StackRadar

CVE-2026-68494

High

Advisory

Published 21 Jul 2026In the index since 3 Oct 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
926
of 17,992 indexed, latest versions
Container images
913
deployed by those charts
Fix available
1 of 1
affected package

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

Carried by container images the latest versions of 926 of 17,992 indexed charts deploy, on 913 images.

Affected packageAffected versionsFixed inImages
jackson-coremaven2.0.5, 2.2.3, 2.3.0, 2.3.3+92 more2.18.8, 2.21.4, 3.1.4913
OSV records
GHSA-r7wm-3cxj-wff9

Charts affected

926 by stars
ChartLatestAffected imagesRadar Score
routr-connectroutr0.4.32 of 10See more

routr-connect routr 0.4.3

2 of the 10 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
fonoster/routr-edgeport:2.13.6d08a8a574a50
jackson-core@2.9.6
2.18.8
fonoster/routr-requester:2.13.6e0c823506eb2
jackson-core@2.9.6
2.18.8

Open the chart page →

12,136
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jackson-core@2.21.2
2.21.4

Open the chart page →

7,151
housekeepersaashousekeeper1.0.01 of 14See more

housekeeper saashousekeeper 1.0.0

1 of the 14 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
saashousekeeper/event-tracking:1.0.0d8786cea5bc4
jackson-core@2.13.2
2.18.8

Open the chart page →

4,707
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
jackson-core@2.12.2
2.18.8

Open the chart page →

4,086
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
jackson-core@2.13.3
2.18.8

Open the chart page →

18,729
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
jackson-core@2.13.3
2.18.8

Open the chart page →

8,537
helm-chart-examplesalaboy0.1.01 of 1See more

helm-chart-example salaboy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
jackson-core@2.11.1
2.18.8

Open the chart page →

3,296
pagessamanvithkaranth1.0.01 of 3See more

pages samanvithkaranth 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-core@2.11.0
2.18.8

Open the chart page →

21,120
pagessarubits-pages1.0.01 of 3See more

pages sarubits-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-core@2.11.0
2.18.8

Open the chart page →

21,120
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
jackson-core@2.15.2
2.18.8

Open the chart page →

1,732
keycloaksb-helm-charts0.3.01 of 2See more

keycloak sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-core@2.17.2
2.18.8

Open the chart page →

2,877
sponge-vanillaschichtelVerified publisher0.1.21 of 1See more

sponge-vanilla schichtel 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
ghcr.io/cubeengine/sponge:1.20.2-11.0.0-RC13755c85f2b82064
jackson-core@2.12.3
2.18.8

Open the chart page →

1,027
smartquerysearchhub0.1.01 of 1See more

smartquery searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
commerceexperts/smartquery-service:2.2.09e33ad89baf6
jackson-core@2.13.5
2.18.8

Open the chart page →

1,621
smartsuggestsearchhub0.1.01 of 1See more

smartsuggest searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
jackson-core@2.15.3
2.18.8

Open the chart page →

1,343
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
jackson-core@2.13.5
2.18.8

Open the chart page →

4,766
pagessekharpkube1.0.01 of 3See more

pages sekharpkube 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-core@2.11.0
2.18.8

Open the chart page →

21,120
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
jackson-core@2.9.9
2.18.8

Open the chart page →

8,172
keycloakself-hosters-by-nightVerified publisher0.1.11 of 1See more

keycloak self-hosters-by-night 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-core@2.21.2
2.21.4

Open the chart page →

689
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
jackson-core@2.9.10
2.18.8

Open the chart page →

12,043
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
jackson-core@2.17.0
2.18.8

Open the chart page →

5,884
shenyushenyu0.6.32 of 2See more

shenyu shenyu 0.6.3

2 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.5.1e2be712fc4f4
jackson-core@2.13.3
2.18.8
apache/shenyu-bootstrap:2.5.11bd5756f6273
jackson-core@2.13.3
2.18.8

