StackRadar

CVE-2026-18401

Medium

Advisory

Published 28 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
314
deployed by those charts
Fix available
1 of 1
affected package

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 314 images.

Affected packageAffected versionsFixed inImages
jackson-coremaven2.15.0, 2.15.2, 2.15.3, 2.15.4+21 more2.18.6, 2.21.1, 3.1.0314
OSV records
GHSA-72hv-8253-57qq

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
hazelcastwenerme5.10.22 of 2See more

hazelcast wenerme 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
jackson-core@2.17.2
2.18.6
hazelcast/management-center:5.5.2991ddb27c251
jackson-core@2.17.2
2.18.6

Open the chart page →

2,634
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
jackson-core@2.15.0
2.18.6

Open the chart page →

2,191
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
jackson-core@2.19.2
2.21.1

Open the chart page →

7,624
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-core@2.15.3
2.18.6

Open the chart page →

11,577
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-core@2.17.2
2.18.6

Open the chart page →

9,381
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
jackson-core@2.15.2
2.18.6

Open the chart page →

3,480
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-18401.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
jackson-core@2.18.0
2.18.6

Open the chart page →

1,571

Container images carrying it

314 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-core@2.18.2
2.18.6
1
quay.io/keycloak/keycloak:26.5.68d44614c7479
jackson-core@2.19.2
2.21.1
1
quay.io/keycloak/keycloak:26.49409c59bdfb6
jackson-core@2.19.2
2.21.1
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-core@2.17.2
2.18.6
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-core@2.20.0
2.21.1
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-core@2.15.3
2.18.6
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-core@2.19.2
2.21.1
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
jackson-core@2.15.3
2.18.6
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
jackson-core@2.15.3
2.18.6
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-core@2.15.3
2.18.6
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-core@2.17.2
2.18.6
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-core@2.16.2
2.18.6
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-core@2.17.2
2.18.6
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
jackson-core@2.18.0
2.18.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.