StackRadar

CVE-2026-54514

Medium

Advisory

Published 23 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
871
of 17,787 indexed, latest versions
Container images
876
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)

Carried by container images the latest versions of 871 of 17,787 indexed charts deploy, on 876 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.0.5, 2.2.3, 2.3.0, 2.3.3+105 more2.18.8, 2.21.4, 3.1.4876
OSV records
GHSA-hgj6-7826-r7m5

Charts affected

871 by stars
ChartLatestAffected imagesRadar Score
radar-upload-connect-backendradar-baseVerified publisher0.9.11 of 1See more

radar-upload-connect-backend radar-base 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
jackson-databind@2.19.2
2.21.4

Open the chart page →

2,571
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-databind@2.18.3
2.18.8

Open the chart page →

1,968
pagesranjinigogga1.0.01 of 3See more

pages ranjinigogga 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
pagesrebecca-pages1.0.01 of 3See more

pages rebecca-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
authentication-serviceredestroyder0.2.21 of 1See more

authentication-service redestroyder 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
redestroyder/authorization-service:0.0.1740364a619fd
jackson-databind@2.13.1
2.18.8

Open the chart page →

2,583
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
jackson-databind@2.13.1
2.18.8

Open the chart page →

2,600
iparedhat-cop1.3.91 of 1See more

ipa redhat-cop 1.3.9

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
jackson-databind@2.15.2
2.18.8

Open the chart page →

951
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
jackson-databind@2.17.1
2.18.8

Open the chart page →

4,242
reportportalreportportal5.7.23 of 8See more

reportportal reportportal 5.7.2

3 of the 8 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
jackson-databind@2.10.2
2.18.8
reportportal/service-authorization:5.7.09e73114dbd15
jackson-databind@2.10.2
2.18.8
reportportal/service-jobs:5.7.2dc166c58485a
jackson-databind@2.11.4
2.18.8

Open the chart page →

25,739
pagesroccohiggins-pages1.0.01 of 3See more

pages roccohiggins-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
pagesronan-pages1.0.01 of 3See more

pages ronan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
routr-connectroutr0.4.32 of 10See more

routr-connect routr 0.4.3

2 of the 10 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
fonoster/routr-edgeport:2.13.6d08a8a574a50
jackson-databind@2.9.6
2.18.8
fonoster/routr-requester:2.13.6e0c823506eb2
jackson-databind@2.9.6
2.18.8

Open the chart page →

11,021
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jackson-databind@3.1.2
3.1.4

Open the chart page →

6,293
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
jackson-databind@2.12.2
2.18.8

Open the chart page →

3,978
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
jackson-databind@2.13.3
2.18.8

Open the chart page →

16,159
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
jackson-databind@2.13.3
2.18.8

Open the chart page →

8,073
helm-chart-examplesalaboy0.1.01 of 1See more

helm-chart-example salaboy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
jackson-databind@2.11.1
2.18.8

Open the chart page →

2,847
pagessamanvithkaranth1.0.01 of 3See more

pages samanvithkaranth 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
pagessarubits-pages1.0.01 of 3See more

pages sarubits-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
jackson-databind@2.15.2
2.18.8

Open the chart page →

1,597
keycloaksb-helm-charts0.3.01 of 2See more

keycloak sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-databind@2.17.2
2.18.8

Open the chart page →

2,591
smartquerysearchhub0.1.01 of 1See more

smartquery searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
commerceexperts/smartquery-service:2.2.09e33ad89baf6
jackson-databind@2.13.5
2.18.8

Open the chart page →

1,527
smartsuggestsearchhub0.1.01 of 1See more

smartsuggest searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
jackson-databind@2.15.3
2.18.8

Open the chart page →

1,235
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
jackson-databind@2.13.5
2.18.8

Open the chart page →

4,245
pagessekharpkube1.0.01 of 3See more

pages sekharpkube 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
jackson-databind@2.9.9
2.18.8

Open the chart page →

8,098
keycloakself-hosters-by-nightVerified publisher0.1.11 of 1See more

keycloak self-hosters-by-night 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-databind@2.21.2
2.21.4

Open the chart page →

519
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
jackson-databind@2.9.10.1
2.18.8

Open the chart page →

10,972
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
jackson-databind@2.17.0
2.18.8

Open the chart page →

5,496
shenyushenyu0.6.32 of 2See more

shenyu shenyu 0.6.3

2 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.5.1e2be712fc4f4
jackson-databind@2.13.3
2.18.8
apache/shenyu-bootstrap:2.5.11bd5756f6273
jackson-databind@2.13.2.1
2.18.8

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.272 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

2 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
jackson-databind@2.10.1
2.18.8
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
jackson-databind@2.10.1
2.18.8

Open the chart page →

12,512
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.4

Open the chart page →

5,230
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
jackson-databind@2.13.2.1
2.18.8

Open the chart page →

2,919
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.8

Open the chart page →

1,689
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
jackson-databind@2.13.4.2
2.18.8

Open the chart page →

6,443
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
jackson-databind@2.14.1
2.18.8

Open the chart page →

4,948
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
jackson-databind@2.13.3
2.18.8

Open the chart page →

5,894
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
jackson-databind@2.9.10
2.18.8

Open the chart page →

6,950
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
jackson-databind@2.3.0
2.18.8

Open the chart page →

6,907
hetzner-iroboslamdev0.0.51 of 1See more

hetzner-irobo slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
slamdev/hetzner-irobo:0.0.13ca20c184c55
jackson-databind@2.12.5
2.18.8

Open the chart page →

3,754
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
jackson-databind@3.1.1
3.1.4

