StackRadar

CVE-2026-54514

Medium

Advisory

Published 23 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
869
of 17,790 indexed, latest versions
Container images
870
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)

Carried by container images the latest versions of 869 of 17,790 indexed charts deploy, on 870 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.0.5, 2.2.3, 2.3.0, 2.3.3+105 more2.18.8, 2.21.4, 3.1.4870
OSV records
GHSA-hgj6-7826-r7m5

Charts affected

869 by stars
ChartLatestAffected imagesRadar Score
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
jackson-databind@2.15.2
2.18.8

Open the chart page →

5,154
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
jackson-databind@2.15.2
2.18.8

Open the chart page →

4,625
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
jackson-databind@2.13.3
2.18.8

Open the chart page →

12,858
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
jackson-databind@2.13.1
2.18.8

Open the chart page →

11,281
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jackson-databind@2.9.5
2.18.8

Open the chart page →

15,873
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
jackson-databind@2.3.3
2.18.8

Open the chart page →

43,532
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
jackson-databind@2.11.2
2.18.8

Open the chart page →

10,683
standard-application-stackmintel11.4.11 of 12See more

standard-application-stack mintel 11.4.1

1 of the 12 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
jackson-databind@2.11.2
2.18.8

Open the chart page →

10,613
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
jackson-databind@2.14.3
2.18.8

Open the chart page →

3,086
verapdfmlohrVerified publisher1.4.01 of 1See more

verapdf mlohr 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
verapdf/rest:v1.30.2341359ac6af5
jackson-databind@2.19.2
2.21.4

Open the chart page →

493
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

11,762
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

11,762
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

12,175
backendmojaloop0.1.02 of 6See more

backend mojaloop 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
jackson-databind@2.10.5.1
2.18.8
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
jackson-databind@2.15.2
2.18.8

Open the chart page →

16,299
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

11,546
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.18.8

Open the chart page →

19,293
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
jackson-databind@2.17.0
2.18.8

Open the chart page →

30,524
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
jackson-databind@2.12.3
2.18.8

Open the chart page →

26,022
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
jackson-databind@2.12.6
2.18.8

Open the chart page →

15,727
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
jackson-databind@2.13.4.2
2.18.8

Open the chart page →

5,719
commafeedmt1905028.2.01 of 3See more

commafeed mt190502 8.2.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
jackson-databind@2.20.1
2.21.4

Open the chart page →

3,733
keycloakmt1905021.4.61 of 3See more

keycloak mt190502 1.4.6

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.5.68d44614c7479
jackson-databind@2.19.2
2.21.4

Open the chart page →

2,924
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
jackson-databind@2.13.4
2.18.8

Open the chart page →

8,976
pagesmuthu-pages1.0.01 of 3See more

pages muthu-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
jackson-databind@2.17.1
2.18.8

Open the chart page →

2,143
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
jackson-databind@2.10.4
2.18.8

Open the chart page →

9,345
Practica_4_helmmy-heml-appVerified publisher0.1.03 of 7See more

Practica_4_helm my-heml-app 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
adagber/planner:v1.0e5c1ed097752
jackson-databind@2.13.0
2.18.8
codeurjc/server:v1.0310bea5b1ee7
jackson-databind@2.13.4.2
2.18.8
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.8

Open the chart page →

27,822
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
jackson-databind@2.18.3
2.18.8

Open the chart page →

1,786
pagesnarain1.0.01 of 3See more

pages narain 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
pagesnarasimha-pages1.0.01 of 3See more

pages narasimha-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
pagesnavin-brixton1.0.01 of 3See more

pages navin-brixton 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ncsa/datawolf:4.7.0af6649d59150
jackson-databind@2.0.5
2.18.8

Open the chart page →

4,990
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
jackson-databind@2.16.1
2.18.8

Open the chart page →

15,429
polyglotncsaVerified publisher0.1.114 of 18See more

polyglot ncsa 0.1.1

14 of the 18 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
jackson-databind@2.5.0
2.18.8
ncsapolyglot/converters-avconv:latestc44b22eb58bb
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-ffmpeg:latest48c852c1204b
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-flac:latest072cf5bc6f99
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-gdal:latestf746049515c1
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-ghostscript:latestf350da56dd55
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-htmldoc:latest317dd9e56922
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-imagemagick:latestd244ea8c32ac
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-txt2html:latest30ee96508c0b
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
jackson-databind@2.2.3
2.18.8
ncsapolyglot/converters-zip:latestf889fe30e2c7
jackson-databind@2.2.3
2.18.8
ncsapolyglot/polyglot:2.4.097a8c01c076e
jackson-databind@2.2.3
2.18.8

Open the chart page →

55,728
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
jackson-databind@2.10.5.1
2.18.8

Open the chart page →

2,641
ma1sdnetsocVerified publisher0.2.11 of 1See more

ma1sd netsoc 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
jackson-databind@2.9.9.1
2.18.8

Open the chart page →

3,583
neuralbank-stackneuralbank-stack0.1.01 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-databind@2.20.0
2.21.4

Open the chart page →

5,279
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
jackson-databind@2.13.3
2.18.8

Open the chart page →

3,425
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
jackson-databind@2.13.3
2.18.8

Open the chart page →

5,900
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jackson-databind@2.10.5.1
2.18.8

Open the chart page →

4,558
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
jackson-databind@2.13.3
2.18.8

Open the chart page →

6,878
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
jackson-databind@2.13.3
2.18.8

Open the chart page →

5,942
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
jackson-databind@2.13.3
2.18.8

Open the chart page →

5,899
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
jackson-databind@2.10.3
2.18.8

Open the chart page →

3,635
nexus2novum-rgi-charts0.1.11 of 1See more

nexus2 novum-rgi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
sonatype/nexus:oss6bc88b51d4d7
jackson-databind@2.11.3
2.18.8

Open the chart page →

3,220
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
jackson-databind@2.15.2
2.18.8

Open the chart page →

2,093
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
jackson-databind@2.17.0
2.18.8

Open the chart page →

5,826
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jackson-databind@2.4.0
2.18.8

Open the chart page →

8,547
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
jackson-databind@2.14.2
2.18.8

Open the chart page →

9,062
apicurioone-acre-fundVerified publisher2.3.03 of 5See more

apicurio one-acre-fund 2.3.0

3 of the 5 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
jackson-databind@2.15.2
2.18.8
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
jackson-databind@2.15.2
2.18.8
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
jackson-databind@2.15.2
2.18.8

Open the chart page →

18,667

Container images carrying it

870 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-databind@2.17.2
2.18.8
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jackson-databind@2.13.4.2
2.18.8
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
jackson-databind@2.13.4.2
2.18.8
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-databind@2.20.0
2.21.4
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-databind@2.15.3
2.18.8
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-databind@2.19.2
2.21.4
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jackson-databind@2.10.1
2.18.8
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
jackson-databind@2.14.1
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-databind@2.15.3
2.18.8
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-databind@2.17.2
2.18.8
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
jackson-databind@2.13.5
2.18.8
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
jackson-databind@2.12.3
2.18.8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.8
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.8
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.8
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
jackson-databind@2.13.5
2.18.8
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.