StackRadar

CVE-2026-54513

High

Advisory

Published 23 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
782
of 17,787 indexed, latest versions
Container images
771
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

Carried by container images the latest versions of 782 of 17,787 indexed charts deploy, on 771 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.10.0, 2.10.1, 2.10.2, 2.10.3+67 more2.18.8, 2.21.4, 3.1.4771
OSV records
GHSA-rmj7-2vxq-3g9f

Charts affected

782 by stars
ChartLatestAffected imagesRadar Score
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
jackson-databind@2.13.3
2.18.8

Open the chart page →

7,292
jenkinskallakruparaju-jenkins1.0.01 of 1See more

jenkins kallakruparaju-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.4

Open the chart page →

2,487
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
jackson-databind@2.14.1
2.18.8

Open the chart page →

12,541
kron-aapm-agentkron-aapm-agent1.1.01 of 1See more

kron-aapm-agent kron-aapm-agent 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.1.07feef7d2ab42
jackson-databind@2.11.3
2.18.8

Open the chart page →

8,922
dinsrokronkltdVerified publisher0.1.71 of 2See more

dinsro kronkltd 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
duck1123/dinsro:latest9568c5961d5d
jackson-databind@2.14.2
2.18.8

Open the chart page →

1,628
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
jackson-databind@2.13.4
2.18.8

Open the chart page →

4,665
tapm-componentkubebb5.7.12 of 3See more

tapm-component kubebb 5.7.1

2 of the 3 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
refar/apm-api:v5.7.1241373fa2972
jackson-databind@2.11.1
2.18.8
refar/apm-operator-server:v5.7.1e5490f050f9f
jackson-databind@2.11.1
2.18.8

Open the chart page →

10,265
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
jackson-databind@2.13.3
2.18.8

Open the chart page →

6,490
sonarqubekubesphereVerified publisher6.7.01 of 3See more

sonarqube kubesphere 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
library/sonarqube:8.9-communityeb2f0be32efd
jackson-databind@2.13.2.2
2.18.8

Open the chart page →

2,275
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
jackson-databind@2.13.5
2.18.8

Open the chart page →

5,759
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
radondb/zookeeper:3.6.216981604f1a0
jackson-databind@2.10.3
2.18.8

Open the chart page →

6,701
nacoskubesphere-testVerified publisher0.1.11 of 1See more

nacos kubesphere-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
nacos/nacos-server:1.4.1fe6e5688cdf3
jackson-databind@2.10.4
2.18.8

Open the chart page →

4,153
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
jackson-databind@2.15.2
2.18.8
penpotapp/exporter:2.2.15c835ffd87ab
jackson-databind@2.12.4
2.18.8

Open the chart page →

17,002
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
jackson-databind@2.17.2
2.18.8

Open the chart page →

3,143
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
jackson-databind@2.17.1
2.18.8

Open the chart page →

3,373
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
jackson-databind@2.17.1
2.18.8

Open the chart page →

7,842
strimzi-kafka-operatorkvalitetsitVerified publisher0.36.11 of 1See more

strimzi-kafka-operator kvalitetsit 0.36.1

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.8

Open the chart page →

4,097
mock-oidclabs64io-helm-chartsVerified publisher0.1.01 of 1See more

mock-oidc labs64io-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
ghcr.io/navikt/mock-oauth2-server:2.1.1065d4ed47ce09
jackson-databind@2.17.2
2.18.8

Open the chart page →

703
pageslatif-pages1.0.01 of 3See more

pages latif-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
pageslavanya-pages1.0.01 of 3See more

pages lavanya-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
jackson-databind@2.11.0
2.18.8

Open the chart page →

2,427
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.4

Open the chart page →

4,434
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
jackson-databind@2.18.1
2.18.8

Open the chart page →

3,131
pagesliviu884422-pages1.0.01 of 3See more

pages liviu884422-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
jackson-databind@2.13.5
2.18.8

Open the chart page →

6,674
kafka-connect-wrapperlsmhun0.1.01 of 1See more

kafka-connect-wrapper lsmhun 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
jackson-databind@2.11.1
2.18.8

Open the chart page →

2,391
elastictranscoderluiscajl0.46.04 of 4See more

elastictranscoder luiscajl 0.46.0

4 of the 4 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
jackson-databind@2.12.3
2.18.8
elastictranscoder/media-storage:f6d861a026208b8c2359
jackson-databind@2.12.3
2.18.8
elastictranscoder/transcoder:627e21dcb4a0327029e6
jackson-databind@2.12.3
2.18.8
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
jackson-databind@2.12.3
2.18.8

