StackRadar

CVE-2026-19032

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,032
of 17,939 indexed, latest versions
Container images
1,027
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution

Carried by container images the latest versions of 1,032 of 17,939 indexed charts deploy, on 1,027 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.8.1, 2.8.4, 2.8.6, 2.8.7+105 more2.18.10, 2.21.6, 2.22.2, 3.1.6+1 more1,027
OSV records
GHSA-wjgm-6hv5-3cvf
Trending
Rank 2 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

1,032 by stars
ChartLatestAffected imagesRadar Score
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
jackson-databind@3.1.4
3.1.6

Open the chart page →

513
mod-inventory-storagefolio-org0.1.371 of 1See more

mod-inventory-storage folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-inventory-storage:latestf92ff0a3ca40
jackson-databind@3.1.5
3.1.6

Open the chart page →

81
mod-inventory-updatefolio-org0.1.21 of 1See more

mod-inventory-update folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-inventory-update:latestba84812b4d58
jackson-databind@2.18.2
2.18.10

Open the chart page →

883
mod-invoicefolio-org0.1.351 of 1See more

mod-invoice folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-invoice:latest45b7b13e81e1
jackson-databind@3.1.4
3.1.6

Open the chart page →

571
mod-invoice-storagefolio-org0.1.341 of 1See more

mod-invoice-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-invoice-storage:latest0bc720abcb78
jackson-databind@2.21.5
2.21.6

Open the chart page →

226
mod-ldpfolio-org0.1.331 of 1See more

mod-ldp folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-ldp:latestb55696fd9065
jackson-databind@2.15.4
2.18.10

Open the chart page →

1,929
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
jackson-databind@2.18.7
2.18.10

Open the chart page →

1,787
mod-loginfolio-org0.1.341 of 1See more

mod-login folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-login:latest88de493f86db
jackson-databind@2.16.1
2.18.10

Open the chart page →

1,160
mod-login-samlfolio-org0.1.341 of 1See more

mod-login-saml folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-login-saml:latest5f3358ccaa0f
jackson-databind@2.21.2
2.21.6

Open the chart page →

1,097
mod-marccatfolio-org0.1.301 of 1See more

mod-marccat folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-marccat:latest1b57d690d568
jackson-databind@2.9.4
2.18.10

Open the chart page →

6,993
mod-notesfolio-org0.1.341 of 1See more

mod-notes folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-notes:latest998ac4782e0d
jackson-databind@2.21.5
2.21.6

Open the chart page →

157
mod-notifyfolio-org0.1.341 of 1See more

mod-notify folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-notify:latesta8c1a90005fc
jackson-databind@3.1.4
3.1.6

Open the chart page →

272
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
jackson-databind@2.11.1
2.18.10

Open the chart page →

1,735
mod-oai-pmhfolio-org0.1.341 of 1See more

mod-oai-pmh folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-oai-pmh:latest5cd5ef063f2a
jackson-databind@2.18.2
2.18.10

Open the chart page →

966
mod-ordersfolio-org0.1.341 of 1See more

mod-orders folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-orders:latestfc4528220fb8
jackson-databind@3.1.4
3.1.6

Open the chart page →

458
mod-orders-storagefolio-org0.1.351 of 1See more

mod-orders-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-orders-storage:latestceeaacc3bf16
jackson-databind@3.1.4
3.1.6

Open the chart page →

443
mod-organizationsfolio-org0.1.341 of 1See more

mod-organizations folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-organizations:latest7dc9ccf3d937
jackson-databind@2.18.6
2.18.10

Open the chart page →

814
mod-organizations-storagefolio-org0.1.341 of 1See more

mod-organizations-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-organizations-storage:lateste46892405fde
jackson-databind@2.21.4
2.21.6

Open the chart page →

670
mod-password-validatorfolio-org0.1.341 of 1See more

mod-password-validator folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-password-validator:latestb31d75f2bf7b
jackson-databind@3.1.4
3.1.6

Open the chart page →

395
mod-patronfolio-org0.1.341 of 1See more

mod-patron folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-patron:latest5f213acfe2f8
jackson-databind@2.18.2
2.18.10

Open the chart page →

832
mod-patron-blocksfolio-org0.1.341 of 1See more

mod-patron-blocks folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-patron-blocks:latestde7318069a67
jackson-databind@2.21.5
2.21.6

Open the chart page →

360
mod-permissionsfolio-org0.1.351 of 1See more

mod-permissions folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-permissions:latest5363e98c6299
jackson-databind@2.18.6
2.18.10

