StackRadar

CVE-2026-59889

Medium

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
224
of 17,781 indexed, latest versions
Container images
224
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

Carried by container images the latest versions of 224 of 17,781 indexed charts deploy, on 224 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.18.0, 2.18.1, 2.18.2, 2.18.3+17 more2.18.9, 2.21.5, 2.22.1, 3.1.5+1 more224
OSV records
GHSA-5gvw-p9qm-jgwh

Charts affected

224 by stars
ChartLatestAffected imagesRadar Score
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-databind@2.18.3
2.18.9

Open the chart page →

1,951
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
jackson-databind@2.21.4
2.21.5

Open the chart page →

2,261
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jackson-databind@3.1.2
3.1.5

Open the chart page →

6,207
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jackson-databind@2.22.0
2.22.1

Open the chart page →

1,610
keycloakself-hosters-by-nightVerified publisher0.1.11 of 1See more

keycloak self-hosters-by-night 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-databind@2.21.2
2.21.5

Open the chart page →

518
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.5

Open the chart page →

5,201
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.9

Open the chart page →

1,690
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
jackson-databind@3.1.1
3.1.5

Open the chart page →

3,003
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,702
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
jackson-databind@2.18.3
2.18.9

Open the chart page →

3,153
tekton-ci-environment-injectortekton-ci-environment-injectorVerified publisher0.2.41 of 1See more

tekton-ci-environment-injector tekton-ci-environment-injector 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
jackson-databind@2.21.4
2.21.5

Open the chart page →

510
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
jackson-databind@2.21.4
2.21.5

Open the chart page →

1,082
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jackson-databind@2.21.1
2.21.5

Open the chart page →

1,825
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

4,423
openunison-operatortremolo3.0.301 of 1See more

openunison-operator tremolo 3.0.30

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5

Open the chart page →

2,126
orchestratremolo3.1.552 of 5See more

orchestra tremolo 3.1.55

2 of the 5 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
jackson-databind@2.21.3
2.21.5
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5

Open the chart page →

7,637
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest0ad069035863
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,551
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
jackson-databind@2.18.2
2.18.9

Open the chart page →

5,484
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,639
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-databind@2.18.0
2.18.9

Open the chart page →

9,381
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
jackson-databind@2.18.0
2.18.9