Open the chart page →

3,042
stewardsoftwaremillVerified publisher0.1.121 of 1See more

steward softwaremill 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
fthomas/scala-steward:latest367afe974b7a
jackson-databind@2.12.7.1
2.18.8

Open the chart page →

590
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
jackson-databind@2.10.0
2.18.8

Open the chart page →

13,653
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
jackson-databind@2.10.0
2.18.8

Open the chart page →

13,127
smtp-fake-serversomeblackmagic0.1.01 of 1See more

smtp-fake-server someblackmagic 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
someblackmagic/smtp-fake-server:latest0d63ba37a560
jackson-databind@2.11.3
2.18.8

Open the chart page →

4,278
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.8

Open the chart page →

1,853
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.8

Open the chart page →

20,233
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jackson-databind@2.10.1
2.18.8

Open the chart page →

3,165
retail-store-sample-cart-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-cart-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54514.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
jackson-databind@2.19.2
2.21.4

Open the chart page →

1,068

Container images carrying it

876 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
anguda/ant-media:2.5c435285fc241
jackson-databind@2.9.6
2.18.8
1
apache/bookkeeper:4.14.5a7d9970c148f
jackson-databind@2.11.0
2.18.8
1
apache/camel-k:1.10.43bb13d14f64a
jackson-databind@2.13.4
2.18.8
1
apache/drill:1.21.11f96558fd292
jackson-databind@2.14.1
2.18.8
1
apache/druid:29.0.10cef139b6bf1
jackson-databind@2.13.4.2
2.18.8
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
jackson-databind@2.21.3
2.21.4
1
apache/hadoop:3af361b20bec0
jackson-databind@2.12.7.1
2.18.8
1
apache/hertzbeat:1.8.075d48a62748f
jackson-databind@2.18.2
2.18.8
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
jackson-databind@2.18.2
2.18.8
1
apacheignite/ignite:2.7.0d7deab68b8fa
jackson-databind@2.9.6
2.18.8
1
apache/iotdb:0.11.28647309f95d1
jackson-databind@2.10.0
2.18.8
1
apache/iotdb:0.13.3-nodeafa47bf1692a
jackson-databind@2.10.5
2.18.8
1
apache/kafka:4.1.0bff074a5d005
jackson-databind@2.19.0
2.21.4
1
apache/kafka:3.9.0fbc7d7c428e3
jackson-databind@2.16.2
2.18.8
1
apache/nifi-registry:1.14.0090b7f87ec7f
jackson-databind@2.12.3
2.18.8
1
apache/nifi-registry:1.27.063b8e3e40742
jackson-databind@2.17.1
2.18.8
1
apache/nifi-registry:0.8.0974efa2f21da
jackson-databind@2.10.3
2.18.8
1
apachepinot/pinot:latest-jdk110018bb04ced7
jackson-databind@2.4.0
2.18.8
1
apache/polaris:lateste66366e783f1
jackson-databind@2.18.6
2.18.8
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
jackson-databind@2.14.2
2.18.8
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
jackson-databind@2.12.6
2.18.8
1
apachepulsar/pulsar:2.6.14db6ff0b4045
jackson-databind@2.11.1
2.18.8
1
apachepulsar/pulsar:3.0.79c9947de139d
jackson-databind@2.14.2
2.18.8
1
apachepulsar/pulsar:2.9.0d056c89b7131
jackson-databind@2.12.3
2.18.8
1
apachepulsar/pulsar:2.8.2d538416d5afe
jackson-databind@2.12.3
2.18.8
1
apache/ranger:2.7.076c176e8a0e4
jackson-databind@2.17.2
2.18.8
1
apache/rocketmq-exporter:0.0.2c8fb51195444
jackson-databind@2.13.5
2.18.8
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
jackson-databind@2.10.1
2.18.8
1
apache/shenyu-admin:2.5.1e2be712fc4f4
jackson-databind@2.13.3
2.18.8
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
jackson-databind@2.13.2.1
2.18.8
1
apache/skywalking-oap-server:9.2.0133d35d2c263
jackson-databind@2.13.2.2
2.18.8
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
jackson-databind@2.9.5
2.18.8
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
jackson-databind@2.12.2
2.18.8
1
apache/skywalking-ui:9.2.0295f1dc87d98
jackson-databind@2.13.2.2
2.18.8
1
apache/skywalking-ui:8.1.067d50e4deff4
jackson-databind@2.9.10
2.18.8
1
apache/skywalking-ui:8.9.180530f0308a5
jackson-databind@2.12.2
2.18.8
1
apache/tika:3.3.1.090b7fa1dc018
jackson-databind@2.21.3
2.21.4
1
apache/tika:2.9.0.092d055a84e9e
jackson-databind@2.15.2
2.18.8
1
apache/tika:3.2.2.0-fullffab324253ed
jackson-databind@2.19.2
2.21.4
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
jackson-databind@2.11.3
2.18.8
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jackson-databind@2.12.1
2.18.8
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
jackson-databind@2.15.2
2.18.8
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
jackson-databind@2.15.2
2.18.8
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
jackson-databind@2.15.2
2.18.8
1
apimap/api:v1.8.11ae2b3ab00177
jackson-databind@2.13.4.2
2.18.8
1
aroralalit/student-producer:1.0.02a094f597b36
jackson-databind@2.13.5
2.18.8
1
arturisimo/planner:v1.0fff9de644941
jackson-databind@2.13.0
2.18.8
1
arturisimo/webapp-db-java:v2c95524e90b57
jackson-databind@2.13.1
2.18.8
1
assistiot/authorization_svr:latestdb9361dad79b
jackson-databind@2.6.0
2.18.8
1
assistiot/automated_configuration:latest23f195a7a26a
jackson-databind@2.2.3
2.18.8
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.