StackRadar

CVE-2026-59889

Medium

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
224
of 17,781 indexed, latest versions
Container images
224
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

Carried by container images the latest versions of 224 of 17,781 indexed charts deploy, on 224 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.18.0, 2.18.1, 2.18.2, 2.18.3+17 more2.18.9, 2.21.5, 2.22.1, 3.1.5+1 more224
OSV records
GHSA-5gvw-p9qm-jgwh

Charts affected

224 by stars
ChartLatestAffected imagesRadar Score
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-databind@2.18.3
2.18.9

Open the chart page →

1,951
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
jackson-databind@2.21.4
2.21.5

Open the chart page →

2,261
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jackson-databind@3.1.2
3.1.5

Open the chart page →

6,207
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jackson-databind@2.22.0
2.22.1

Open the chart page →

1,610
keycloakself-hosters-by-nightVerified publisher0.1.11 of 1See more

keycloak self-hosters-by-night 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-databind@2.21.2
2.21.5

Open the chart page →

518
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.5

Open the chart page →

5,201
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.9

Open the chart page →

1,690
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
jackson-databind@3.1.1
3.1.5

Open the chart page →

3,003
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,702
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
jackson-databind@2.18.3
2.18.9

Open the chart page →

3,153
tekton-ci-environment-injectortekton-ci-environment-injectorVerified publisher0.2.41 of 1See more

tekton-ci-environment-injector tekton-ci-environment-injector 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
jackson-databind@2.21.4
2.21.5

Open the chart page →

510
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
jackson-databind@2.21.4
2.21.5

Open the chart page →

1,082
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jackson-databind@2.21.1
2.21.5

Open the chart page →

1,825
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

4,423
openunison-operatortremolo3.0.301 of 1See more

openunison-operator tremolo 3.0.30

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5

Open the chart page →

2,126
orchestratremolo3.1.552 of 5See more

orchestra tremolo 3.1.55

2 of the 5 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
jackson-databind@2.21.3
2.21.5
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5

Open the chart page →

7,637
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest0ad069035863
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,551
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
jackson-databind@2.18.2
2.18.9

Open the chart page →

5,484
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,639
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-databind@2.18.0
2.18.9

Open the chart page →

9,381
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
jackson-databind@2.18.0
2.18.9

Open the chart page →

1,571
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,159

Container images carrying it

224 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kubelauncher/keycloakafe3bd73d7cf
jackson-databind@2.21.2
2.21.5
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
jackson-databind@2.18.2
2.18.9
1
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
jackson-databind@2.21.2
2.21.5
1
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
jackson-databind@2.21.2
2.21.5
1
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
jackson-databind@2.21.2
2.21.5
1
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
jackson-databind@2.21.3
2.21.5
1
ghcr.io/projectnessie/nessie:0.108.4c0f42874c810
jackson-databind@2.22.0
2.22.1
1
ghcr.io/quenchworks/images/jenkinse92dba4e78c5
jackson-databind@2.22.0
2.22.1
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jackson-databind@3.1.2
3.1.5
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
jackson-databind@2.21.2
2.21.5
1
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jackson-databind@2.22.0
2.22.1
1
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
jackson-databind@2.21.3
2.21.5
1
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
jackson-databind@2.21.4
2.21.5
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
jackson-databind@2.18.2
2.18.9
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
jackson-databind@2.22.0
2.22.1
1
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-databind@2.21.2
2.21.5
1
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.9
1
quay.io/keycloak/keycloak:26.6.39b0330756022
jackson-databind@2.21.2
2.21.5
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-databind@2.21.2
2.21.5
1
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
jackson-databind@2.21.4
2.21.5
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.5
1
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
jackson-databind@2.21.4
2.21.5
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
jackson-databind@2.21.4
2.21.5
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
jackson-databind@2.22.0
2.22.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.