StackRadar

CVE-2026-59889

Medium

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
224
of 17,781 indexed, latest versions
Container images
224
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

Carried by container images the latest versions of 224 of 17,781 indexed charts deploy, on 224 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.18.0, 2.18.1, 2.18.2, 2.18.3+17 more2.18.9, 2.21.5, 2.22.1, 3.1.5+1 more224
OSV records
GHSA-5gvw-p9qm-jgwh

Charts affected

224 by stars
ChartLatestAffected imagesRadar Score
kafkahelmforgeVerified publisher1.3.141 of 1See more

kafka helmforge 1.3.14

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
apache/kafka:4.3.177e3df905404
jackson-databind@2.21.2
2.21.5

Open the chart page →

549
iceberg-resticeberg-rest-fixture0.0.11 of 2See more

iceberg-rest iceberg-rest-fixture 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
jackson-databind@2.18.4
2.18.9

Open the chart page →

3,470
traccarjeffrescVerified publisher0.2.01 of 2See more

traccar jeffresc 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
traccar/traccar:6.7-alpine621c8d6d46fd
jackson-databind@2.18.2
2.18.9

Open the chart page →

1,341
chronoreaperjfwenischVerified publisher1.1.101 of 1See more

chronoreaper jfwenisch 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
jackson-databind@2.21.3
2.21.5

Open the chart page →

1,021
ipfix-generatorjfwenischVerified publisher0.3.16-feature-helm-package.01 of 1See more

ipfix-generator jfwenisch 0.3.16-feature-helm-package.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
jackson-databind@2.21.2
2.21.5

Open the chart page →

697
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
jackson-databind@2.18.2
2.18.9

Open the chart page →

12,019
auditflowlabs64io-helm-chartsVerified publisher0.12.11 of 3See more

auditflow labs64io-helm-charts 0.12.1

1 of the 3 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
jackson-databind@2.21.4
2.21.5

Open the chart page →

1,446
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.01 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
jackson-databind@2.21.4
2.21.5

Open the chart page →

2,657
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
glarad/mc-service-registry:latest7b02b9e7f1ef
jackson-databind@2.21.4
2.21.5

Open the chart page →

6,929
openccuopenccuVerified publisher3.89.81 of 1See more

openccu openccu 3.89.8

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
jackson-databind@2.18.2
2.18.9

Open the chart page →

1,916
opentelemetry-demoopentelemetry-helmVerified publisher0.41.13 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

3 of the 34 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
jackson-databind@2.21.2
2.21.5
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
jackson-databind@2.21.2
2.21.5
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
jackson-databind@2.21.2
2.21.5

Open the chart page →

22,420
opikopikOfficialVerified publisher2.2.591 of 13See more

opik opik 2.2.59

1 of the 13 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/comet-ml/opik/opik-backend:2.2.5950a7aa0562f5
jackson-databind@2.21.4
2.21.5

Open the chart page →

14,334
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
reportportalreportportal-ioOfficialVerified publisher26.8.122 of 15See more

reportportal reportportal-io 26.8.12

2 of the 15 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
reportportal/service-api:5.15.4bf193091525a
jackson-databind@2.21.2
2.21.5
reportportal/service-authorization:5.15.16a954407b417
jackson-databind@2.21.4
2.21.5

Open the chart page →

11,869
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
jackson-databind@2.18.2
2.18.9

Open the chart page →

7,432
querysiakhooiVerified publisher1.0.01 of 1See more

query siakhooi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
siakhooi/query:1.0.0f1f4b5b1b870
jackson-databind@3.1.0
3.1.5

Open the chart page →

1,792
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
jackson-databind@2.18.2
2.18.9

Open the chart page →

2,406
stardogstardog3.1.01 of 3See more

stardog stardog 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
stardog/stardog:latest2714e5c4b3c1
jackson-databind@2.18.3
2.18.9

Open the chart page →

293
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
jackson-databind@2.21.2
2.21.5

Open the chart page →

2,826
strimzi-drain-cleanerstrimzi1.6.11 of 1See more

strimzi-drain-cleaner strimzi 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
jackson-databind@2.21.2
2.21.5

Open the chart page →

502
strimzi-drain-cleanerstrimzi-drain-cleaner1.6.11 of 1See more

strimzi-drain-cleaner strimzi-drain-cleaner 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
jackson-databind@2.21.2
2.21.5

Open the chart page →

502
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
akto-central-setupakto1.1.101 of 5See more

akto-central-setup akto 1.1.10

1 of the 5 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
jackson-databind@2.21.2
2.21.5

Open the chart page →

4,905
akto-mini-runtimeakto0.7.221 of 3See more

akto-mini-runtime akto 0.7.22

1 of the 3 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.5

Open the chart page →

2,741
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.5

Open the chart page →

6,486
akto-regional-setupakto1.3.11 of 9See more

akto-regional-setup akto 1.3.1

1 of the 9 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
jackson-databind@2.21.2
2.21.5

Open the chart page →

7,603
akto-runtimeakto0.1.81 of 2See more

akto-runtime akto 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,411
akto-threat-backendakto0.1.51 of 2See more

akto-threat-backend akto 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,490
akto-threat-clientakto0.2.01 of 2See more

akto-threat-client akto 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,523
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:latestdc171ec796d5
jackson-databind@2.22.0
2.22.1

