StackRadar

CVE-2026-89407

High

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
464
of 17,985 indexed, latest versions
Container images
493
deployed by those charts
Fix available
1 of 1
affected package

jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()

Carried by container images the latest versions of 464 of 17,985 indexed charts deploy, on 493 images.

Affected packageAffected versionsFixed inImages
jackson-coremaven2.17.0, 2.17.1, 2.17.2, 2.17.3+37 more2.18.11, 2.21.7, 2.22.3, 3.1.7+1 more493
OSV records
GHSA-p6pp-m3f8-5c89

Charts affected

464 by stars
ChartLatestAffected imagesRadar Score
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
jackson-core@2.19.0
2.21.7

Open the chart page →

3,779
akto-mini-testingakto1.45.72 of 5See more

akto-mini-testing akto 1.45.7

2 of the 5 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
jackson-core@2.18.9
2.18.11
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-core@2.21.2
2.21.7

Open the chart page →

7,598
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
jackson-core@2.19.0
2.21.7

Open the chart page →

2,185
akto-regional-setupakto1.4.34 of 9See more

akto-regional-setup akto 1.4.3

4 of the 9 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
jackson-core@2.18.9
2.18.11
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
jackson-core@2.18.9
2.18.11
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
jackson-core@2.18.9
2.18.11
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
jackson-core@2.21.2
2.21.7

Open the chart page →

47,593
akto-runtimeakto0.1.82 of 2See more

akto-runtime akto 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8b9208c09d76
jackson-core@2.18.9
2.18.11
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-core@2.21.2
2.21.7

Open the chart page →

1,762
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
jackson-core@2.18.9
2.18.11

Open the chart page →

40,374
akto-threat-backendakto0.1.52 of 2See more

akto-threat-backend akto 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:latestdffb8c3676ef
jackson-core@2.18.9
2.18.11
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-core@2.21.2
2.21.7

Open the chart page →

1,801
akto-threat-clientakto0.2.02 of 2See more

akto-threat-client akto 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latesta728eb2eaf06
jackson-core@2.18.9
2.18.11
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
jackson-core@2.21.2
2.21.7

Open the chart page →

1,832
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:latestdc171ec796d5
jackson-core@2.22.0
2.22.3

Open the chart page →

4,138
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
jackson-core@2.22.0
2.22.3

Open the chart page →

3,170
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
jackson-core@2.19.1
2.21.7

Open the chart page →

4,475
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:latest536358d7b17e
jackson-core@2.19.1
2.21.7

Open the chart page →

17,093
kafka-uiappscodeVerified publisher2026.3.301 of 1See more

kafka-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
jackson-core@2.21.2
2.21.7

Open the chart page →

879
arlas-aiasarlas-stackVerified publisher28.9.05 of 22See more

arlas-aias arlas-stack 28.9.0

5 of the 22 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
jackson-core@2.17.2
2.18.11
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
jackson-core@2.18.2
2.18.11
gisaia/arlas-permissions-server:28.0.0e612fc722e02
jackson-core@2.21.1
2.21.7
gisaia/arlas-persistence-server:28.0.0f667e0ee79be
jackson-core@2.19.2
2.21.7
gisaia/arlas-server:28.0.04e693e7b6f37
jackson-core@2.21.1
2.21.7

Open the chart page →

44,024
arlas-servicesarlas-stackVerified publisher28.9.03 of 3See more

arlas-services arlas-stack 28.9.0

3 of the 3 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
gisaia/arlas-permissions-server:28.0.0e612fc722e02
jackson-core@2.21.1
2.21.7
gisaia/arlas-persistence-server:28.0.0f667e0ee79be
jackson-core@2.19.2
2.21.7
gisaia/arlas-server:28.0.04e693e7b6f37
jackson-core@2.21.1
2.21.7

Open the chart page →

2,052
blackduck-alertblackduck8.4.11 of 4See more

blackduck-alert blackduck 8.4.1

1 of the 4 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.1b66c8385ba53
jackson-core@2.17.3
2.18.11

Open the chart page →

1,664
bluerange-serverbluerangeOfficialVerified publisher1.4.01 of 1See more

bluerange-server bluerange 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
bluerange/bluerange:26.2.0503577ef9143
jackson-core@2.18.3
2.18.11

Open the chart page →

1,956
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
jackson-core@2.18.2
2.18.11

Open the chart page →

29,757
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
jackson-core@2.17.0
2.18.11

Open the chart page →

8,740
casepack-apibysamioVerified publisher0.32.01 of 1See more

casepack-api bysamio 0.32.0

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
ghcr.io/bysamio/casepack-api:0.32.067aa72b00d0a
jackson-core@2.21.4
2.21.7

Open the chart page →

145
keycloakbysamioVerified publisher1.4.11 of 2See more

keycloak bysamio 1.4.1

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
ghcr.io/bysamio/keycloak:26.7.48360a1f317b8
jackson-core@2.21.5
2.21.7