Open the chart page →

1,223
mod-pubsubfolio-org0.1.341 of 1See more

mod-pubsub folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-pubsub:latest0a4fa4ad5d72
jackson-databind@2.18.6
2.18.10

Open the chart page →

1,017
mod-quick-marcfolio-org0.1.351 of 1See more

mod-quick-marc folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-quick-marc:latest4d70ebda4d00
jackson-databind@2.21.5
2.21.6

Open the chart page →

63
mod-remote-storagefolio-org0.1.321 of 1See more

mod-remote-storage folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-remote-storage:latest4f12177123dc
jackson-databind@2.21.4
2.21.6

Open the chart page →

572
mod-rtacfolio-org0.1.341 of 1See more

mod-rtac folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-rtac:latestc959b2d6142f
jackson-databind@2.18.2
2.18.10

Open the chart page →

669
mod-searchfolio-org0.1.351 of 1See more

mod-search folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-search:latest44d7ee9acdf6
jackson-databind@3.1.5
3.1.6

Open the chart page →

1,561
mod-senderfolio-org0.1.341 of 1See more

mod-sender folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-sender:latestd88a675dddf0
jackson-databind@2.18.2
2.18.10

Open the chart page →

822
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
jackson-databind@2.11.1
2.18.10

Open the chart page →

1,735
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
jackson-databind@2.11.1
2.18.10

Open the chart page →

1,735
mod-source-record-managerfolio-org0.1.371 of 1See more

mod-source-record-manager folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-source-record-manager:latesta940caf026ee
jackson-databind@2.21.5
2.21.6

Open the chart page →

59
mod-tagsfolio-org0.1.341 of 1See more

mod-tags folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-tags:latest6e8beeb70272
jackson-databind@2.21.4
2.21.6

Open the chart page →

343
mod-template-enginefolio-org0.1.341 of 1See more

mod-template-engine folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-template-engine:latestd105c585da30
jackson-databind@2.18.2
2.18.10

Open the chart page →

822
mod-user-importfolio-org0.1.341 of 1See more

mod-user-import folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-user-import:latest1807734472bd
jackson-databind@2.18.6
2.18.10

Open the chart page →

1,223
mod-usersfolio-org0.1.341 of 1See more

mod-users folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-users:latest6f60033321b0
jackson-databind@2.21.4
2.21.6

Open the chart page →

432
mod-users-blfolio-org0.1.351 of 1See more

mod-users-bl folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/mod-users-bl:latest4e2d96c9340d
jackson-databind@2.18.2
2.18.10

Open the chart page →

1,329
okapifolio-org0.3.311 of 1See more

okapi folio-org 0.3.31

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
folioci/okapi:latestdf29ac807a45
jackson-databind@3.1.5
3.1.6

Open the chart page →

48
demo-workflowsfrinx-helm-charts2.0.01 of 3See more

demo-workflows frinx-helm-charts 2.0.0

1 of the 3 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
frinx/sample-topology:6.1.01a19658415b6
jackson-databind@2.15.4
2.18.10

Open the chart page →

2,662
frinx-machinefrinx-helm-charts11.0.01 of 26See more

frinx-machine frinx-helm-charts 11.0.0

1 of the 26 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
frinx/conductor-server:6.1.159aa36c359f2
jackson-databind@2.13.5
2.18.10

Open the chart page →

44,191
sample-topologyfrinx-helm-charts3.1.11 of 1See more

sample-topology frinx-helm-charts 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
frinx/sample-topology:6.1.01a19658415b6
jackson-databind@2.15.4
2.18.10

Open the chart page →

1,213
workflow-managerfrinx-helm-charts3.2.11 of 5See more

workflow-manager frinx-helm-charts 3.2.1

1 of the 5 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
frinx/conductor-server:6.1.0d01264a908c9
jackson-databind@2.13.3
2.18.10

Open the chart page →

9,378
accumulogaffer2.2.13 of 4See more

accumulo gaffer 2.2.1

3 of the 4 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
jackson-databind@2.13.2.2
2.18.10
gchq/hdfs:3.3.35ec58edbb2db
jackson-databind@2.13.2.2
2.18.10
library/zookeeper:3.5.5b7a76ec06f68
jackson-databind@2.9.8
2.18.10

Open the chart page →

17,617
gaffer-road-trafficgaffer2.2.12 of 8See more

gaffer-road-traffic gaffer 2.2.1

2 of the 8 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
jackson-databind@2.13.2.2
2.18.10
library/zookeeper:3.5.5b7a76ec06f68
jackson-databind@2.9.8
2.18.10

