StackRadar

CVE-2026-19032

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,012
of 17,957 indexed, latest versions
Container images
1,014
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution

Carried by container images the latest versions of 1,012 of 17,957 indexed charts deploy, on 1,014 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.8.1, 2.8.4, 2.8.6, 2.8.7+105 more2.18.10, 2.21.6, 2.22.2, 3.1.6+1 more1,014
OSV records
GHSA-wjgm-6hv5-3cvf
Trending
Rank 2 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

1,012 by stars
ChartLatestAffected imagesRadar Score
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
jackson-databind@2.13.4.2
2.18.10

Open the chart page →

57,545
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
jackson-databind@2.13.4.2
2.18.10

Open the chart page →

7,129
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
jackson-databind@2.10.1
2.18.10

Open the chart page →

20,125
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
jackson-databind@2.11.0
2.18.10

Open the chart page →

2,350
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
jackson-databind@2.15.4
2.18.10

Open the chart page →

2,610
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.6.39b0330756022
jackson-databind@2.21.2
2.21.6

Open the chart page →

4,942
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
jackson-databind@2.15.4
2.18.10

Open the chart page →

4,037
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
jackson-databind@2.13.4
2.18.10

Open the chart page →

11,705
pagesedgwarepages1.0.01 of 3See more

pages edgwarepages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.10

Open the chart page →

20,652
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
jackson-databind@2.17.3
2.18.10

Open the chart page →

7,864
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-databind@2.15.2
2.18.10

Open the chart page →

4,220
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-databind@2.15.2
2.18.10

Open the chart page →

4,207
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-databind@2.15.2
2.18.10

Open the chart page →

4,207
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-databind@2.15.2
2.18.10

Open the chart page →

4,207
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
jackson-databind@2.16.2
2.18.10

Open the chart page →

3,471
cerebroempathyco2.1.01 of 1See more

cerebro empathyco 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
lmenezes/cerebro:0.9.47d9e2b77e459
jackson-databind@2.10.5.1
2.18.10

Open the chart page →

972
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
jackson-databind@2.10.4
2.18.10

Open the chart page →

10,898
yaadeencircle360-ossVerified publisher0.2.11 of 1See more

yaade encircle360-oss 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
esperotech/yaade:latest24d2d692d948
jackson-databind@2.15.3
2.18.10

Open the chart page →

1,095
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
oscarsotosanchez/planner:v1.0730c00a099b8
jackson-databind@2.11.3
2.18.10
oscarsotosanchez/toposervice:v1.0d4d020e9f272
jackson-databind@2.11.3
2.18.10

Open the chart page →

28,383
eoloPlanteolo-plannerVerified publisher0.1.03 of 7See more

eoloPlant eolo-planner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
jackson-databind@2.14.1
2.18.10
mastercloudapps/planner:v1.2340a950b311b2
jackson-databind@2.13.0
2.18.10
mastercloudapps/server:v2.23f3d24dfe2686
jackson-databind@2.13.4.2
2.18.10

Open the chart page →

28,983
eoloplannereoloplannerVerified publisher0.1.03 of 7See more

eoloplanner eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
jackson-databind@2.13.0
2.18.10
codeurjc/server:v1.0310bea5b1ee7
jackson-databind@2.13.4.2
2.18.10
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

33,644
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.03 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
jackson-databind@2.14.1
2.18.10
mastercloudapps/planner:v1.2340a950b311b2
jackson-databind@2.13.0
2.18.10
mastercloudapps/server:v2.23f3d24dfe2686
jackson-databind@2.13.4.2
2.18.10

Open the chart page →

28,983
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
franrobles8/planner:v3.099985392d63c
jackson-databind@2.11.3
2.18.10
oscarsotosanchez/toposervice:v1.0d4d020e9f272
jackson-databind@2.11.3
2.18.10

Open the chart page →

28,349
eoloplannereoloplanner-molynx-gat0.1.03 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
jackson-databind@2.13.4.2
2.18.10
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10
molynx/planner:v1441c9f52f092
jackson-databind@2.13.0
2.18.10

Open the chart page →

29,600
eolo-plannereolo-planner-repo0.1.02 of 7See more

eolo-planner eolo-planner-repo 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
arturisimo/planner:v1.0fff9de644941
jackson-databind@2.13.0
2.18.10
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

28,353
eoloplanteoloplant1.0.03 of 7See more

eoloplant eoloplant 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
jackson-databind@2.14.1
2.18.10
mastercloudapps/planner:v1.2340a950b311b2
jackson-databind@2.13.0
2.18.10
mastercloudapps/server:v2.23f3d24dfe2686
jackson-databind@2.13.4.2
2.18.10

Open the chart page →

28,983
eoloplantseoloplants-urjcVerified publisher0.1.03 of 7See more

eoloplants eoloplants-urjc 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
jackson-databind@2.13.4.2
2.18.10
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10
lourdesmorente/new-planner:1.0.0608745878cdb
jackson-databind@2.13.0
2.18.10

Open the chart page →

28,869
servereoloserverVerified publisher0.1.03 of 7See more

server eoloserver 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
jackson-databind@2.13.0
2.18.10
codeurjc/server:v1.0310bea5b1ee7
jackson-databind@2.13.4.2
2.18.10
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