Open the chart page →

9,092
shenyushenyu-helm-chart-test2.4.272 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

2 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
jackson-core@2.10.1
2.18.8
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
jackson-core@2.10.1
2.18.8

Open the chart page →

12,719
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-core@2.21.2
2.21.4

Open the chart page →

6,037
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-core@2.11.0
2.18.8

Open the chart page →

21,120
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
jackson-core@2.13.2
2.18.8

Open the chart page →

3,590
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-core@2.18.2
2.18.8

Open the chart page →

1,941
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
jackson-core@2.13.4
2.18.8

Open the chart page →

6,691
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
jackson-core@2.11.2
2.18.8

Open the chart page →

5,052
simple-apisimple-api0.1.11 of 2See more

simple-api simple-api 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
jkaninda/simple-api:latestce4122d4c789
jackson-core@2.15.4
2.18.8

Open the chart page →

1,848
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
jackson-core@2.13.3
2.18.8

Open the chart page →

6,230
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
jackson-core@2.9.10
2.18.8

Open the chart page →

7,026
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
jackson-core@2.3.0
2.18.8

Open the chart page →

6,940
hetzner-iroboslamdev0.0.51 of 1See more

hetzner-irobo slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
slamdev/hetzner-irobo:0.0.13ca20c184c55
jackson-core@2.12.5
2.18.8

Open the chart page →

3,835
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
jackson-core@3.1.1
3.1.4

Open the chart page →

3,727
stewardsoftwaremillVerified publisher0.1.121 of 1See more

steward softwaremill 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
fthomas/scala-steward:latesta8eb43927576
jackson-core@2.12.7
2.18.8

Open the chart page →

623
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
jackson-core@2.10.0
2.18.8

Open the chart page →

14,185
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
jackson-core@2.3.3
2.18.8

Open the chart page →

13,553
smtp-fake-serversomeblackmagic0.1.01 of 1See more

smtp-fake-server someblackmagic 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
someblackmagic/smtp-fake-server:latest0d63ba37a560
jackson-core@2.11.3
2.18.8

Open the chart page →

4,963
languagetoolsomeone-stole-my-nameVerified publisher0.1.91 of 1See more

languagetool someone-stole-my-name 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
ghcr.io/someone-stole-my-name/docker-languagetool:6.0d411e4365eef
jackson-core@2.13.4
2.18.8

Open the chart page →

1,645
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-core@2.16.2
2.18.8

Open the chart page →

2,112
spring-boot-helm-starterspring-boot-helm-starter0.1.01 of 1See more

spring-boot-helm-starter spring-boot-helm-starter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
alexandreroman/hello:latest4b79473442be
jackson-core@2.9.8
2.18.8

Open the chart page →

119,833
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-core@2.11.0
2.18.8

Open the chart page →

21,120
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jackson-core@2.10.1
2.18.8

Open the chart page →

3,238
retail-store-sample-cart-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-cart-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
jackson-core@2.19.2
2.21.4

Open the chart page →

1,218
retail-store-sample-orders-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-orders-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
jackson-core@2.19.2
2.21.4

Open the chart page →

1,406
retail-store-sample-ui-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-ui-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
jackson-core@2.19.2
2.21.4

Open the chart page →

995
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
jackson-core@2.9.9
2.18.8

Open the chart page →

6,134
cerebrostakaterVerified publisher0.5.11 of 2See more

cerebro stakater 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
lmenezes/cerebro:0.8.13e860068e403
jackson-core@2.8.11
2.18.8

Open the chart page →

2,991
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
jackson-core@2.21.2
2.21.4

Open the chart page →

1,880
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-68494.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-core@2.20.1
2.21.4

