StackRadar

CVE-2026-54514

Medium

Advisory

Published 23 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
871
of 17,787 indexed, latest versions
Container images
876
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)

Carried by container images the latest versions of 871 of 17,787 indexed charts deploy, on 876 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.0.5, 2.2.3, 2.3.0, 2.3.3+105 more2.18.8, 2.21.4, 3.1.4876
OSV records
GHSA-hgj6-7826-r7m5

Charts affected

871 by stars
ChartLatestAffected imagesRadar Score
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
jackson-databind@2.11.1
2.18.8

Open the chart page →

1,733
mod-template-enginefolio-org0.1.341 of 1See more

mod-template-engine folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
folioci/mod-template-engine:latestd105c585da30
jackson-databind@2.18.2
2.18.8

Open the chart page →

818
mod-user-importfolio-org0.1.341 of 1See more

mod-user-import folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
folioci/mod-user-import:latest1807734472bd
jackson-databind@2.18.6
2.18.8

Open the chart page →

1,215
mod-users-blfolio-org0.1.351 of 1See more

mod-users-bl folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
folioci/mod-users-bl:latest4e2d96c9340d
jackson-databind@2.18.2
2.18.8

Open the chart page →

1,321
accumulogaffer2.2.13 of 4See more

accumulo gaffer 2.2.1

3 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
jackson-databind@2.13.2.2
2.18.8
gchq/hdfs:3.3.35ec58edbb2db
jackson-databind@2.13.2.2
2.18.8
library/zookeeper:3.5.5b7a76ec06f68
jackson-databind@2.9.8
2.18.8

Open the chart page →

16,969
gaffer-road-trafficgaffer2.2.12 of 8See more

gaffer-road-traffic gaffer 2.2.1

2 of the 8 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
jackson-databind@2.13.2.2
2.18.8
library/zookeeper:3.5.5b7a76ec06f68
jackson-databind@2.9.8
2.18.8

Open the chart page →

9,381
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jackson-databind@2.15.3
2.18.8

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jackson-databind@2.15.3
2.18.8

Open the chart page →

11,961
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
jackson-databind@2.12.3
2.18.8

Open the chart page →

18,217
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
jackson-databind@2.11.0
2.18.8

Open the chart page →

19,234
gapsgeek-cookbookVerified publisher5.4.21 of 1See more

gaps geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
housewrecker/gaps:latestf417dd0a7547
jackson-databind@2.13.1
2.18.8

Open the chart page →

8,982
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
jackson-databind@2.12.3
2.18.8

Open the chart page →

12,586
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
jackson-databind@2.9.8
2.18.8

Open the chart page →

17,758
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
jackson-databind@2.12.5
2.18.8

Open the chart page →

2,887
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
jackson-databind@2.9.7
2.18.8

Open the chart page →

28,039
promcordgeek-cookbookVerified publisher5.4.21 of 1See more

promcord geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
biospheere/promcord:latest16d4fd269e66
jackson-databind@2.10.1
2.18.8

Open the chart page →

1,147
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
jackson-databind@2.16.1
2.18.8

Open the chart page →

8,955
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jackson-databind@2.10.5.1
2.18.8

Open the chart page →

4,547
zookeepergengxiankun-charts0.2.01 of 1See more

zookeeper gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
library/zookeeper:3.6.24c8a6d3b2338
jackson-databind@2.10.3
2.18.8

Open the chart page →

1,913
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.83 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

3 of the 5 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
jackson-databind@2.9.6
2.18.8
jingking/geonetwork-hnap:4.2.843e74ab234e1
jackson-databind@2.10.5
2.18.8
library/elasticsearch:7.17.1588c2ec10c7f2
jackson-databind@2.14.2
2.18.8

Open the chart page →

34,879
geysergeyserVerified publisher0.1.31 of 1See more

geyser geyser 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/joffreybvn/k8s-geyser:0.0.247f36880072e
jackson-databind@2.18.0
2.18.8

Open the chart page →

350
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
jackson-databind@2.11.1
2.18.8

Open the chart page →

3,064
jaegergpg-dev3.3.31 of 5See more

jaeger gpg-dev 3.3.3

1 of the 5 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
jackson-databind@2.13.2.2
2.18.8

Open the chart page →

19,291
opentelemetry-demogpg-dev0.33.84 of 27See more

opentelemetry-demo gpg-dev 0.33.8

4 of the 27 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-databind@2.17.2
2.18.8
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jackson-databind@2.16.0
2.18.8
ghcr.io/open-telemetry/demo:1.12.0-frauddetectionservice77cefdab4d5c
jackson-databind@2.17.1
2.18.8
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
jackson-databind@2.17.2
2.18.8

Open the chart page →

47,117
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
jackson-databind@2.9.6
2.18.8

Open the chart page →

15,780
hdfsgradiant-bigdataVerified publisher0.1.101 of 2See more

hdfs gradiant-bigdata 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gradiant/hdfs:2.7.73b28784ba41f
jackson-databind@2.4.0
2.18.8

