StackRadar

CVE-2026-59888

Medium

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
380
of 17,781 indexed, latest versions
Container images
390
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

Carried by container images the latest versions of 380 of 17,781 indexed charts deploy, on 390 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.15.0, 2.15.1, 2.15.2, 2.15.3+31 more2.18.8, 2.21.4, 3.1.4390
OSV records
GHSA-3pjw-73gf-8qr5

Charts affected

380 by stars
ChartLatestAffected imagesRadar Score
edge-oai-pmhfolio-org0.1.311 of 1See more

edge-oai-pmh folio-org 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/edge-oai-pmh:latesteedfcbc29792
jackson-databind@2.18.2
2.18.8

Open the chart page →

874
edge-ordersfolio-org0.1.301 of 1See more

edge-orders folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/edge-orders:latest1ef654ee9f23
jackson-databind@2.18.6
2.18.8

Open the chart page →

735
edge-patronfolio-org0.1.281 of 1See more

edge-patron folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/edge-patron:latest682b852e056d
jackson-databind@3.1.0
3.1.4

Open the chart page →

905
edge-rtacfolio-org0.1.281 of 1See more

edge-rtac folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/edge-rtac:latest15ef73b1abd0
jackson-databind@3.0.4
3.1.4

Open the chart page →

1,259
mod-authtokenfolio-org0.1.351 of 1See more

mod-authtoken folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-authtoken:latest995a25a33133
jackson-databind@2.16.1
2.18.8

Open the chart page →

1,558
mod-circulationfolio-org0.1.351 of 1See more

mod-circulation folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-circulation:latest3eecd2ac2d8a
jackson-databind@2.18.6
2.18.8

Open the chart page →

497
mod-circulation-storagefolio-org0.1.351 of 1See more

mod-circulation-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-circulation-storage:latest6bdddcafbc0f
jackson-databind@2.18.6
2.18.8

Open the chart page →

658
mod-configurationfolio-org0.1.341 of 1See more

mod-configuration folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-configuration:latestdd0cdc89670a
jackson-databind@2.18.6
2.18.8

Open the chart page →

711
mod-copycatfolio-org0.1.31 of 1See more

mod-copycat folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-copycat:latest1513fad2b799
jackson-databind@2.18.6
2.18.8

Open the chart page →

1,466
mod-coursesfolio-org0.1.341 of 1See more

mod-courses folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-courses:latest68ca414f5596
jackson-databind@2.18.2
2.18.8

Open the chart page →

1,533
mod-data-exportfolio-org0.1.401 of 1See more

mod-data-export folio-org 0.1.40

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-data-export:latest0cc86bf09755
jackson-databind@2.20.2
2.21.4

Open the chart page →

1,393
mod-data-export-springfolio-org0.1.41 of 1See more

mod-data-export-spring folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-data-export-spring:latestf1d7caf4544b
jackson-databind@3.0.4
3.1.4

Open the chart page →

1,253
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
jackson-databind@3.0.4
3.1.4

Open the chart page →

1,214
mod-ebsconetfolio-org0.1.31 of 1See more

mod-ebsconet folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-ebsconet:latest3ae8cb99daa3
jackson-databind@2.20.2
2.21.4

Open the chart page →

1,203
mod-emailfolio-org0.1.341 of 1See more

mod-email folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-email:latest79ea8e2e7ebf
jackson-databind@2.18.2
2.18.8

Open the chart page →

866
mod-erm-usage-harvesterfolio-org0.1.341 of 1See more

mod-erm-usage-harvester folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-erm-usage-harvester:latest2d6767933c59
jackson-databind@2.18.6
2.18.8

Open the chart page →

563
mod-feesfinesfolio-org0.1.341 of 1See more

mod-feesfines folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-feesfines:latestfe3a7049f2fb
jackson-databind@2.18.2
2.18.8

Open the chart page →

663
mod-gobifolio-org0.1.341 of 1See more

mod-gobi folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-gobi:latestc58c989dac44
jackson-databind@2.20.1
2.21.4