Open the chart page →

3,141

Container images carrying it

913 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
choerodon/event-store-service:0.8.03c94c97f6f69
jackson-core@2.8.8
2.18.8
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
jackson-core@2.18.0
2.18.8
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jackson-core@2.14.0
2.18.8
1
cnieg/gantt:1.1.2d4b478d76f2a
jackson-core@2.13.4
2.18.8
1
codetogether/codetogether:latest4348c8a38752
jackson-core@2.12.2
2.18.8
1
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
jackson-core@2.15.3
2.18.8
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
jackson-core@2.13.5
2.18.8
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jackson-core@2.10.5
2.18.8
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jackson-core@2.10.5
2.18.8
1
confluentinc/cp-kafka:5.4.01bbda887bc53
jackson-core@2.9.10
2.18.8
1
confluentinc/cp-kafka:7.6.024cdd3a7fa89
jackson-core@2.14.2
2.18.8
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
jackson-core@2.13.2
2.18.8
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
jackson-core@2.14.2
2.18.8
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
jackson-core@2.16.0
2.18.8
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
jackson-core@2.14.2
2.18.8
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
jackson-core@2.9.6
2.18.8
1
confluentinc/cp-kafka:7.5.1dc9b972db002
jackson-core@2.13.5
2.18.8
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jackson-core@2.10.5
2.18.8
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jackson-core@2.10.5
2.18.8
1
confluentinc/cp-ksqldb-cli:7.6.0118cec1c87e2
jackson-core@2.14.2
2.18.8
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
jackson-core@2.14.2
2.18.8
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jackson-core@2.10.5
2.18.8
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jackson-core@2.10.5
2.18.8
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
jackson-core@2.14.2
2.18.8
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
jackson-core@2.16.0
2.18.8
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
jackson-core@2.10.5
2.18.8
1
confluentinc/ksqldb-server:latest1a3266adff1a
jackson-core@2.13.4
2.18.8
1
consensys/teku:latest6bfef491dc27
jackson-core@3.1.0
3.1.4
1
consensys/teku:25.4.1bf6ecd2ea716
jackson-core@2.18.3
2.18.8
1
consensys/web3signer:latestf146a51a1ba3
jackson-core@2.21.2
2.21.4
1
craigwillis/c2metadata-bd:latestae317d7e4724
jackson-core@2.2.3
2.18.8
1
dannielkil/book-backend:lateste3b479a55a69
jackson-core@2.13.3
2.18.8
1
datappeal/hive-metastore:lateste38c085a3567
jackson-core@2.9.5
2.18.8
1
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
jackson-core@2.10.0
2.18.8
1
dbanda/livy:0.80ca125e68e53
jackson-core@2.4.0
2.18.8
1
dbanda/spark:2.4.6d0e6367876ae
jackson-core@2.7.8
2.18.8
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
jackson-core@2.15.2
2.18.8
1
dellcloud/category:distributed02fc234353a9
jackson-core@2.11.0
2.18.8
1
dellcloud/pages:1.04d2eb25b9225
jackson-core@2.11.4
2.18.8
1
deltaio/delta-sharing-server:0.2.08b75118187c5
jackson-core@2.4.0
2.18.8
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
jackson-core@2.21.1
2.21.4
1
dniel/api-posts:master45a667852f2a
jackson-core@2.10.0
2.18.8
1
dniel/forwardauth:latestf67129ea1c64
jackson-core@2.9.9
2.18.8
1
dremio/dremio-oss:24.1.080ed2e3b7c43
jackson-core@2.14.2
2.18.8
1
drpcorg/dshackle:0.54.08858fae1859d
jackson-core@2.14.2
2.18.8
1
duck1123/cert-downloader:latest0e29f19fa67c
jackson-core@2.13.3
2.18.8
1
duck1123/dinsro:latest9568c5961d5d
jackson-core@2.14.2
2.18.8
1
duck1123/lnd-fileserver:latest9d6fb247b714
jackson-core@2.13.3
2.18.8
1
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
jackson-core@2.14.1
2.18.8
1
easypi/openrefine:3.7.0d2950a36a576
jackson-core@2.13.4
2.18.8
1

syft 1.42.1 · advisories as of 4 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.