.6
1
opensearchproject/opensearch:2.12.0645d3d9390ad
jackson-core@2.16.1
2.18.6
1
opensearchproject/opensearch:2.19.269588c664014
jackson-core@2.18.2
2.18.6
1
opensearchproject/opensearch:3.3.2798cf28e226a
jackson-core@2.16.2
2.18.6
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
jackson-core@2.15.2
2.18.6
1
openzipkin/zipkin:2.24197a9692f6a9
jackson-core@2.16.0
2.18.6
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
jackson-core@2.18.3
2.18.6
1
payara/micro:7.2026.2-jdk25fb44b8ce1cb2
jackson-core@2.21.0
2.21.1
1
payara/server-full:7.2026.2-jdk2531f1253f0cf8
jackson-core@2.21.0
2.21.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.