Open the chart page →

595
mod-inventory-updatefolio-org0.1.21 of 1See more

mod-inventory-update folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-inventory-update:latestba84812b4d58
jackson-databind@2.18.2
2.18.8

Open the chart page →

878
mod-ldpfolio-org0.1.331 of 1See more

mod-ldp folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-ldp:latestb55696fd9065
jackson-databind@2.15.4
2.18.8

Open the chart page →

1,938
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
jackson-databind@2.18.7
2.18.8

Open the chart page →

1,760
mod-loginfolio-org0.1.341 of 1See more

mod-login folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-login:latest88de493f86db
jackson-databind@2.16.1
2.18.8

Open the chart page →

1,151
mod-login-samlfolio-org0.1.341 of 1See more

mod-login-saml folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-login-saml:latest5f3358ccaa0f
jackson-databind@2.21.2
2.21.4

Open the chart page →

1,088
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
jackson-databind@2.18.7
2.18.8

Open the chart page →

1,733
mod-oai-pmhfolio-org0.1.341 of 1See more

mod-oai-pmh folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-oai-pmh:latest5cd5ef063f2a
jackson-databind@2.18.2
2.18.8

Open the chart page →

962
mod-organizationsfolio-org0.1.341 of 1See more

mod-organizations folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-organizations:latest7dc9ccf3d937
jackson-databind@2.18.6
2.18.8

Open the chart page →

808
mod-organizations-storagefolio-org0.1.341 of 1See more

mod-organizations-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-organizations-storage:lateste46892405fde
jackson-databind@3.1.3
3.1.4

Open the chart page →

665
mod-patronfolio-org0.1.341 of 1See more

mod-patron folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-patron:latest5f213acfe2f8
jackson-databind@2.18.2
2.18.8

Open the chart page →

827
mod-permissionsfolio-org0.1.351 of 1See more

mod-permissions folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-permissions:latest5363e98c6299
jackson-databind@2.18.6
2.18.8

Open the chart page →

1,214
mod-pubsubfolio-org0.1.341 of 1See more

mod-pubsub folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-pubsub:latest0a4fa4ad5d72
jackson-databind@2.18.6
2.18.8

Open the chart page →

1,009
mod-rtacfolio-org0.1.341 of 1See more

mod-rtac folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-rtac:latestc959b2d6142f
jackson-databind@2.18.2
2.18.8

Open the chart page →

665
mod-senderfolio-org0.1.341 of 1See more

mod-sender folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-sender:latestd88a675dddf0
jackson-databind@2.18.2
2.18.8

Open the chart page →

818
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
jackson-databind@2.18.7
2.18.8

Open the chart page →

1,733
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
jackson-databind@2.18.7
2.18.8

Open the chart page →

1,733
mod-template-enginefolio-org0.1.341 of 1See more

mod-template-engine folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-template-engine:latestd105c585da30
jackson-databind@2.18.2
2.18.8

Open the chart page →

818
mod-user-importfolio-org0.1.341 of 1See more

mod-user-import folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-user-import:latest1807734472bd
jackson-databind@2.18.6
2.18.8

Open the chart page →

1,214
mod-users-blfolio-org0.1.351 of 1See more

mod-users-bl folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
folioci/mod-users-bl:latest4e2d96c9340d
jackson-databind@2.18.2
2.18.8

Open the chart page →

1,321
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jackson-databind@2.15.3
2.18.8

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jackson-databind@2.15.3
2.18.8

Open the chart page →

11,961
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
jackson-databind@2.16.1
2.18.8

Open the chart page →

8,923
geysergeyserVerified publisher0.1.31 of 1See more

geyser geyser 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
ghcr.io/joffreybvn/k8s-geyser:0.0.247f36880072e
jackson-databind@2.18.0
2.18.8