Open the chart page →

155
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
apache/kafka:4.1.0bff074a5d005
jackson-core@2.19.0
2.21.7

Open the chart page →

2,597
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
jackson-core@2.19.4
2.21.7

Open the chart page →

8,564
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
jackson-core@2.17.1
2.18.11

Open the chart page →

1,333
metabasecasemark2.16.111 of 1See more

metabase casemark 2.16.11

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
jackson-core@2.17.0
2.18.11

Open the chart page →

1,310
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
jackson-core@2.22.0
2.22.3

Open the chart page →

1,634
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
jackson-core@2.18.0
2.18.11

Open the chart page →

7,799
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
jackson-core@2.18.0
2.18.11

Open the chart page →

7,572
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
jackson-core@2.18.3
2.18.11

Open the chart page →

5,010
opencloudcommunity-opencloud3.1.01 of 13See more

opencloud community-opencloud 3.1.0

1 of the 13 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
apache/tika:latest-full80072bb73dd3
jackson-core@2.22.1
2.22.3

Open the chart page →

10,377
custom-rhcl-consolecustom-rhcl-consoleVerified publisher0.1.21 of 3See more

custom-rhcl-console custom-rhcl-console 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
jackson-core@2.21.2
2.21.7

Open the chart page →

2,160
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
jackson-core@2.17.0
2.18.11

Open the chart page →

5,917
damap-chartdamapVerified publisher0.3.12 of 5See more

damap-chart damap 0.3.1

2 of the 5 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
ghcr.io/damap-org/damap-backend:5.0.10d5166b01eec
jackson-core@2.17.1
2.18.11
quay.io/keycloak/keycloak:26.545ae20191531
jackson-core@2.21.2
2.21.7

Open the chart page →

15,957
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
jackson-core@2.19.2
2.21.7

Open the chart page →

3,627
kafka-connectdasmeta1.0.21 of 3See more

kafka-connect dasmeta 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
confluentinc/cp-schema-registry:latest482d3048b3f6
jackson-core@2.22.1
2.22.3

Open the chart page →

336
metabasedasmeta0.1.01 of 1See more

metabase dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
metabase/metabase:v0.63.1.124f150effd484
jackson-core@2.21.5
2.21.7

Open the chart page →

942
datagrokdatagrok1.0.31 of 7See more

datagrok datagrok 1.0.3

1 of the 7 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
datagrok/grok_connect:latestf5876d3aebb8
jackson-core@2.21.5
2.21.7

Open the chart page →

2,669
datagrok_grok_connectdatagrok1.0.01 of 1See more

datagrok_grok_connect datagrok 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
datagrok/grok_connect:latestf5876d3aebb8
jackson-core@2.21.5
2.21.7

Open the chart page →

1,952
db2restdb2rest0.2.01 of 1See more

db2rest db2rest 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
kdhrubo/db2rest:lateste20610ff81b0
jackson-core@2.19.2
2.21.7

Open the chart page →

1,046
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
jackson-core@2.20.0
2.21.7

Open the chart page →

12,549
dial-admindialVerified publisher0.19.01 of 3See more

dial-admin dial 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
epam/ai-dial-admin-backend:0.21.08b91130e3731
jackson-core@2.22.1
2.22.3

Open the chart page →

4,062
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
jackson-core@2.18.2
2.18.11

Open the chart page →

1,441
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.6.39b0330756022
jackson-core@2.21.2
2.21.7

Open the chart page →

5,039
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
jackson-core@2.17.3
2.18.11

Open the chart page →

7,957
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
jackson-core@2.17.2
2.18.11

Open the chart page →

3,622
gerrit-operatorepmdedpVerified publisher2.25.01 of 2See more

gerrit-operator epmdedp 2.25.0

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
epamedp/edp-gerrit:3.14.249e8fe9c4855
jackson-core@2.21.1
2.21.7

Open the chart page →

1,346
tekuethereum-helm-chartsVerified publisher1.2.11 of 2See more

teku ethereum-helm-charts 1.2.1

1 of the 2 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
consensys/teku:latest6bfef491dc27
jackson-core@2.22.1
2.22.3

Open the chart page →

822
web3signerethereum-helm-chartsVerified publisher1.0.61 of 4See more

web3signer ethereum-helm-charts 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
consensys/web3signer:latestf146a51a1ba3
jackson-core@2.21.2
2.21.7

Open the chart page →

2,278
eximeebpmseximeebpms-k8sOfficialVerified publisher0.4.01 of 1See more

eximeebpms eximeebpms-k8s 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.4.00f4a5c0eea07
jackson-core@2.22.2
2.22.3

Open the chart page →

257
factor-platformfactorhouseVerified publisher0.0.51 of 1See more

factor-platform factorhouse 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-89407.

