StackRadar

CVE-2026-59889

Medium

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
224
of 17,781 indexed, latest versions
Container images
224
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

Carried by container images the latest versions of 224 of 17,781 indexed charts deploy, on 224 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.18.0, 2.18.1, 2.18.2, 2.18.3+17 more2.18.9, 2.21.5, 2.22.1, 3.1.5+1 more224
OSV records
GHSA-5gvw-p9qm-jgwh

Charts affected

224 by stars
ChartLatestAffected imagesRadar Score
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-databind@2.18.3
2.18.9

Open the chart page →

1,951
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
jackson-databind@2.21.4
2.21.5

Open the chart page →

2,261
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jackson-databind@3.1.2
3.1.5

Open the chart page →

6,207
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jackson-databind@2.22.0
2.22.1

Open the chart page →

1,610
keycloakself-hosters-by-nightVerified publisher0.1.11 of 1See more

keycloak self-hosters-by-night 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-databind@2.21.2
2.21.5

Open the chart page →

518
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.5

Open the chart page →

5,201
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.9

Open the chart page →

1,690
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
jackson-databind@3.1.1
3.1.5

Open the chart page →

3,003
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,702
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
jackson-databind@2.18.3
2.18.9

Open the chart page →

3,153
tekton-ci-environment-injectortekton-ci-environment-injectorVerified publisher0.2.41 of 1See more

tekton-ci-environment-injector tekton-ci-environment-injector 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
jackson-databind@2.21.4
2.21.5

Open the chart page →

510
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
jackson-databind@2.21.4
2.21.5

Open the chart page →

1,082
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jackson-databind@2.21.1
2.21.5

Open the chart page →

1,825
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

4,423
openunison-operatortremolo3.0.301 of 1See more

openunison-operator tremolo 3.0.30

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5

Open the chart page →

2,126
orchestratremolo3.1.552 of 5See more

orchestra tremolo 3.1.55

2 of the 5 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
jackson-databind@2.21.3
2.21.5
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5

Open the chart page →

7,637
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:latest0ad069035863
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,551
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
jackson-databind@2.18.2
2.18.9

Open the chart page →

5,484
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5

Open the chart page →

2,476
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,639
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-databind@2.18.0
2.18.9

Open the chart page →

9,381
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
jackson-databind@2.18.0
2.18.9

Open the chart page →

1,571
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,159

Container images carrying it

224 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5
13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.5
7
apache/fineract:1.12.1a83cf1980609
jackson-databind@2.18.3
2.18.9
2
apache/kafka:4.3.177e3df905404
jackson-databind@2.21.2
2.21.5
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
jackson-databind@2.18.3
2.18.9
2
gisaia/arlas-permissions-server:28.0.0e612fc722e02
jackson-databind@2.21.0
2.21.5
2
gisaia/arlas-persistence-server:28.0.0f667e0ee79be
jackson-databind@2.21.0
2.21.5
2
gisaia/arlas-server:28.0.04e693e7b6f37
jackson-databind@2.21.0
2.21.5
2
gotson/komga:1.26.36c2a967bbe9a
jackson-databind@2.21.4
2.21.5
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
jackson-databind@2.18.1
2.18.9
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
jackson-databind@3.1.1
3.1.5
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
jackson-databind@2.18.0
2.18.9
2
metabase/metabase:v0.61.1.x9491ed11c901
jackson-databind@2.21.2
2.21.5
2
nacos/nacos-server:latest1c191c30c8cd
jackson-databind@2.21.2
2.21.5
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-databind@2.18.0
2.18.9
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
jackson-databind@2.21.2
2.21.5
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
jackson-databind@2.21.2
2.21.5
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5
2
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
jackson-databind@2.21.2
2.21.5
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-databind@2.18.3
2.18.9
2
acryldata/datahub-frontend-react:v1.7.0.199513cc1c45e
jackson-databind@2.21.2
2.21.5
1
acryldata/datahub-upgrade:v1.7.0.1c3db54d8fb94
jackson-databind@2.21.2
2.21.5
1
adeptiainc/adeptia-connect-migration:4.8.1f1087da3da0b
jackson-databind@2.21.1
2.21.5
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
jackson-databind@2.18.4
2.18.9
1
alfio/alf.io:2.0-M5-26060c836a081446
jackson-databind@2.21.2
2.21.5
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
jackson-databind@2.18.2
2.18.9
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
jackson-databind@2.21.3
2.21.5
1
apache/hertzbeat:1.8.075d48a62748f
jackson-databind@2.18.2
2.18.9
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
jackson-databind@2.18.2
2.18.9
1
apache/polaris:lateste66366e783f1
jackson-databind@3.2.0
3.2.1
1
apache/tika:3.3.1.090b7fa1dc018
jackson-databind@2.21.3
2.21.5
1
atlassian/bitbucket:10.2.705933f2b1cfd
jackson-databind@2.18.2
2.18.9
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
jackson-databind@2.18.6
2.18.9
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
jackson-databind@2.18.2
2.18.9
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
jackson-databind@2.18.0
2.18.9
1
bluerange/bluerange:26.1.307c8f73b55df
jackson-databind@2.18.3
2.18.9
1
castlemock/castlemock:latestb7f3f1527ba9
jackson-databind@2.18.3
2.18.9
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
jackson-databind@2.18.0
2.18.9
1
confluentinc/cp-kafka:latest0ad069035863
jackson-databind@2.21.2
2.21.5
1
confluentinc/cp-schema-registry:latestf0cfd047a839
jackson-databind@2.21.2
2.21.5
1
consensys/teku:latest3a4f5761ae1c
jackson-databind@3.1.0
3.1.5
1
consensys/teku:25.4.1bf6ecd2ea716
jackson-databind@2.18.3
2.18.9
1
consensys/web3signer:latestf146a51a1ba3
jackson-databind@2.21.2
2.21.5
1
crushftp/crushftp11:latestae62db2d83b7
jackson-databind@2.21.4
2.21.5
1
crushftp/crushftp11:latest-devd9afab76df30
jackson-databind@2.21.4
2.21.5
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
jackson-databind@2.21.1
2.21.5
1
dependencytrack/apiserver:latestf1da63ed610a
jackson-databind@2.22.0
2.22.1
1
eginnovations/agent:7.5.4e4dfe242fe9f
jackson-databind@2.21.1
2.21.5
1
epamedp/edp-gerrit:3.14.249e8fe9c4855
jackson-databind@2.21.1
2.21.5
1
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
jackson-databind@2.18.0
2.18.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.