StackRadar

CVE-2026-59889

Medium

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
224
of 17,781 indexed, latest versions
Container images
224
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

Carried by container images the latest versions of 224 of 17,781 indexed charts deploy, on 224 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.18.0, 2.18.1, 2.18.2, 2.18.3+17 more2.18.9, 2.21.5, 2.22.1, 3.1.5+1 more224
OSV records
GHSA-5gvw-p9qm-jgwh

Charts affected

224 by stars
ChartLatestAffected imagesRadar Score
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-databind@2.18.3
2.18.9

Open the chart page →

1,951
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
jackson-databind@2.21.4
2.21.5

Open the chart page →

2,261
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jackson-databind@3.1.2
3.1.5

Open the chart page →

6,207
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jackson-databind@2.22.0
2.22.1

Open the chart page →

1,610
keycloakself-hosters-by-nightVerified publisher0.1.11 of 1See more

keycloak self-hosters-by-night 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-databind@2.21.2
2.21.5

Open the chart page →

518
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.5

Open the chart page →

5,201
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.9

Open the chart page →

1,690
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
jackson-databind@3.1.1
3.1.5

Open the chart page →

3,003
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,702
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
jackson-databind@2.18.3
2.18.9

Open the chart page →

3,153
tekton-ci-environment-injectortekton-ci-environment-injectorVerified publisher0.2.41 of 1See more

tekton-ci-environment-injector tekton-ci-environment-injector 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
jackson-databind@2.21.4
2.21.5

Open the chart page →

510
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
jackson-databind@2.21.4
2.21.5

Open the chart page →

1,082
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jackson-databind@2.21.1
2.21.5

Open the chart page →

1,825
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

4,423
openunison-operatortremolo3.0.301 of 1See more

openunison-operator tremolo 3.0.30

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5

Open the chart page →

2,126
orchestratremolo3.1.552 of 5See more

orchestra tremolo 3.1.55

2 of the 5 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
jackson-databind@2.21.3
2.21.5
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5

Open the chart page →

7,637
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest0ad069035863
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,551
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
jackson-databind@2.18.2
2.18.9

Open the chart page →

5,484
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,639
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-databind@2.18.0
2.18.9

Open the chart page →

9,381
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
jackson-databind@2.18.0
2.18.9

Open the chart page →

1,571
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,159

Container images carrying it

224 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
folioci/mod-serials-management:latest571fa1ffe8c9
jackson-databind@2.18.7
2.18.9
1
folioci/mod-service-interaction:latestf53c327a48e8
jackson-databind@2.18.7
2.18.9
1
folioci/mod-tags:latest6e8beeb70272
jackson-databind@2.21.4
2.21.5
1
folioci/mod-template-engine:latestd105c585da30
jackson-databind@2.18.2
2.18.9
1
folioci/mod-user-import:latest1807734472bd
jackson-databind@2.18.6
2.18.9
1
folioci/mod-users:latest6f60033321b0
jackson-databind@2.21.4
2.21.5
1
folioci/mod-users-bl:latest4e2d96c9340d
jackson-databind@2.18.2
2.18.9
1
frankescobar/allure-docker-service:latestdc171ec796d5
jackson-databind@2.22.0
2.22.1
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
jackson-databind@2.21.0
2.21.5
1
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
jackson-databind@3.1.2
3.1.5
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
jackson-databind@2.21.0
2.21.5
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
jackson-databind@3.1.2
3.1.5
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
jackson-databind@2.21.0
2.21.5
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
jackson-databind@2.21.0
2.21.5
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
jackson-databind@3.1.2
3.1.5
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
jackson-databind@2.21.0
2.21.5
1
glarad/mc-service-registry:latest7b02b9e7f1ef
jackson-databind@2.21.4
2.21.5
1
gocd/gocd-server:v26.1.0720d1012b93f
jackson-databind@2.22.0
2.22.1
1
gotson/komga:1.22.0ba892ab3e082
jackson-databind@2.18.1
2.18.9
1
graviteeio/ae-engine:3.0.24140932887e0
jackson-databind@2.18.3
2.18.9
1
graviteeio/am-gateway:4.12.607b7f6dc267a
jackson-databind@2.21.3
2.21.5
1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
jackson-databind@2.21.3
2.21.5
1
graylog/graylog:7.1.9598bd41fefd5
jackson-databind@2.21.2
2.21.5
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
jackson-databind@2.21.2
2.21.5
1
gridgain/gridgain9:9.1.1895018390077b
jackson-databind@2.21.0
2.21.5
1
hazelcast/hazelcast:latestf086bf0ecb23
jackson-databind@2.21.2
2.21.5
1
hazelcast/hazelcast-enterprise:5.7.1cf244da155eb
jackson-databind@2.22.0
2.22.1
1
hazelcast/management-center:5.11.11fbb7814f2a1
jackson-databind@3.2.0
3.2.1
1
itzg/bungeecord:latest1c59f9631f3b
jackson-databind@3.1.3
3.1.5
1
itzg/minecraft-server:2026.9.04e29d14082d9
jackson-databind@3.1.3
3.1.5
1
itzg/minecraft-server:latest8672e335dbef
jackson-databind@3.1.3
3.1.5
1
keyfactor/signserver-ce:7.3.2798fbbe00283
jackson-databind@2.18.2
2.18.9
1
labs64/auditflowc7b26d3ca11c
jackson-databind@2.21.4
2.21.5
1
labs64/payment-gateway:0.0.10c66feefca17
jackson-databind@2.21.4
2.21.5
1
library/convertigo:8.4.3ae605bfcda05
jackson-databind@2.21.3
2.21.5
1
library/elasticsearch:9.5.19656a9ca03f8
jackson-databind@2.18.8
2.18.9
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
jackson-databind@2.21.3
2.21.5
1
library/neo4j:2026.05.06c162e2432f8
jackson-databind@2.21.3
2.21.5
1
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
jackson-databind@2.21.2
2.21.5
1
metabase/metabase:v0.53.4.17807bc5cad17
jackson-databind@2.18.0
2.18.9
1
nacos/nacos-server:v3.0.20e951a1d07bb
jackson-databind@2.18.3
2.18.9
1
nacos/nacos-server:v3.0.130a39cb0c54d
jackson-databind@2.18.3
2.18.9
1
openhab/openhab:5.2.1bfd4a60e90da
jackson-databind@2.21.4
2.21.5
1
opennms/sentinel:36.0.288869082a14f
jackson-databind@2.21.3
2.21.5
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
jackson-databind@2.18.2
2.18.9
1
opensearchproject/opensearch:2.19.269588c664014
jackson-databind@2.18.2
2.18.9
1
opensearchproject/opensearch:3.3.2798cf28e226a
jackson-databind@2.18.2
2.18.9
1
opensearchproject/opensearch:2.19.68690b204fe91
jackson-databind@2.18.8
2.18.9
1
openzipkin/zipkin-slim:3.6.0a69e1057df36
jackson-databind@2.21.2
2.21.5
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
jackson-databind@2.18.3
2.18.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.