StackRadar

CVE-2026-68497

High

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
578
of 17,939 indexed, latest versions
Container images
606
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS

Carried by container images the latest versions of 578 of 17,939 indexed charts deploy, on 606 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.14.0, 2.14.1, 2.14.2, 2.14.3+46 more2.18.10, 2.21.6, 2.22.2, 3.1.6+1 more606
OSV records
GHSA-q4xh-88c3-wmh7
Trending
Rank 8 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

578 by stars
ChartLatestAffected imagesRadar Score
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-databind@2.15.2
2.18.10

Open the chart page →

4,192
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-databind@2.15.2
2.18.10

Open the chart page →

4,192
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
jackson-databind@2.16.2
2.18.10

Open the chart page →

3,416
yaadeencircle360-ossVerified publisher0.2.11 of 1See more

yaade encircle360-oss 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
esperotech/yaade:latest24d2d692d948
jackson-databind@2.15.3
2.18.10

Open the chart page →

1,095
eoloPlanteolo-plannerVerified publisher0.1.01 of 7See more

eoloPlant eolo-planner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

28,822
eoloplannereoloplannerVerified publisher0.1.01 of 7See more

eoloplanner eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

33,480
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.01 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

28,822
eoloplannereoloplanner-molynx-gat0.1.01 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

29,474
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

28,201
eoloplanteoloplant1.0.01 of 7See more

eoloplant eoloplant 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

28,822
eoloplantseoloplants-urjcVerified publisher0.1.01 of 7See more

eoloplants eoloplants-urjc 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

28,742
servereoloserverVerified publisher0.1.01 of 7See more

server eoloserver 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
jackson-databind@2.14.1
2.18.10

Open the chart page →

33,480
gerrit-operatorepmdedpVerified publisher2.25.01 of 2See more

gerrit-operator epmdedp 2.25.0

1 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
epamedp/edp-gerrit:3.14.249e8fe9c4855
jackson-databind@2.21.1
2.21.6

Open the chart page →

1,262
tekuethereum-helm-chartsVerified publisher1.2.11 of 2See more

teku ethereum-helm-charts 1.2.1

1 of the 2 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
consensys/teku:latest6bfef491dc27
jackson-databind@3.1.0
3.1.6

Open the chart page →

704
web3signerethereum-helm-chartsVerified publisher1.0.61 of 4See more

web3signer ethereum-helm-charts 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
consensys/web3signer:latestf146a51a1ba3
jackson-databind@2.21.2
2.21.6

Open the chart page →

2,116
eximeebpmseximeebpms-k8sOfficialVerified publisher0.4.01 of 1See more

eximeebpms eximeebpms-k8s 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.4.00f4a5c0eea07
jackson-databind@2.21.5
2.21.6

Open the chart page →

196
factor-platformfactorhouseVerified publisher0.0.51 of 1See more

factor-platform factorhouse 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
factorhouse/factor-platform:96.5b19f8edcb778
jackson-databind@3.2.0
3.2.2

Open the chart page →

51
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.6

Open the chart page →

2,688
fddb-exporterfddb-exporterVerified publisher2.4.31 of 1See more

fddb-exporter fddb-exporter 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
jackson-databind@2.22.1
2.22.2

Open the chart page →

559
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
jackson-databind@2.17.2
2.18.10
golenski/fibonacci-task-manager:2.0.03a2b36df247b
jackson-databind@2.17.2
2.18.10
golenski/fibonacci-worker:2.0.0954caf4aaf6a
jackson-databind@2.17.2
2.18.10

Open the chart page →

17,957
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
jackson-databind@2.18.3
2.18.10

Open the chart page →

7,650
consent-facadefiware0.1.11 of 1See more

consent-facade fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-databind@2.17.2
2.18.10

Open the chart page →

2,646
contract-managementfiware3.5.361 of 1See more

contract-management fiware 3.5.36

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/fiware/contract-management:3.3.122bcfcf874451
jackson-databind@2.17.2
2.18.10

Open the chart page →

2,579
credentials-config-servicefiware2.6.41 of 1See more

credentials-config-service fiware 2.6.4

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
jackson-databind@2.19.2
2.21.6

Open the chart page →

2,438
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.10

Open the chart page →

4,702
tm-forum-apifiware0.17.1719 of 19See more

tm-forum-api fiware 0.17.17

19 of the 19 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/fiware/tmforum-account:1.18.65a9893a6c684
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-agreement:1.18.630ec0a5a9622
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-customer-bill-management:1.18.6fff6d26c5ca3
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-customer-management:1.18.650a5fd555046
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-party-catalog:1.18.6d8c5558c94ae
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-party-role:1.18.6f42cfd885f91
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-product-catalog:1.18.6af6bbdf4e818
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-product-inventory:1.18.6f138402fbdf7
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-product-ordering-management:1.18.604c1c4e9f1da
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-quote:1.18.62b4acd86144a
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-resource-catalog:1.18.68576a60e2fa4
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-resource-function-activation:1.18.670a65c2088d3
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-resource-inventory:1.18.626167d4e4999
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-resource-order-management:1.18.67400974ae09f
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-service-catalog:1.18.614925066a9c5
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-service-inventory:1.18.6a8e66f6cfdb8
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-service-order-management:1.18.6e3d04942ba85
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-software-management:1.18.620954f098e76
jackson-databind@3.0.3
3.1.6
quay.io/fiware/tmforum-usage-management:1.18.6d5f1d688a742
jackson-databind@3.0.3
3.1.6