Open the chart page →

9,695
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jackson-databind@2.15.3
2.18.10

Open the chart page →

12,167
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jackson-databind@2.15.3
2.18.10

Open the chart page →

12,167
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.10

Open the chart page →

20,574
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
jackson-databind@2.12.3
2.18.10

Open the chart page →

18,559
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
jackson-databind@2.11.0
2.18.10

Open the chart page →

19,706
gapsgeek-cookbookVerified publisher5.4.21 of 1See more

gaps geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
housewrecker/gaps:latestf417dd0a7547
jackson-databind@2.13.1
2.18.10

Open the chart page →

9,151
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-19032.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
jackson-databind@2.12.3
2.18.10

Open the chart page →

12,778

Container images carrying it

1,027 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
audig/clamapi:2.1.62c3fe34ee430
jackson-databind@2.11.1
2.18.10
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
jackson-databind@2.13.1
2.18.10
1
beastob/url-shortener:1.0.299a49885ab33
jackson-databind@2.11.4
2.18.10
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
jackson-databind@2.18.6
2.18.10
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
jackson-databind@2.16.1
2.18.10
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
jackson-databind@2.9.8
2.18.10
1
biospheere/promcord:latest16d4fd269e66
jackson-databind@2.10.1
2.18.10
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
jackson-databind@2.13.2.2
2.18.10
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
jackson-databind@2.13.4.2
2.18.10
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
jackson-databind@2.13.4.2
2.18.10
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
jackson-databind@2.15.0
2.18.10
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
jackson-databind@2.13.5
2.18.10
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
jackson-databind@2.13.4.2
2.18.10
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
jackson-databind@2.10.5.1
2.18.10
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
jackson-databind@2.13.4.2
2.18.10
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
jackson-databind@2.16.1
2.18.10
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
jackson-databind@2.18.2
2.18.10
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
jackson-databind@2.17.2
2.18.10
1
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
jackson-databind@2.15.2
2.18.10
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
jackson-databind@2.13.4.2
2.18.10
1
bivas/presto:0.19605545994f806
jackson-databind@2.8.1
2.18.10
1
blackducksoftware/blackduck-alert:8.4.1b66c8385ba53
jackson-databind@2.17.3
2.18.10
1
bluerange/bluerange:26.2.0503577ef9143
jackson-databind@2.18.3
2.18.10
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
jackson-databind@2.15.2
2.18.10
1
camunda/zeebe:8.4.5ab5abc09e407
jackson-databind@2.16.1
2.18.10
1
castlemock/castlemock:latestb7f3f1527ba9
jackson-databind@2.18.3
2.18.10
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
jackson-databind@2.19.2
2.21.6
1
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
jackson-databind@2.12.5
2.18.10
1
choerodon/event-store-service:0.8.03c94c97f6f69
jackson-databind@2.8.8
2.18.10
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
jackson-databind@2.12.7.1
2.18.10
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jackson-databind@2.14.0
2.18.10
1
cnieg/gantt:1.1.2d4b478d76f2a
jackson-databind@2.13.4
2.18.10
1
codetogether/codetogether:latest4348c8a38752
jackson-databind@2.12.7.1
2.18.10
1
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
jackson-databind@2.15.3
2.18.10
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
jackson-databind@2.13.5
2.18.10
1
confluentinc/cp-cmf:2.4.1f466f8649aa8
jackson-databind@2.21.5
2.21.6
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jackson-databind@2.10.5.1
2.18.10
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jackson-databind@2.10.5.1
2.18.10
1
confluentinc/cp-kafka:5.4.01bbda887bc53
jackson-databind@2.9.10.1
2.18.10
1
confluentinc/cp-kafka:7.6.024cdd3a7fa89
jackson-databind@2.14.2
2.18.10
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
jackson-databind@2.13.2.2
2.18.10
1
confluentinc/cp-kafka:latest5e8f3ab5b497
jackson-databind@2.22.1
2.22.2
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
jackson-databind@2.13.5
2.18.10
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
jackson-databind@2.16.2
2.18.10
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
jackson-databind@2.13.5
2.18.10
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
jackson-databind@2.9.6
2.18.10
1
confluentinc/cp-kafka:7.5.1dc9b972db002
jackson-databind@2.14.2
2.18.10
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jackson-databind@2.10.5.1
2.18.10
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jackson-databind@2.10.5.1
2.18.10
1
confluentinc/cp-ksqldb-cli:7.6.0118cec1c87e2
jackson-databind@2.14.2
2.18.10
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.