Open the chart page →

7,072
hivegradiant-bigdataVerified publisher0.1.63 of 5See more

hive gradiant-bigdata 0.1.6

3 of the 5 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
jackson-databind@2.6.5
2.18.8
gradiant/hdfs:2.7.73b28784ba41f
jackson-databind@2.4.0
2.18.8
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
jackson-databind@2.2.3
2.18.8

Open the chart page →

20,836
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
jackson-databind@2.6.5
2.18.8

Open the chart page →

6,882
opentsdbgradiant-bigdataVerified publisher0.1.73 of 6See more

opentsdb gradiant-bigdata 0.1.7

3 of the 6 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
jackson-databind@2.4.0
2.18.8
gradiant/hdfs:2.7.73b28784ba41f
jackson-databind@2.4.0
2.18.8
gradiant/opentsdb:2.4.0c33d53913869
jackson-databind@2.9.5
2.18.8

Open the chart page →

17,509
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
jackson-databind@2.6.7.1
2.18.8

Open the chart page →

6,147
supertokensgraphql-hive1.0.01 of 1See more

supertokens graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
supertokens/supertokens-postgresql:3.1418d34c781347
jackson-databind@2.10.0
2.18.8

Open the chart page →

2,709
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
jackson-databind@2.21.3
2.21.4

Open the chart page →

4,604
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
jackson-databind@2.17.2
2.18.8

Open the chart page →

5,339
siembolgresearch0.1.62 of 4See more

siembol gresearch 0.1.6

2 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
jackson-databind@2.13.4.2
2.18.8
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
jackson-databind@2.13.4.2
2.18.8

Open the chart page →

14,312
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
jackson-databind@2.19.4
2.21.4

Open the chart page →

1,691
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
jackson-databind@2.19.2
2.21.4

Open the chart page →

3,211
mautrix-signalhalkeye0.3.01 of 2See more

mautrix-signal halkeye 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
signald/signald:0.23.2edbff058278c
jackson-databind@2.14.1
2.18.8

Open the chart page →

1,499
ubooquityhalkeye0.1.11 of 1See more

ubooquity halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jackson-databind@2.8.4
2.18.8

Open the chart page →

4,302
hapi-fhirhapi-fhirVerified publisher0.1.01 of 1See more

hapi-fhir hapi-fhir 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
jackson-databind@2.3.3
2.18.8

Open the chart page →

6,362
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
jackson-databind@2.11.4
2.18.8

Open the chart page →

6,102
hbasehbase0.1.72 of 4See more

hbase hbase 0.1.7

2 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jackson-databind@2.4.0
2.18.8
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jackson-databind@2.13.2.2
2.18.8

Open the chart page →

10,539
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
jackson-databind@2.12.2
2.18.8

Open the chart page →

3,978
hello-world-apihello-world-api0.0.51 of 1See more

hello-world-api hello-world-api 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
fabioformosa/hello-world-api:latest063873af085c
jackson-databind@2.18.3
2.18.8

Open the chart page →

1,417
helm-airportshelm-airports0.1.04 of 7See more

helm-airports helm-airports 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
jackson-databind@2.14.2
2.18.8
dina1993/airports-consumer:latest669d146a5e63
jackson-databind@2.14.2
2.18.8
dina1993/airports-producer:latest3d6b0dac1cb4
jackson-databind@2.14.2
2.18.8
wurstmeister/kafka:latest2d4bbf9cc83d
jackson-databind@2.10.5.1
2.18.8

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jackson-databind@2.10.5.1
2.18.8

Open the chart page →

4,547
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jackson-databind@2.10.5.1
2.18.8

Open the chart page →

5,573
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jackson-databind@2.10.5.1
2.18.8

Open the chart page →

4,547
pageshelm-chart-repos-camden1.0.01 of 3See more

pages helm-chart-repos-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
springboothelmcharts1.0.01 of 1See more

springboot helmcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
kimb88/hello-world-spring-boot:latest0639155241cb
jackson-databind@2.9.6
2.18.8

Open the chart page →

6,451

Container images carrying it

876 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
jackson-databind@2.15.2
2.18.8
1
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.8
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
jackson-databind@2.13.4.2
2.18.8
1
quay.io/keycloak/keycloak:26.5.68d44614c7479
jackson-databind@2.19.2
2.21.4
1
quay.io/keycloak/keycloak:26.49409c59bdfb6
jackson-databind@2.19.2
2.21.4
1
quay.io/keycloak/keycloak:26.6.39b0330756022
jackson-databind@2.21.2
2.21.4
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-databind@2.17.2
2.18.8
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jackson-databind@2.13.4.2
2.18.8
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
jackson-databind@2.13.4.2
2.18.8
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-databind@2.20.0
2.21.4
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-databind@2.15.3
2.18.8
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-databind@2.19.2
2.21.4
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jackson-databind@2.10.1
2.18.8
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
jackson-databind@2.14.1
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-databind@2.15.3
2.18.8
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-databind@2.17.2
2.18.8
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
jackson-databind@2.13.5
2.18.8
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
jackson-databind@2.12.3
2.18.8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.8
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.8
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.8
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
jackson-databind@2.13.5
2.18.8
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.