Open the chart page →

58,225
filebot-botluiscajl0.0.111 of 1See more

filebot-bot luiscajl 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
jackson-databind@2.13.1
2.18.8

Open the chart page →

3,679
lavandaluiscajl0.0.1344 of 5See more

lavanda luiscajl 0.0.134

4 of the 5 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
jackson-databind@2.11.2
2.18.8
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
jackson-databind@2.11.2
2.18.8
lavandadelpatio/filebot:0.0.671f2ccec8c0d
jackson-databind@2.11.4
2.18.8
lavandadelpatio/tmdb:0.0.2f36af885e915
jackson-databind@2.11.4
2.18.8

Open the chart page →

18,248
tmdbluiscajl0.2.41 of 1See more

tmdb luiscajl 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
lavandadelpatio/tmdb:latestded9377636e9
jackson-databind@2.15.3
2.18.8

Open the chart page →

2,234
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
jackson-databind@2.14.2
2.18.8

Open the chart page →

3,290
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
jackson-databind@2.13.2.2
2.18.8

Open the chart page →

24,488
eoloplantmca-eoloplaner0.1.02 of 7See more

eoloplant mca-eoloplaner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
hugohg34/planner:0.0.2171f61e8d7e2
jackson-databind@2.13.0
2.18.8
hugohg34/toposervice:0.0.2812a03b3f274
jackson-databind@2.13.0
2.18.8

Open the chart page →

29,712
dependency-trackmediamarktsaturn1.9.21 of 2See more

dependency-track mediamarktsaturn 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.14.21ba4f004e1ec
jackson-databind@2.21.1
2.21.4

Open the chart page →

3,797
tinymediamanagermedia-servarrVerified publisher1.6.21 of 2See more

tinymediamanager media-servarr 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
jackson-databind@2.21.2
2.21.4

Open the chart page →

7,760
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
jackson-databind@2.17.1
2.18.8

Open the chart page →

2,589
activemqmicroboxlabs3.8.01 of 1See more

activemq microboxlabs 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
jackson-databind@2.18.2
2.18.8

Open the chart page →

1,501
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
jackson-databind@2.15.0
2.18.8

Open the chart page →

4,295
miot-calendarmicroboxlabs0.1.01 of 1See more

miot-calendar microboxlabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-calendar:latest-jvm7157cdc0bf5b
jackson-databind@2.20.1
2.21.4

Open the chart page →

1,955
microcks-operatormicrocksVerified publisher0.0.111 of 1See more

microcks-operator microcks 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-databind@2.19.2
2.21.4

Open the chart page →

1,279
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
jackson-databind@2.15.2
2.18.8

Open the chart page →

3,684
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
jackson-databind@2.15.2
2.18.8

Open the chart page →

5,141
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
jackson-databind@2.15.2
2.18.8

Open the chart page →

4,612
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
jackson-databind@2.13.3
2.18.8

Open the chart page →

12,862
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
jackson-databind@2.13.1
2.18.8

Open the chart page →

11,254
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
jackson-databind@2.11.2
2.18.8

Open the chart page →

10,639
standard-application-stackmintel11.4.11 of 12See more

standard-application-stack mintel 11.4.1

1 of the 12 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
jackson-databind@2.11.2
2.18.8

Open the chart page →

10,515
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
jackson-databind@2.14.3
2.18.8

Open the chart page →

3,083
verapdfmlohrVerified publisher1.4.01 of 1See more

verapdf mlohr 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
verapdf/rest:v1.30.2341359ac6af5
jackson-databind@2.19.2
2.21.4

Open the chart page →

493
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-54513.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

11,734

Container images carrying it

771 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:26.6.39b0330756022
jackson-databind@2.21.2
2.21.4
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-databind@2.17.2
2.18.8
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jackson-databind@2.13.4.2
2.18.8
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
jackson-databind@2.13.4.2
2.18.8
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-databind@2.20.0
2.21.4
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-databind@2.15.3
2.18.8
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-databind@2.19.2
2.21.4
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jackson-databind@2.10.1
2.18.8
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
jackson-databind@2.14.1
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-databind@2.15.3
2.18.8
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-databind@2.17.2
2.18.8
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
jackson-databind@2.13.5
2.18.8
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
jackson-databind@2.12.3
2.18.8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.8
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.8
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.8
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
jackson-databind@2.13.5
2.18.8
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.