Open the chart page →

350
opentelemetry-demogpg-dev0.33.84 of 27See more

opentelemetry-demo gpg-dev 0.33.8

4 of the 27 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-databind@2.17.2
2.18.8
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jackson-databind@2.16.0
2.18.8
ghcr.io/open-telemetry/demo:1.12.0-frauddetectionservice77cefdab4d5c
jackson-databind@2.17.1
2.18.8
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
jackson-databind@2.17.2
2.18.8

Open the chart page →

49,025
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
jackson-databind@2.21.3
2.21.4

Open the chart page →

4,556
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
jackson-databind@2.17.2
2.18.8

Open the chart page →

5,261
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
jackson-databind@2.19.4
2.21.4

Open the chart page →

1,691
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
jackson-databind@2.19.2
2.21.4

Open the chart page →

3,199
hello-world-apihello-world-api0.0.51 of 1See more

hello-world-api hello-world-api 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
fabioformosa/hello-world-api:latest063873af085c
jackson-databind@2.18.3
2.18.8

Open the chart page →

1,417
cruise-controlhelm-cruise-controlVerified publisher2.1.11 of 2See more

cruise-control helm-cruise-control 2.1.1

1 of the 2 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
jackson-databind@2.16.2
2.18.8

Open the chart page →

1,453
alfiohelmforgeVerified publisher1.2.121 of 3See more

alfio helmforge 1.2.12

1 of the 3 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
alfio/alf.io:2.0-M5-26060c836a081446
jackson-databind@2.21.2
2.21.4

Open the chart page →

2,091
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-59888.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
jackson-databind@2.18.0
2.18.8

Open the chart page →

9,920

Container images carrying it

390 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
jackson-databind@2.21.3
2.21.4
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
jackson-databind@2.19.2
2.21.4
1
ghcr.io/wundergraph/cosmo/keycloak:0.13.0b37408461b9b
jackson-databind@2.19.2
2.21.4
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime4d3a8042c761
jackson-databind@2.16.1
2.18.8
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.54.4_localb2b97137aef5
jackson-databind@2.16.1
2.18.8
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:improve-testing-performance8e9d15ed71c7
jackson-databind@2.16.1
2.18.8
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jackson-databind@2.16.1
2.18.8
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
jackson-databind@2.19.0
2.21.4
1
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
jackson-databind@2.19.2
2.21.4
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
jackson-databind@2.19.2
2.21.4
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
jackson-databind@2.19.2
2.21.4
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
jackson-databind@2.18.2
2.18.8
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
jackson-databind@2.15.2
2.18.8
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
jackson-databind@2.20.0
2.21.4
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
jackson-databind@2.17.2
2.18.8
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
jackson-databind@2.19.2
2.21.4
1
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
jackson-databind@2.19.2
2.21.4
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
jackson-databind@2.15.0
2.18.8
1
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
jackson-databind@2.15.2
2.18.8
1
quay.io/keycloak/keycloak:26.009a381c715ab
jackson-databind@2.17.2
2.18.8
1
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-databind@2.21.2
2.21.4
1
quay.io/keycloak/keycloak:26.0.74388e2379b7e
jackson-databind@2.17.2
2.18.8
1
quay.io/keycloak/keycloak:24.0.34d6f22991266
jackson-databind@2.16.1
2.18.8
1
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
jackson-databind@2.15.2
2.18.8
1
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.8
1
quay.io/keycloak/keycloak:26.5.68d44614c7479
jackson-databind@2.19.2
2.21.4
1
quay.io/keycloak/keycloak:26.49409c59bdfb6
jackson-databind@2.19.2
2.21.4
1
quay.io/keycloak/keycloak:26.6.39b0330756022
jackson-databind@2.21.2
2.21.4
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-databind@2.17.2
2.18.8
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-databind@2.20.0
2.21.4
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.4
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-databind@2.15.3
2.18.8
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-databind@2.19.2
2.21.4
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
jackson-databind@2.15.3
2.18.8
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-databind@2.15.3
2.18.8
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-databind@2.17.2
2.18.8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.8
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.