StackRadar

CVE-2026-18401

Medium

Advisory

Published 28 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
314
deployed by those charts
Fix available
1 of 1
affected package

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 314 images.

Affected packageAffected versionsFixed inImages
jackson-coremaven2.15.0, 2.15.2, 2.15.3, 2.15.4+21 more2.18.6, 2.21.1, 3.1.0314
OSV records
GHSA-72hv-8253-57qq

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
akto-hybrid-redactakto1.44.41 of 5See more

akto-hybrid-redact akto 1.44.4

1 of the 5 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
jackson-core@2.19.0
2.21.1

Open the chart page →

4,777
akto-mini-runtime-shaakto0.7.232 of 3See more

akto-mini-runtime-sha akto 0.7.23

2 of the 3 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtimedigest-pinned4d3a8042c761
jackson-core@2.16.1
2.18.6
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
jackson-core@2.19.0
2.21.1

Open the chart page →

3,217
akto-mini-testing-kafkaakto1.42.13 of 5See more

akto-mini-testing-kafka akto 1.42.1

3 of the 5 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
jackson-core@2.16.0
2.18.6
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
jackson-core@2.16.0
2.18.6
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:improve-testing-performance8e9d15ed71c7
jackson-core@2.16.1
2.18.6

Open the chart page →

6,397
akto-mrs-runtime-combinedakto0.0.22 of 2See more

akto-mrs-runtime-combined akto 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.54.4_localb2b97137aef5
jackson-core@2.16.1
2.18.6
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
jackson-core@2.19.0
2.21.1

Open the chart page →

1,826
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
aktosecurity/akto-api-protection:localbcd7382c9c1b
jackson-core@2.16.1
2.18.6

Open the chart page →

11,285
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
jackson-core@2.16.1
2.18.6

Open the chart page →

4,880
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jackson-core@2.16.1
2.18.6

Open the chart page →

5,489
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
jackson-core@2.16.1
2.18.6

Open the chart page →

3,442
zunivers-ninjaalexpressoVerified publisher1.31.21 of 2See more

zunivers-ninja alexpresso 1.31.2

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
library/neo4j:5.18.18f01f7bb053e
jackson-core@2.16.1
2.18.6

Open the chart page →

1,165
amorphieamorphie0.1.24 of 18See more

amorphie amorphie 0.1.2

4 of the 18 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
jackson-core@2.16.1
2.18.6
hazelcast/hazelcast:5.3.18fe26efde8e1
jackson-core@2.15.2
2.18.6
hazelcast/management-center:5.3.2f9d34300d330
jackson-core@2.15.2
2.18.6
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
jackson-core@2.15.2
2.18.6

Open the chart page →

28,131
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
jackson-core@2.16.0
2.18.6

Open the chart page →

2,453
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
jackson-core@2.15.3
2.18.6

Open the chart page →

6,187
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
jackson-core@2.19.1
2.21.1

Open the chart page →

3,963
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:latest536358d7b17e
jackson-core@2.19.1
2.21.1

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
jackson-core@2.15.2
2.18.6

Open the chart page →

16,975
arlas-aiasarlas-stackVerified publisher28.8.03 of 22See more

arlas-aias arlas-stack 28.8.0

3 of the 22 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
jackson-core@2.15.0
2.18.6
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
jackson-core@2.18.2
2.18.6
gisaia/arlas-persistence-server:28.0.0f667e0ee79be
jackson-core@2.19.2
2.21.1

Open the chart page →

40,238
arlas-servicesarlas-stackVerified publisher28.8.01 of 3See more

arlas-services arlas-stack 28.8.0

1 of the 3 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
gisaia/arlas-persistence-server:28.0.0f667e0ee79be
jackson-core@2.19.2
2.21.1

Open the chart page →

1,534
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
jackson-core@2.15.2
2.18.6

Open the chart page →

14,728
keycloakbarravarVerified publisher1.0.41 of 1See more

keycloak barravar 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:24.0.34d6f22991266
jackson-core@2.16.1
2.18.6

Open the chart page →

2,381
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
jackson-core@2.17.3
2.18.6