Open the chart page →

1,571
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,159

Container images carrying it

224 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
erudikaltd/para:latest_stable235e0bc53da2
jackson-databind@2.21.4
2.21.5
1
erudikaltd/scoold:1.66.0949c56b57e8f
jackson-databind@3.0.4
3.1.5
1
fabioformosa/hello-world-api:latest063873af085c
jackson-databind@2.18.3
2.18.9
1
folioci/edge-caiasoft:latestc3cfa89eee2f
jackson-databind@2.21.4
2.21.5
1
folioci/edge-connexion:latestb4863d135524
jackson-databind@2.18.2
2.18.9
1
folioci/edge-dematic:latest48c9b1d180d4
jackson-databind@3.1.4
3.1.5
1
folioci/edge-inn-reach:latestc64e4d9dd3fc
jackson-databind@3.1.4
3.1.5
1
folioci/edge-ncip:lateste760dbb81d1a
jackson-databind@2.18.2
2.18.9
1
folioci/edge-oai-pmh:latesteedfcbc29792
jackson-databind@2.18.2
2.18.9
1
folioci/edge-orders:latest1ef654ee9f23
jackson-databind@2.18.6
2.18.9
1
folioci/edge-patron:latest682b852e056d
jackson-databind@3.1.0
3.1.5
1
folioci/edge-rtac:latest15ef73b1abd0
jackson-databind@3.0.4
3.1.5
1
folioci/edge-sip2:latest86106f20ef51
jackson-databind@2.21.4
2.21.5
1
folioci/mod-agreements:latest29c3f233a498
jackson-databind@2.22.0
2.22.1
1
folioci/mod-audit:latest88f40730ed45
jackson-databind@3.1.4
3.1.5
1
folioci/mod-calendar:latest22f65982efd7
jackson-databind@3.1.4
3.1.5
1
folioci/mod-circulation:latest3eecd2ac2d8a
jackson-databind@2.18.6
2.18.9
1
folioci/mod-circulation-storage:latest6bdddcafbc0f
jackson-databind@2.18.6
2.18.9
1
folioci/mod-configuration:latestdd0cdc89670a
jackson-databind@2.18.6
2.18.9
1
folioci/mod-copycat:latest1513fad2b799
jackson-databind@2.18.6
2.18.9
1
folioci/mod-courses:latest68ca414f5596
jackson-databind@2.18.2
2.18.9
1
folioci/mod-data-export:latest0cc86bf09755
jackson-databind@3.0.4
3.1.5
1
folioci/mod-data-export-spring:latestf1d7caf4544b
jackson-databind@3.0.4
3.1.5
1
folioci/mod-data-export-worker:latest1ad1811c9b37
jackson-databind@3.0.4
3.1.5
1
folioci/mod-ebsconet:latest3ae8cb99daa3
jackson-databind@3.1.0
3.1.5
1
folioci/mod-email:latest79ea8e2e7ebf
jackson-databind@2.18.2
2.18.9
1
folioci/mod-erm-usage-harvester:latest2d6767933c59
jackson-databind@2.18.6
2.18.9
1
folioci/mod-event-config:latest0192adad3897
jackson-databind@3.1.4
3.1.5
1
folioci/mod-feesfines:latestfe3a7049f2fb
jackson-databind@2.18.2
2.18.9
1
folioci/mod-finance:latest14450bc15430
jackson-databind@2.21.4
2.21.5
1
folioci/mod-finance-storage:latest4bc4057abaea
jackson-databind@3.1.4
3.1.5
1
folioci/mod-inn-reach:latestcc8584e43382
jackson-databind@3.1.4
3.1.5
1
folioci/mod-inventory-update:latestba84812b4d58
jackson-databind@2.18.2
2.18.9
1
folioci/mod-invoice:latest45b7b13e81e1
jackson-databind@3.1.4
3.1.5
1
folioci/mod-licenses:latestcfd6109bf477
jackson-databind@2.18.7
2.18.9
1
folioci/mod-login-saml:latest5f3358ccaa0f
jackson-databind@2.21.2
2.21.5
1
folioci/mod-notify:latesta8c1a90005fc
jackson-databind@3.1.4
3.1.5
1
folioci/mod-oa:latestae3b069d4ba5
jackson-databind@2.18.7
2.18.9
1
folioci/mod-oai-pmh:latest5cd5ef063f2a
jackson-databind@2.18.2
2.18.9
1
folioci/mod-orders:latestfc4528220fb8
jackson-databind@3.1.4
3.1.5
1
folioci/mod-orders-storage:latestceeaacc3bf16
jackson-databind@3.1.4
3.1.5
1
folioci/mod-organizations:latest7dc9ccf3d937
jackson-databind@2.18.6
2.18.9
1
folioci/mod-organizations-storage:lateste46892405fde
jackson-databind@2.21.4
2.21.5
1
folioci/mod-password-validator:latestb31d75f2bf7b
jackson-databind@3.1.4
3.1.5
1
folioci/mod-patron:latest5f213acfe2f8
jackson-databind@2.18.2
2.18.9
1
folioci/mod-permissions:latest5363e98c6299
jackson-databind@2.18.6
2.18.9
1
folioci/mod-pubsub:latest0a4fa4ad5d72
jackson-databind@2.18.6
2.18.9
1
folioci/mod-remote-storage:latest4f12177123dc
jackson-databind@2.21.4
2.21.5
1
folioci/mod-rtac:latestc959b2d6142f
jackson-databind@2.18.2
2.18.9
1
folioci/mod-sender:latestd88a675dddf0
jackson-databind@2.18.2
2.18.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.