StackRadar

CVE-2026-54514

Medium

Advisory

Published 23 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
869
of 17,790 indexed, latest versions
Container images
870
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)

Carried by container images the latest versions of 869 of 17,790 indexed charts deploy, on 870 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.0.5, 2.2.3, 2.3.0, 2.3.3+105 more2.18.8, 2.21.4, 3.1.4870
OSV records
GHSA-hgj6-7826-r7m5

Charts affected

869 by stars
ChartLatestAffected imagesRadar Score
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
jackson-databind@2.9.9
2.18.8

Open the chart page →

6,104
cerebrostakaterVerified publisher0.5.11 of 2See more

cerebro stakater 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
lmenezes/cerebro:0.8.13e860068e403
jackson-databind@2.8.11.1
2.18.8

Open the chart page →

2,956
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
jackson-databind@2.21.2
2.21.4

Open the chart page →

1,703
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.4

Open the chart page →

2,498
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jackson-databind@2.13.3
2.18.8

Open the chart page →

11,557
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jackson-databind@2.13.3
2.18.8

Open the chart page →

11,557
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
jackson-databind@2.9.5
2.18.8

Open the chart page →

11,845
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
jackson-databind@2.18.3
2.18.8

Open the chart page →

3,198
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
jackson-databind@2.13.1
2.18.8

Open the chart page →

14,548
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jackson-databind@2.12.3
2.18.8

Open the chart page →

6,067
solrstatcan1.5.102 of 3See more

solr statcan 1.5.10

2 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jackson-databind@2.12.3
2.18.8
library/zookeeper:3.5.5b7a76ec06f68
jackson-databind@2.9.8
2.18.8

Open the chart page →

8,808
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
jackson-databind@2.13.3
2.18.8

Open the chart page →

13,844
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.54 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

4 of the 6 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
jackson-databind@2.13.4.2
2.18.8
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
jackson-databind@2.13.4.2
2.18.8
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
jackson-databind@2.13.4.2
2.18.8
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
jackson-databind@2.13.4.2
2.18.8

Open the chart page →

13,696
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
jackson-databind@2.3.3
2.18.8

Open the chart page →

8,556
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
jackson-databind@2.15.0
2.18.8

Open the chart page →

1,830
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.009a381c715ab
jackson-databind@2.17.2
2.18.8

Open the chart page →

5,116
student-producerstudentproducerVerified publisher2.0.01 of 1See more

student-producer studentproducer 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
aroralalit/student-producer:1.0.02a094f597b36
jackson-databind@2.13.5
2.18.8

Open the chart page →

3,021
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
jackson-databind@2.17.0
2.18.8

Open the chart page →

4,701
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jackson-databind@2.15.0
2.18.8

Open the chart page →

18,846
languagetool-serverszpadel-chartsVerified publisher0.4.01 of 1See more

languagetool-server szpadel-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
jackson-databind@2.17.2
2.18.8

Open the chart page →

809
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
jackson-databind@2.7.9.3
2.18.8

Open the chart page →

4,538
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
jackson-databind@2.12.7.1
2.18.8

Open the chart page →

4,240
clickhousetemp-charts0.7.11 of 3See more

clickhouse temp-charts 0.7.1

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
library/zookeeper:3.6.180ad2170ad62
jackson-databind@2.10.3
2.18.8

Open the chart page →

8,706
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
yuzutech/kroki:0.17.0192b7b27c857
jackson-databind@2.13.1
2.18.8

Open the chart page →

8,717
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
shenyutest-helm2.4.212 of 2See more

shenyu test-helm 2.4.21

2 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
jackson-databind@2.10.1
2.18.8
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
jackson-databind@2.10.1
2.18.8

Open the chart page →

12,516
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
jackson-databind@2.13.2
2.18.8
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
jackson-databind@2.13.2
2.18.8
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
jackson-databind@2.13.2
2.18.8
thingsboard/tb-node:3.4.1645f43b688f7
jackson-databind@2.13.2
2.18.8

Open the chart page →

25,423
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jackson-databind@2.21.1
2.21.4

Open the chart page →

1,826
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.4

Open the chart page →

4,445
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
jackson-databind@2.15.3
2.18.8

Open the chart page →

3,225
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jackson-databind@2.12.1
2.18.8

Open the chart page →

12,724
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
jackson-databind@2.17.2
2.18.8

Open the chart page →

2,147
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest0ad069035863
jackson-databind@2.21.2
2.21.4

Open the chart page →

1,569
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
jackson-databind@2.19.2
2.21.4

Open the chart page →

1,530
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
jackson-databind@2.19.2
2.21.4

Open the chart page →

1,693
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
jackson-databind@2.16.2
2.18.8

Open the chart page →

1,733
opencloudunxwaresVerified publisher0.2.32 of 13See more

opencloud unxwares 0.2.3

2 of the 13 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
jackson-databind@2.17.0
2.18.8
quay.io/keycloak/keycloak:26.1.4044a457e0498
jackson-databind@2.17.2
2.18.8

Open the chart page →

45,472
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jackson-databind@2.8.4
2.18.8

Open the chart page →

4,304
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
jackson-databind@2.12.4
2.18.8

Open the chart page →

7,897
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,242
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
jackson-databind@2.18.2
2.18.8

Open the chart page →

5,492
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jackson-databind@2.9.8
2.18.8

Open the chart page →

4,650
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
jackson-databind@2.9.8
2.18.8

Open the chart page →

3,177
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
jackson-databind@2.14.1
2.18.8
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
jackson-databind@2.15.2
2.18.8

Open the chart page →

9,403
webapp-db-javawebapp-db-java-repo0.1.01 of 2See more

webapp-db-java webapp-db-java-repo 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
arturisimo/webapp-db-java:v2c95524e90b57
jackson-databind@2.13.1
2.18.8

Open the chart page →

2,568

Container images carrying it

870 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-databind@2.17.2
2.18.8
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jackson-databind@2.13.4.2
2.18.8
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
jackson-databind@2.13.4.2
2.18.8
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-databind@2.20.0
2.21.4
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-databind@2.15.3
2.18.8
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-databind@2.19.2
2.21.4
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jackson-databind@2.10.1
2.18.8
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
jackson-databind@2.14.1
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-databind@2.15.3
2.18.8
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-databind@2.17.2
2.18.8
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
jackson-databind@2.13.5
2.18.8
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
jackson-databind@2.12.3
2.18.8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.8
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.8
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.8
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
jackson-databind@2.13.5
2.18.8
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.