Open the chart page →

19,874
trusted-issuers-listfiware0.18.71 of 1See more

trusted-issuers-list fiware 0.18.7

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
jackson-databind@2.19.2
2.21.6

Open the chart page →

1,899
trusted-issuers-registryfiware0.13.01 of 1See more

trusted-issuers-registry fiware 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
jackson-databind@2.15.0
2.18.10

Open the chart page →

7,266
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
jackson-databind@2.14.0
2.18.10

Open the chart page →

24,403
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
jackson-databind@2.19.2
2.21.6

Open the chart page →

3,888
flyte-devboxflyte0.1.01 of 14See more

flyte-devbox flyte 0.1.0

1 of the 14 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
jackson-databind@2.19.2
2.21.6

Open the chart page →

8,624
keycloak-operatorfmjstudios0.1.21 of 1See more

keycloak-operator fmjstudios 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:26.0.68e3a1a56346f
jackson-databind@2.17.2
2.18.10

Open the chart page →

1,320
edge-caiasoftfolio-org0.1.321 of 1See more

edge-caiasoft folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-caiasoft:latestc3cfa89eee2f
jackson-databind@2.21.4
2.21.6

Open the chart page →

526
edge-connexionfolio-org0.1.51 of 1See more

edge-connexion folio-org 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-connexion:latestb4863d135524
jackson-databind@2.18.2
2.18.10

Open the chart page →

1,140
edge-dematicfolio-org0.1.331 of 1See more

edge-dematic folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-dematic:latest48c9b1d180d4
jackson-databind@3.1.4
3.1.6

Open the chart page →

526
edge-inn-reachfolio-org0.1.41 of 1See more

edge-inn-reach folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-inn-reach:latestc64e4d9dd3fc
jackson-databind@3.1.4
3.1.6

Open the chart page →

526
edge-ncipfolio-org0.1.281 of 1See more

edge-ncip folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-ncip:lateste760dbb81d1a
jackson-databind@2.18.2
2.18.10

Open the chart page →

825
edge-oai-pmhfolio-org0.1.311 of 1See more

edge-oai-pmh folio-org 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-oai-pmh:latesteedfcbc29792
jackson-databind@2.18.2
2.18.10

Open the chart page →

878
edge-ordersfolio-org0.1.301 of 1See more

edge-orders folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-orders:latest1ef654ee9f23
jackson-databind@2.18.6
2.18.10

Open the chart page →

740
edge-patronfolio-org0.1.281 of 1See more

edge-patron folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-patron:latest682b852e056d
jackson-databind@3.1.0
3.1.6

Open the chart page →

910
edge-rtacfolio-org0.1.281 of 1See more

edge-rtac folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-rtac:latest15ef73b1abd0
jackson-databind@3.0.4
3.1.6

Open the chart page →

1,265
edge-sip2folio-org0.1.281 of 1See more

edge-sip2 folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/edge-sip2:latest86106f20ef51
jackson-databind@2.21.4
2.21.6

Open the chart page →

254
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
jackson-databind@2.22.0
2.22.2

Open the chart page →

1,902
mod-auditfolio-org0.1.361 of 1See more

mod-audit folio-org 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/mod-audit:latest88f40730ed45
jackson-databind@3.1.4
3.1.6

Open the chart page →

267
mod-authtokenfolio-org0.1.351 of 1See more

mod-authtoken folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/mod-authtoken:latest995a25a33133
jackson-databind@2.16.1
2.18.10

Open the chart page →

1,567
mod-calendarfolio-org0.1.341 of 1See more

mod-calendar folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/mod-calendar:latest22f65982efd7
jackson-databind@3.1.4
3.1.6

Open the chart page →

416
mod-circulationfolio-org0.1.351 of 1See more

mod-circulation folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/mod-circulation:latest3eecd2ac2d8a
jackson-databind@2.18.6
2.18.10

Open the chart page →

500
mod-circulation-storagefolio-org0.1.351 of 1See more

mod-circulation-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/mod-circulation-storage:latest6bdddcafbc0f
jackson-databind@2.18.6
2.18.10

Open the chart page →

662
mod-configurationfolio-org0.1.341 of 1See more

mod-configuration folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/mod-configuration:latestdd0cdc89670a
jackson-databind@2.18.6
2.18.10

Open the chart page →

716
mod-copycatfolio-org0.1.31 of 1See more

mod-copycat folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-68497.

Container imageDigestPackageFixed in
folioci/mod-copycat:latest1513fad2b799
jackson-databind@2.18.6
2.18.10

Open the chart page →

1,474

Container images carrying it

606 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
jackson-databind@2.22.0
2.22.2
1
quay.io/streamshub/console-operator:0.11.0e40bbfeae125
jackson-databind@2.19.2
2.21.6
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.10
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.10
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.10
1
registry.gitlab.com/lenitech/docker/keycloak:26.7.4-0993dd8a5e1f8
jackson-databind@2.21.5
2.21.6
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.