StackRadar

CVE-2026-68497

High

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
578
of 17,939 indexed, latest versions
Container images
606
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS

Carried by container images the latest versions of 578 of 17,939 indexed charts deploy, on 606 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.14.0, 2.14.1, 2.14.2, 2.14.3+46 more2.18.10, 2.21.6, 2.22.2, 3.1.6+1 more606
OSV records
GHSA-q4xh-88c3-wmh7
Trending
Rank 8 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

578 by stars
ChartLatestAffected imagesRadar Score
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.6.683dbca3efd2a
jackson-databind@2.14.2
2.18.10

Open the chart page →

17,558
querysiakhooiVerified publisher1.0.01 of 1See more

query siakhooi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
siakhooi/query:1.0.0f1f4b5b1b870
jackson-databind@3.1.0
3.1.6

Open the chart page →

1,941
signserver-cesignserverOfficialVerified publisher2.4.41 of 1See more

signserver-ce signserver 2.4.4

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.7.1f8d64caeaea9
jackson-databind@2.20.1
2.21.6

Open the chart page →

1,174
nexus-iq-server-hasonatypeVerified publisher207.1.01 of 2See more

nexus-iq-server-ha sonatype 207.1.0

1 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
sonatype/nexus-iq-server:1.207.1a70014ed10b1
jackson-databind@2.22.1
2.22.2

Open the chart page →

125
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
jackson-databind@2.19.2
2.21.6

Open the chart page →

1,587
stardogstardog3.1.01 of 3See more

stardog stardog 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
stardog/stardog:latest2714e5c4b3c1
jackson-databind@2.18.3
2.18.10

Open the chart page →

495
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
jackson-databind@2.21.2
2.21.6

Open the chart page →

3,034
strimzi-drain-cleanerstrimzi1.6.11 of 1See more

strimzi-drain-cleaner strimzi 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
jackson-databind@2.21.2
2.21.6

Open the chart page →

646
strimzi-drain-cleanerstrimzi-drain-cleaner1.6.11 of 1See more

strimzi-drain-cleaner strimzi-drain-cleaner 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
jackson-databind@2.21.2
2.21.6

Open the chart page →

646
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
mongodb/mongodb-atlas-local:8e118f5c131c5
jackson-databind@2.18.9
2.18.10

Open the chart page →

2,667
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
jackson-databind@2.15.2
2.18.10

Open the chart page →

9,355
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
jackson-databind@2.15.2
2.18.10

Open the chart page →

9,355
tocktock0.6.36 of 9See more

tock tock 0.6.3

6 of the 9 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
tock/bot_admin:25.10.7df3e38c77a38
jackson-databind@2.20.0
2.21.6
tock/bot_api:25.10.7dd5d5c70e333
jackson-databind@2.20.0
2.21.6
tock/build_worker:25.10.7080cb6b08d5b
jackson-databind@2.20.0
2.21.6
tock/duckling:25.10.7ac1f3f1a1e9c
jackson-databind@2.20.0
2.21.6
tock/kotlin_compiler:25.10.7c9c0fb40089a
jackson-databind@2.20.0
2.21.6
tock/nlp_api:25.10.7c04ffe67b977
jackson-databind@2.20.0
2.21.6

Open the chart page →

14,881
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
jackson-databind@2.15.2
2.18.10

Open the chart page →

59,873
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
jackson-databind@2.15.0
2.18.10

Open the chart page →

2,198
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
jackson-databind@2.15.0
2.18.10

Open the chart page →

2,359
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
jackson-databind@2.15.0
2.18.10

Open the chart page →

2,920
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
jackson-databind@2.15.0
2.18.10

Open the chart page →

2,252
quotes-provideraccount-serviceVerified publisher0.4.21 of 1See more

quotes-provider account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
jackson-databind@2.15.0
2.18.10

Open the chart page →

2,238
migrationadeptia-automate-migration5.2.91 of 1See more

migration adeptia-automate-migration 5.2.9

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
jackson-databind@2.19.4
2.21.6

Open the chart page →

549
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.6

Open the chart page →

2,688
keycloak-operatoradnoctemVerified publisher0.3.01 of 1See more

keycloak-operator adnoctem 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:26.7.33172bf49511c
jackson-databind@2.21.5
2.21.6

Open the chart page →

70
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
jackson-databind@2.17.0
2.18.10

Open the chart page →

932
connector-rollout-workerairbyteVerified publisher1.9.21 of 1See more

connector-rollout-worker airbyte 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
jackson-databind@2.20.1
2.21.6

Open the chart page →

931
airbyteairbyte-v2Verified publisher2.3.06 of 10See more

airbyte airbyte-v2 2.3.0

6 of the 10 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
airbyte/bootloader:2.3.0205b99d17c1a
jackson-databind@2.21.5
2.21.6
airbyte/cron:2.3.0bf4835757eaa
jackson-databind@2.21.5
2.21.6
airbyte/server:2.3.039141ed8ce5e
jackson-databind@2.21.5
2.21.6
airbyte/worker:2.3.0f2e33fbc53d1
jackson-databind@2.21.5
2.21.6
airbyte/workload-api-server:2.3.0434b4a811156
jackson-databind@2.21.5
2.21.6
airbyte/workload-launcher:2.3.00e18b1abcda6
jackson-databind@2.21.5
2.21.6

Open the chart page →

13,002
airbyte-data-planeairbyte-v2Verified publisher2.3.01 of 1See more

airbyte-data-plane airbyte-v2 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
airbyte/workload-launcher:2.3.00e18b1abcda6
jackson-databind@2.21.5
2.21.6