Container imageDigestPackageFixed in
factorhouse/factor-platform:96.5b19f8edcb778
jackson-core@2.22.2
2.22.3

Open the chart page →

103

Container images carrying it

493 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/quenchworks/images/trino9b3f2f1d90ac
jackson-core@2.22.1
2.22.3
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
jackson-core@2.19.0
2.21.7
2
quay.io/keycloak/keycloak:26.1.4044a457e0498
jackson-core@2.17.2
2.18.11
2
quay.io/keycloak/keycloak-operator:26.7.33172bf49511c
jackson-core@2.21.5
2.21.7
2
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
jackson-core@2.21.2
2.21.7
2
quay.io/strimzi/operator:1.2.077f8fa8121a6
jackson-core@3.1.5
3.1.7
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-core@2.18.3
2.18.11
2
2martens/configserver:latestbf1cdb80239d
jackson-core@2.17.2
2.18.11
1
2martens/timetable:latestbd1ba6ab84c9
jackson-core@2.19.2
2.21.7
1
2martens/wahlrecht:latestba2c3040dab0
jackson-core@2.19.2
2.21.7
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
jackson-core@2.19.4
2.21.7
1
acryldata/datahub-frontend-react:v1.7.0.199513cc1c45e
jackson-core@2.21.5
2.21.7
1
acryldata/datahub-upgrade:v1.7.0.1c3db54d8fb94
jackson-core@3.1.2
3.1.7
1
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
jackson-core@2.19.4
2.21.7
1
adeptiainc/adeptia-connect-migration:4.8.1f1087da3da0b
jackson-core@2.21.1
2.21.7
1
adityaprasadpathak/myapp:3.07e3b9777362c
jackson-core@2.17.1
2.18.11
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
jackson-core@2.17.2
2.18.11
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
jackson-core@2.17.1
2.18.11
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
jackson-core@2.18.4.1
2.18.11
1
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
jackson-core@2.17.1
2.18.11
1
airbyte/bootloader:2.3.0205b99d17c1a
jackson-core@2.21.5
2.21.7
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
jackson-core@2.20.1
2.21.7
1
airbyte/cron:2.3.0bf4835757eaa
jackson-core@2.21.5
2.21.7
1
airbyte/server:2.3.039141ed8ce5e
jackson-core@2.21.5
2.21.7
1
airbyte/worker:2.3.0f2e33fbc53d1
jackson-core@2.21.5
2.21.7
1
airbyte/workload-api-server:2.3.0434b4a811156
jackson-core@2.21.5
2.21.7
1
aktosecurity/akto-api-security-dashboard:latest3ecdd301cdbd
jackson-core@2.18.9
2.18.11
1
aktosecurity/akto-threat-detection-backend:1.18.4b12ce3e2dc71
jackson-core@2.18.9
2.18.11
1
aktosecurity/akto-threat-detection-backend:latestdffb8c3676ef
jackson-core@2.18.9
2.18.11
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
jackson-core@2.18.9
2.18.11
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
jackson-core@2.18.9
2.18.11
1
alfio/alf.io:2.0-M5-26060c836a081446
jackson-core@2.21.2
2.21.7
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux88c10693fe71a
jackson-core@2.18.2
2.18.11
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
jackson-core@2.18.4.1
2.18.11
1
apache/hertzbeat:1.8.075d48a62748f
jackson-core@2.18.2
2.18.11
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
jackson-core@2.18.2
2.18.11
1
apache/kafka:4.1.0bff074a5d005
jackson-core@2.19.0
2.21.7
1
apache/nifi-registry:1.27.063b8e3e40742
jackson-core@2.17.1
2.18.11
1
apache/polaris:lateste66366e783f1
jackson-core@2.22.0
2.22.3
1
apache/ranger:2.7.076c176e8a0e4
jackson-core@2.17.0
2.18.11
1
apache/tika:latest-full80072bb73dd3
jackson-core@2.22.1
2.22.3
1
apache/tika:3.3.1.090b7fa1dc018
jackson-core@2.21.3
2.21.7
1
apache/tika:3.2.2.0-fullffab324253ed
jackson-core@2.19.2
2.21.7
1
arcadedata/arcadedb:26.9.102a1a74fcef3
jackson-core@2.22.2
2.22.3
1
archivebox/archivebox:0.9.708c21bb233130
jackson-core@2.22.2
2.22.3
1
athou/commafeed:6.2.0-postgresql5e388351df1a
jackson-core@2.20.1
2.21.7
1
atlassian/bamboo:12.1.119160c3bfb73b
jackson-core@2.21.6
2.21.7
1
atlassian/bitbucket:10.2.705933f2b1cfd
jackson-core@2.21.5
2.21.7
1
atlassian/crowd:7.2.351e6d33676f6
jackson-core@2.21.5
2.21.7
1
atlassian/jira-software:11.3.114046f4a668a4
jackson-core@2.21.6
2.21.7
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.