33,644
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
jackson-databind@2.13.4.2
2.18.10

Open the chart page →

76,545
gerrit-operatorepmdedpVerified publisher2.25.01 of 2See more

gerrit-operator epmdedp 2.25.0

1 of the 2 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
epamedp/edp-gerrit:3.14.249e8fe9c4855
jackson-databind@2.21.1
2.21.6

Open the chart page →

1,262
shenyuerdeng2.4.212 of 2See more

shenyu erdeng 2.4.21

2 of the 2 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
jackson-databind@2.10.1
2.18.10
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
jackson-databind@2.10.1
2.18.10

Open the chart page →

12,642
dshackleethereum-helm-chartsVerified publisher0.1.91 of 2See more

dshackle ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.14.0126f0ae0b388
jackson-databind@2.11.0
2.18.10

Open the chart page →

2,134
tekuethereum-helm-chartsVerified publisher1.2.11 of 2See more

teku ethereum-helm-charts 1.2.1

1 of the 2 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
consensys/teku:latest6bfef491dc27
jackson-databind@3.1.0
3.1.6

Open the chart page →

727
web3signerethereum-helm-chartsVerified publisher1.0.61 of 4See more

web3signer ethereum-helm-charts 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
consensys/web3signer:latestf146a51a1ba3
jackson-databind@2.21.2
2.21.6

Open the chart page →

2,148
spring-boot-adminevryfs-ossVerified publisher0.1.101 of 1See more

spring-boot-admin evryfs-oss 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
jackson-databind@2.13.4.2
2.18.10

Open the chart page →

6,292
eximeebpmseximeebpms-k8sOfficialVerified publisher0.4.01 of 1See more

eximeebpms eximeebpms-k8s 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.4.00f4a5c0eea07
jackson-databind@2.21.5
2.21.6

Open the chart page →

196
factor-platformfactorhouseVerified publisher0.0.51 of 1See more

factor-platform factorhouse 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
factorhouse/factor-platform:96.5b19f8edcb778
jackson-databind@3.2.0
3.2.2

Open the chart page →

51
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.6

Open the chart page →

2,766
fddb-exporterfddb-exporterVerified publisher2.4.31 of 1See more

fddb-exporter fddb-exporter 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
jackson-databind@2.22.1
2.22.2

Open the chart page →

559
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
jackson-databind@2.17.2
2.18.10
golenski/fibonacci-task-manager:2.0.03a2b36df247b
jackson-databind@2.17.2
2.18.10
golenski/fibonacci-worker:2.0.0954caf4aaf6a
jackson-databind@2.17.2
2.18.10

Open the chart page →

18,003
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
jackson-databind@2.12.5
2.18.10

Open the chart page →

8,182
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
jackson-databind@2.18.3
2.18.10

Open the chart page →

7,754
apollofiware0.1.41 of 1See more

apollo fiware 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/fiware/apollo:0.0.1055330b1b60c1
jackson-databind@2.13.2.2
2.18.10

Open the chart page →

7,120
canis-majorfiware0.2.31 of 1See more

canis-major fiware 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
jackson-databind@2.12.4
2.18.10

Open the chart page →

8,697
consent-facadefiware0.1.11 of 1See more

consent-facade fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-databind@2.17.2
2.18.10

Open the chart page →

2,662
contract-managementfiware3.5.361 of 1See more

contract-management fiware 3.5.36

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/fiware/contract-management:3.3.122bcfcf874451
jackson-databind@2.17.2
2.18.10

Open the chart page →

2,594
credentials-config-servicefiware2.6.41 of 1See more

credentials-config-service fiware 2.6.4

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
jackson-databind@2.19.2
2.21.6

Open the chart page →

2,453
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.10

Open the chart page →

4,717
endpoint-auth-servicefiware0.1.41 of 4See more

endpoint-auth-service fiware 0.1.4

1 of the 4 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
jackson-databind@2.12.4
2.18.10

Open the chart page →

12,035
mintakafiware0.4.71 of 1See more

mintaka fiware 0.4.7

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
fiware/mintaka:latestefc6793388cc
jackson-databind@2.13.4
2.18.10

Open the chart page →

7,204

Container images carrying it

1,014 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-databind@2.15.3
2.18.10
1
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
jackson-databind@2.21.4
2.21.6
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
jackson-databind@2.21.4
2.21.6
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-databind@2.17.2
2.18.10
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
jackson-databind@2.13.5
2.18.10
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
jackson-databind@2.12.3
2.18.10
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
jackson-databind@2.22.0
2.22.2
1
quay.io/streamshub/console-operator:0.11.0e40bbfeae125
jackson-databind@2.19.2
2.21.6
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.10
1
quay.io/strimzi/operator:0.32.0c5e0e5dca750
jackson-databind@2.13.4.1
2.18.10
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.10
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.10
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.1126450354eba9
jackson-databind@2.13.5
2.18.10
1
registry.gitlab.com/lenitech/docker/keycloak:26.7.4-0993dd8a5e1f8
jackson-databind@2.21.5
2.21.6
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.