Open the chart page →

769
airports-apiairports-api0.1.01 of 1See more

airports-api airports-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
jackson-databind@2.14.2
2.18.10

Open the chart page →

2,002
airports-consumerairports-consumer0.1.01 of 1See more

airports-consumer airports-consumer 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
dina1993/airports-consumer:latest669d146a5e63
jackson-databind@2.14.2
2.18.10

Open the chart page →

1,991
airports-producerairports-producer0.1.01 of 1See more

airports-producer airports-producer 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
dina1993/airports-producer:latest3d6b0dac1cb4
jackson-databind@2.14.2
2.18.10

Open the chart page →

1,991
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4e9272f1fb326
jackson-databind@2.17.2
2.18.10

Open the chart page →

1,999
aktoakto0.2.05 of 7See more

akto akto 0.2.0

5 of the 7 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
jackson-databind@2.14.2
2.18.10
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
jackson-databind@2.14.2
2.18.10
public.ecr.aws/aktosecurity/akto-api-security-dashboard:latestb53a854bd7c1
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestfacdfba6d4e4
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
jackson-databind@2.18.9
2.18.10

Open the chart page →

14,519
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
jackson-databind@2.16.1
2.18.10

Open the chart page →

49,091
akto-central-setupakto1.2.14 of 5See more

akto-central-setup akto 1.2.1

4 of the 5 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:1.18.00d407ce850a3
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.7fd278c2d8647
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.70.0ac89679314c1
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
jackson-databind@2.21.2
2.21.6

Open the chart page →

4,179
akto-dashboardakto0.1.71 of 1See more

akto-dashboard akto 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
aktosecurity/akto-api-security-dashboard:latest3ecdd301cdbd
jackson-databind@2.18.9
2.18.10

Open the chart page →

926
akto-dbabsakto0.1.91 of 1See more

akto-dbabs akto 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestac89679314c1
jackson-databind@2.18.9
2.18.10

Open the chart page →

889
akto-hybrid-redactakto1.44.73 of 5See more

akto-hybrid-redact akto 1.44.7

3 of the 5 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.6_local8b9208c09d76
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
jackson-databind@2.19.0
2.21.6

Open the chart page →

5,178
akto-mini-runtimeakto0.7.222 of 3See more

akto-mini-runtime akto 0.7.22

2 of the 3 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8b9208c09d76
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.6

Open the chart page →

2,913
akto-mini-runtime-shaakto0.7.232 of 3See more

akto-mini-runtime-sha akto 0.7.23

2 of the 3 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtimedigest-pinned4d3a8042c761
jackson-databind@2.16.1
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
jackson-databind@2.19.0
2.21.6

Open the chart page →

3,600
akto-mini-testingakto1.45.72 of 5See more

akto-mini-testing akto 1.45.7

2 of the 5 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.6

Open the chart page →

6,930
akto-mini-testing-kafkaakto1.42.13 of 5See more

akto-mini-testing-kafka akto 1.42.1

3 of the 5 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
jackson-databind@2.16.2
2.18.10
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
jackson-databind@2.16.2
2.18.10
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:improve-testing-performance8e9d15ed71c7
jackson-databind@2.16.1
2.18.10

Open the chart page →

6,903
akto-mrs-runtime-combinedakto0.0.22 of 2See more

akto-mrs-runtime-combined akto 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.54.4_localb2b97137aef5
jackson-databind@2.16.1
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
jackson-databind@2.19.0
2.21.6

Open the chart page →

2,055
akto-protectionakto0.1.03 of 4See more

akto-protection akto 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
aktosecurity/akto-api-protection:localbcd7382c9c1b
jackson-databind@2.16.1
2.18.10
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
jackson-databind@2.14.2
2.18.10
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
jackson-databind@2.14.2
2.18.10

Open the chart page →

11,839
akto-regional-setupakto1.4.24 of 9See more

akto-regional-setup akto 1.4.2

4 of the 9 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
jackson-databind@2.18.9
2.18.10
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
jackson-databind@2.21.2
2.21.6

Open the chart page →

47,087
akto-runtimeakto0.1.82 of 2See more

akto-runtime akto 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8b9208c09d76
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.6

Open the chart page →

1,508
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
jackson-databind@2.16.1
2.18.10

Open the chart page →

5,078
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
jackson-databind@2.18.9
2.18.10

Open the chart page →

41,179
akto-threat-backendakto0.1.52 of 2See more

akto-threat-backend akto 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:latestdffb8c3676ef
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.6

Open the chart page →

1,547
akto-threat-clientakto0.2.02 of 2See more

akto-threat-client akto 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latesta728eb2eaf06
jackson-databind@2.18.9
2.18.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.6

Open the chart page →

1,578
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
jackson-databind@2.16.1
2.18.10

Open the chart page →

64,242
zunivers-ninjaalexpressoVerified publisher1.31.21 of 2See more

zunivers-ninja alexpresso 1.31.2

1 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
library/neo4j:5.18.18f01f7bb053e
jackson-databind@2.16.1
2.18.10

Open the chart page →

1,265

Container images carrying it

606 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
jackson-databind@2.22.0
2.22.2
1
quay.io/streamshub/console-operator:0.11.0e40bbfeae125
jackson-databind@2.19.2
2.21.6
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.10
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.10
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.10
1
registry.gitlab.com/lenitech/docker/keycloak:26.7.4-0993dd8a5e1f8
jackson-databind@2.21.5
2.21.6
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.