Open the chart page →

3,647
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
jackson-databind@2.22.0
2.22.1

Open the chart page →

2,902
kafka-uiappscodeVerified publisher2026.3.301 of 1See more

kafka-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
jackson-databind@2.21.2
2.21.5

Open the chart page →

729
arlas-aiasarlas-stackVerified publisher28.8.04 of 22See more

arlas-aias arlas-stack 28.8.0

4 of the 22 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
jackson-databind@2.18.2
2.18.9
gisaia/arlas-permissions-server:28.0.0e612fc722e02
jackson-databind@2.21.0
2.21.5
gisaia/arlas-persistence-server:28.0.0f667e0ee79be
jackson-databind@2.21.0
2.21.5
gisaia/arlas-server:28.0.04e693e7b6f37
jackson-databind@2.21.0
2.21.5

Open the chart page →

40,238
arlas-servicesarlas-stackVerified publisher28.8.03 of 3See more

arlas-services arlas-stack 28.8.0

3 of the 3 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
gisaia/arlas-permissions-server:28.0.0e612fc722e02
jackson-databind@2.21.0
2.21.5
gisaia/arlas-persistence-server:28.0.0f667e0ee79be
jackson-databind@2.21.0
2.21.5
gisaia/arlas-server:28.0.04e693e7b6f37
jackson-databind@2.21.0
2.21.5

Open the chart page →

1,534
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
jackson-databind@2.18.3
2.18.9

Open the chart page →

1,816
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
jackson-databind@2.18.2
2.18.9

Open the chart page →

26,996
casepack-apibysamioVerified publisher0.31.01 of 1See more

casepack-api bysamio 0.31.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/bysamio/casepack-api:0.31.00eb3ad229c2c
jackson-databind@2.21.4
2.21.5

Open the chart page →

339
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
jackson-databind@2.22.0
2.22.1

Open the chart page →

1,423
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
jackson-databind@2.18.0
2.18.9

Open the chart page →

7,168
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
jackson-databind@2.18.0
2.18.9

Open the chart page →

5,238
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
jackson-databind@2.18.3
2.18.9

Open the chart page →

4,578
custom-rhcl-consolecustom-rhcl-consoleVerified publisher0.1.21 of 3See more

custom-rhcl-console custom-rhcl-console 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,885
kafka-connectdasmeta1.0.21 of 3See more

kafka-connect dasmeta 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
confluentinc/cp-schema-registry:latestf0cfd047a839
jackson-databind@2.21.2
2.21.5

Open the chart page →

532
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
jackson-databind@2.18.2
2.18.9

Open the chart page →

1,269
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.6.39b0330756022
jackson-databind@2.21.2
2.21.5

Open the chart page →

4,586
gerrit-operatorepmdedpVerified publisher2.25.01 of 2See more

gerrit-operator epmdedp 2.25.0

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
epamedp/edp-gerrit:3.14.249e8fe9c4855
jackson-databind@2.21.1
2.21.5

Open the chart page →

1,159
tekuethereum-helm-chartsVerified publisher1.2.11 of 2See more

teku ethereum-helm-charts 1.2.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
consensys/teku:latest3a4f5761ae1c
jackson-databind@3.1.0
3.1.5

Open the chart page →

973
web3signerethereum-helm-chartsVerified publisher1.0.61 of 4See more

web3signer ethereum-helm-charts 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
consensys/web3signer:latestf146a51a1ba3
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,997
eximeebpmseximeebpms-k8sOfficialVerified publisher0.3.01 of 1See more

eximeebpms eximeebpms-k8s 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.3.0acb8dbce38fd
jackson-databind@3.0.4
3.1.5

Open the chart page →

727
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476

Container images carrying it

224 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kubelauncher/keycloakafe3bd73d7cf
jackson-databind@2.21.2
2.21.5
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
jackson-databind@2.18.2
2.18.9
1
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
jackson-databind@2.21.2
2.21.5
1
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
jackson-databind@2.21.2
2.21.5
1
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
jackson-databind@2.21.2
2.21.5
1
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
jackson-databind@2.21.3
2.21.5
1
ghcr.io/projectnessie/nessie:0.108.4c0f42874c810
jackson-databind@2.22.0
2.22.1
1
ghcr.io/quenchworks/images/jenkinse92dba4e78c5
jackson-databind@2.22.0
2.22.1
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jackson-databind@3.1.2
3.1.5
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
jackson-databind@2.21.2
2.21.5
1
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jackson-databind@2.22.0
2.22.1
1
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
jackson-databind@2.21.3
2.21.5
1
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
jackson-databind@2.21.4
2.21.5
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
jackson-databind@2.18.2
2.18.9
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
jackson-databind@2.22.0
2.22.1
1
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-databind@2.21.2
2.21.5
1
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.9
1
quay.io/keycloak/keycloak:26.6.39b0330756022
jackson-databind@2.21.2
2.21.5
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-databind@2.21.2
2.21.5
1
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
jackson-databind@2.21.4
2.21.5
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.5
1
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
jackson-databind@2.21.4
2.21.5
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
jackson-databind@2.21.4
2.21.5
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
jackson-databind@2.22.0
2.22.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.