Open the chart page →

4,292
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
jackson-core@2.18.3
2.18.6

Open the chart page →

1,816
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
jackson-core@2.18.2
2.18.6

Open the chart page →

26,996
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
jackson-core@2.16.1
2.18.6

Open the chart page →

8,323
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
apache/kafka:4.1.0bff074a5d005
jackson-core@2.19.0
2.21.1

Open the chart page →

2,398
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
jackson-core@2.19.4
2.21.1

Open the chart page →

8,001
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
jackson-core@2.17.1
2.18.6

Open the chart page →

1,073
metabasecasemark2.16.111 of 1See more

metabase casemark 2.16.11

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jackson-core@2.17.0
2.18.6

Open the chart page →

1,215
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
jackson-core@2.18.0
2.18.6

Open the chart page →

7,168
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
jackson-core@2.18.0
2.18.6

Open the chart page →

5,238
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
jackson-core@2.18.3
2.18.6

Open the chart page →

4,578
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
jackson-core@2.17.0
2.18.6

Open the chart page →

5,398
dadosfake-helmdadosfake-app0.1.01 of 1See more

dadosfake-helm dadosfake-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
jackson-core@2.15.3
2.18.6

Open the chart page →

2,064
damap-chartdamapVerified publisher0.3.02 of 5See more

damap-chart damap 0.3.0

2 of the 5 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
jackson-core@2.17.1
2.18.6
quay.io/keycloak/keycloak:26.49409c59bdfb6
jackson-core@2.19.2
2.21.1

Open the chart page →

13,936
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
jackson-core@2.19.2
2.21.1

Open the chart page →

3,547
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
jackson-core@2.20.0
2.21.1

Open the chart page →

11,160
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
jackson-core@2.18.2
2.18.6

Open the chart page →

1,269
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
jackson-core@2.15.4
2.18.6

Open the chart page →

2,512
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
jackson-core@2.15.4
2.18.6

Open the chart page →

3,888
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
jackson-core@2.17.3
2.18.6

Open the chart page →

7,268
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-core@2.15.2
2.18.6

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-core@2.15.2
2.18.6

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-core@2.15.2
2.18.6

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-core@2.15.2
2.18.6

Open the chart page →

4,033
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
jackson-core@2.16.2
2.18.6

Open the chart page →

2,942
yaadeencircle360-ossVerified publisher0.2.11 of 1See more

yaade encircle360-oss 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
esperotech/yaade:latest24d2d692d948
jackson-core@2.15.3
2.18.6

Open the chart page →

1,000
eximeebpmseximeebpms-k8sOfficialVerified publisher0.3.01 of 1See more

eximeebpms eximeebpms-k8s 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.3.0acb8dbce38fd
jackson-core@2.20.2
2.21.1

Open the chart page →

727
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-core@2.20.1
2.21.1

Open the chart page →

2,476
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
jackson-core@2.17.2
2.18.6
golenski/fibonacci-task-manager:2.0.03a2b36df247b
jackson-core@2.17.2
2.18.6
golenski/fibonacci-worker:2.0.0954caf4aaf6a
jackson-core@2.17.2
2.18.6

Open the chart page →

16,927
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
jackson-core@2.18.3
2.18.6

Open the chart page →

7,792
consent-facadefiware0.1.11 of 1See more

consent-facade fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-core@2.17.2
2.18.6

Open the chart page →

2,475

Container images carrying it

314 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-core@2.18.2
2.18.6
1
quay.io/keycloak/keycloak:26.5.68d44614c7479
jackson-core@2.19.2
2.21.1
1
quay.io/keycloak/keycloak:26.49409c59bdfb6
jackson-core@2.19.2
2.21.1
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-core@2.17.2
2.18.6
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-core@2.20.0
2.21.1
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-core@2.15.3
2.18.6
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-core@2.19.2
2.21.1
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
jackson-core@2.15.3
2.18.6
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
jackson-core@2.15.3
2.18.6
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-core@2.15.3
2.18.6
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-core@2.17.2
2.18.6
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-core@2.16.2
2.18.6
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-core@2.17.2
2.18.6
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
jackson-core@2.18.0
2.18.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.