StackRadar

CVE-2026-54512

High

Advisory

Published 23 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
782
of 17,787 indexed, latest versions
Container images
771
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation

Carried by container images the latest versions of 782 of 17,787 indexed charts deploy, on 771 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.10.0, 2.10.1, 2.10.2, 2.10.3+67 more2.18.8, 2.21.4, 3.1.4771
OSV records
GHSA-j3rv-43j4-c7qm

Charts affected

782 by stars
ChartLatestAffected imagesRadar Score
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

11,734
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

12,147
backendmojaloop0.1.02 of 6See more

backend mojaloop 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
jackson-databind@2.10.5.1
2.18.8
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
jackson-databind@2.15.2
2.18.8

Open the chart page →

16,111
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

11,518
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

19,265
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
jackson-databind@2.17.0
2.18.8

Open the chart page →

30,195
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
jackson-databind@2.12.3
2.18.8

Open the chart page →

25,989
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
jackson-databind@2.12.6
2.18.8

Open the chart page →

15,731
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
jackson-databind@2.13.4.2
2.18.8

Open the chart page →

5,713
commafeedmt1905028.2.01 of 3See more

commafeed mt190502 8.2.0

1 of the 3 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
jackson-databind@2.20.1
2.21.4

Open the chart page →

3,697
keycloakmt1905021.4.61 of 3See more

keycloak mt190502 1.4.6

1 of the 3 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.5.68d44614c7479
jackson-databind@2.19.2
2.21.4

Open the chart page →

2,913
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
jackson-databind@2.13.4
2.18.8

Open the chart page →

8,946
pagesmuthu-pages1.0.01 of 3See more

pages muthu-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
jackson-databind@2.17.1
2.18.8

Open the chart page →

2,141
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
jackson-databind@2.10.4
2.18.8

Open the chart page →

9,341
Practica_4_helmmy-heml-appVerified publisher0.1.03 of 7See more

Practica_4_helm my-heml-app 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
adagber/planner:v1.0e5c1ed097752
jackson-databind@2.13.0
2.18.8
codeurjc/server:v1.0310bea5b1ee7
jackson-databind@2.13.4.2
2.18.8
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.8

Open the chart page →

27,812
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
jackson-databind@2.18.3
2.18.8

Open the chart page →

1,783
pagesnarain1.0.01 of 3See more

pages narain 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
pagesnarasimha-pages1.0.01 of 3See more

pages narasimha-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
pagesnavin-brixton1.0.01 of 3See more

pages navin-brixton 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
jackson-databind@2.16.1
2.18.8

Open the chart page →

15,408
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
jackson-databind@2.10.5.1
2.18.8

Open the chart page →

2,639
neuralbank-stackneuralbank-stack0.1.01 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-databind@2.20.0
2.21.4

Open the chart page →

5,198
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
jackson-databind@2.13.3
2.18.8

Open the chart page →

3,422
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
jackson-databind@2.13.3
2.18.8

Open the chart page →

5,887
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jackson-databind@2.10.5.1
2.18.8

Open the chart page →

4,547
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
jackson-databind@2.13.3
2.18.8

Open the chart page →

6,864
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
jackson-databind@2.13.3
2.18.8

Open the chart page →

5,928
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
jackson-databind@2.13.3
2.18.8

Open the chart page →

5,885
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
jackson-databind@2.10.3
2.18.8

Open the chart page →

3,633
nexus2novum-rgi-charts0.1.11 of 1See more

nexus2 novum-rgi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
sonatype/nexus:oss6bc88b51d4d7
jackson-databind@2.11.3
2.18.8

Open the chart page →

3,219
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
jackson-databind@2.15.2
2.18.8

Open the chart page →

2,088
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
jackson-databind@2.17.0
2.18.8

Open the chart page →

5,825
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jackson-databind@2.13.0
2.18.8

Open the chart page →

8,539
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
jackson-databind@2.14.2
2.18.8

Open the chart page →

9,059
apicurioone-acre-fundVerified publisher2.3.03 of 5See more

apicurio one-acre-fund 2.3.0

3 of the 5 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
jackson-databind@2.15.2
2.18.8
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
jackson-databind@2.15.2
2.18.8
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
jackson-databind@2.15.2
2.18.8

Open the chart page →

18,666
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
jackson-databind@2.14.0-rc1
2.18.8

Open the chart page →

6,083
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
vespaengine/vespa:8.526.1569b160f58211
jackson-databind@2.18.3
2.18.8

Open the chart page →

6,252
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
jackson-databind@2.15.2
2.18.8

Open the chart page →

2,421
mockserveropen-charts1.1.01 of 1See more

mockserver open-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
mockserver/mockserver:5.15.00f9ef78c9489
jackson-databind@2.14.1
2.18.8

Open the chart page →

1,257
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
jackson-databind@2.10.2
2.18.8

Open the chart page →

12,939
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
voltha/voltha-onos:5.1.8e038acb950d3
jackson-databind@2.10.0
2.18.8

Open the chart page →

41,088
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
jackson-databind@2.21.3
2.21.4

Open the chart page →

2,043
bpjstk-serviceopenshift1.0.05 of 6See more

bpjstk-service openshift 1.0.0

5 of the 6 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
andrianrf/backoffice-be:latest6036614803d4
jackson-databind@2.13.5
2.18.8
andrianrf/bpjstk-service:latest46abe878d9d8
jackson-databind@2.11.2
2.18.8
andrianrf/bpjstk-simulator:latestb63fdb51d39d
jackson-databind@2.11.2
2.18.8
andrianrf/iso-client:latestba560086ce15
jackson-databind@2.11.2
2.18.8
andrianrf/iso-server:latest7da47f525c7d
jackson-databind@2.11.0
2.18.8

Open the chart page →

34,721
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
jackson-databind@2.18.3
2.18.8

Open the chart page →

7,848
redhat-springboot-restopenshift0.0.11 of 1See more

redhat-springboot-rest openshift 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
jackson-databind@2.13.5
2.18.8

Open the chart page →

3,063
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
jackson-databind@2.13.2.2
2.18.8

Open the chart page →

13,608
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
jackson-databind@2.13.2.2
2.18.8

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
jackson-databind@2.13.2.2
2.18.8

Open the chart page →

13,570
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-54512.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
jackson-databind@2.13.2.2
2.18.8

Open the chart page →

13,553

Container images carrying it

771 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:26.6.39b0330756022
jackson-databind@2.21.2
2.21.4
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-databind@2.17.2
2.18.8
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jackson-databind@2.13.4.2
2.18.8
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
jackson-databind@2.13.4.2
2.18.8
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-databind@2.20.0
2.21.4
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-databind@2.15.3
2.18.8
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-databind@2.19.2
2.21.4
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jackson-databind@2.10.1
2.18.8
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
jackson-databind@2.14.1
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-databind@2.15.3
2.18.8
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-databind@2.17.2
2.18.8
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
jackson-databind@2.13.5
2.18.8
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
jackson-databind@2.12.3
2.18.8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.8
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.8
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.8
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
jackson-databind@2.13.5
2.18.8
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.