StackRadar

CVE-2026-89425

High

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,075
of 17,985 indexed, latest versions
Container images
1,073
deployed by those charts
Fix available
1 of 1
affected package

jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)

Carried by container images the latest versions of 1,075 of 17,985 indexed charts deploy, on 1,073 images.

Affected packageAffected versionsFixed inImages
jackson-coremaven2.8.1, 2.8.4, 2.8.6, 2.8.7+91 more2.18.11, 2.21.7, 2.22.3, 3.1.7+1 more1,073
OSV records
GHSA-7hhh-6rmp-j9qf
Trending
Rank 3 in indexed charts, since 2 Oct 2026. See the ranking →

Charts affected

1,075 by stars
ChartLatestAffected imagesRadar Score
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
jackson-core@2.13.5
2.18.11

Open the chart page →

7,170
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
radondb/zookeeper:3.6.216981604f1a0
jackson-core@2.10.3
2.18.11

Open the chart page →

7,450
nacoskubesphere-testVerified publisher0.1.11 of 1See more

nacos kubesphere-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
nacos/nacos-server:1.4.1fe6e5688cdf3
jackson-core@2.10.4
2.18.11

Open the chart page →

4,250
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
jackson-core@2.15.2
2.18.11
penpotapp/exporter:2.2.15c835ffd87ab
jackson-core@2.12.4
2.18.11

Open the chart page →

18,975
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
jackson-core@2.17.2
2.18.11

Open the chart page →

3,491
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
jackson-core@2.17.1
2.18.11

Open the chart page →

3,719
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
jackson-core@2.17.1
2.18.11

Open the chart page →

8,847
strimzi-kafka-operatorkvalitetsitVerified publisher0.36.11 of 1See more

strimzi-kafka-operator kvalitetsit 0.36.1

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-core@2.14.2
2.18.11

Open the chart page →

4,304
imageboxkyso1.0.01 of 1See more

imagebox kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
kyso/imagebox:latest68091eace89c
jackson-core@2.9.8
2.18.11

Open the chart page →

3,874
mock-oidclabs64io-helm-chartsVerified publisher0.1.21 of 1See more

mock-oidc labs64io-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/navikt/mock-oauth2-server:2.1.1065d4ed47ce09
jackson-core@2.17.2
2.18.11

Open the chart page →

924
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
jackson-core@2.9.7
2.18.11

Open the chart page →

28,860
pageslatif-pages1.0.01 of 3See more

pages latif-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-core@2.11.0
2.18.11

Open the chart page →

21,119
pageslavanya-pages1.0.01 of 3See more

pages lavanya-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-core@2.11.0
2.18.11

Open the chart page →

21,119
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
jackson-core@2.11.0
2.18.11

Open the chart page →

3,197
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-core@2.20.1
2.21.7

Open the chart page →

5,125
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
jackson-core@2.18.1
2.18.11

Open the chart page →

4,006
pagesliviu884422-pages1.0.01 of 3See more

pages liviu884422-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-core@2.11.0
2.18.11

Open the chart page →

21,119
filebeatlog10x-elastic-helm-chartsVerified publisher1.5.11 of 1See more

filebeat log10x-elastic-helm-charts 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
log10x/filebeat-10x:1.1.39-native7d6a79dacd58
jackson-core@2.21.5
2.21.7

Open the chart page →

7,821
reporter-10xlog10x-helm-chartsVerified publisher1.2.31 of 2See more

reporter-10x log10x-helm-charts 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
log10x/edge-10x:1.1.744d6f596ed0c9
jackson-core@2.21.5
2.21.7

Open the chart page →

2,882
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
jackson-core@2.13.5
2.18.11

Open the chart page →

7,036
allure_docker_servicelovemew67Verified publisher0.0.11 of 1See more

allure_docker_service lovemew67 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.27.00815040339a9
jackson-core@2.16.1
2.18.11

Open the chart page →

66,133
efklovemew67Verified publisher0.0.11 of 2See more

efk lovemew67 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
nshou/elasticsearch-kibana:kibana7a1d1e36814d1
jackson-core@2.14.2
2.18.11

Open the chart page →

4,441
vulnerability-scaninglovemew67Verified publisher0.0.31 of 2See more

vulnerability-scaning lovemew67 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.35.14154286c0209
jackson-core@2.20.0
2.21.7

Open the chart page →

6,255
kafka-connect-wrapperlsmhun0.1.01 of 1See more

kafka-connect-wrapper lsmhun 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
jackson-core@2.11.1
2.18.11

Open the chart page →

2,487
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
jackson-core@2.8.11
2.18.11

Open the chart page →

8,141
elastictranscoderluiscajl0.46.04 of 4See more

elastictranscoder luiscajl 0.46.0

4 of the 4 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
jackson-core@2.12.3
2.18.11
elastictranscoder/media-storage:f6d861a026208b8c2359
jackson-core@2.12.3
2.18.11
elastictranscoder/transcoder:627e21dcb4a0327029e6
jackson-core@2.12.3
2.18.11
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
jackson-core@2.12.3
2.18.11

Open the chart page →

60,340
filebot-botluiscajl0.0.111 of 1See more

filebot-bot luiscajl 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
jackson-core@2.13.1
2.18.11

Open the chart page →

4,194
lavandaluiscajl0.0.1344 of 5See more

lavanda luiscajl 0.0.134

4 of the 5 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
jackson-core@2.11.2
2.18.11
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
jackson-core@2.11.2
2.18.11
lavandadelpatio/filebot:0.0.671f2ccec8c0d
jackson-core@2.11.4
2.18.11
lavandadelpatio/tmdb:0.0.2f36af885e915
jackson-core@2.11.4
2.18.11

Open the chart page →

20,062
tmdbluiscajl0.2.41 of 1See more

tmdb luiscajl 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
lavandadelpatio/tmdb:latestded9377636e9
jackson-core@2.15.3
2.18.11

Open the chart page →

2,322
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
jackson-core@2.14.2
2.18.11

Open the chart page →

3,391
joalm0nsterrr-joalVerified publisher2.2.01 of 2See more

joal m0nsterrr-joal 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
anthonyraymond/joal:2.1.37fc942567c564
jackson-core@2.13.3
2.18.11

Open the chart page →

10,699
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
jackson-core@2.13.2
2.18.11

Open the chart page →

31,371
eoloplantmca-eoloplaner0.1.02 of 7See more

eoloplant mca-eoloplaner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
hugohg34/planner:0.0.2171f61e8d7e2
jackson-core@2.13.0
2.18.11
hugohg34/toposervice:0.0.2812a03b3f274
jackson-core@2.13.0
2.18.11

Open the chart page →

34,101
dependency-trackmediamarktsaturn1.9.21 of 2See more

dependency-track mediamarktsaturn 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.14.21ba4f004e1ec
jackson-core@2.21.1
2.21.7

Open the chart page →

4,273
tinymediamanagermedia-servarrVerified publisher1.6.41 of 2See more

tinymediamanager media-servarr 1.6.4

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.36f332431a2ae
jackson-core@2.21.2
2.21.7

Open the chart page →

9,969
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
jackson-core@2.17.1
2.18.11

Open the chart page →

3,037
activemqmicroboxlabs3.8.01 of 1See more

activemq microboxlabs 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux88c10693fe71a
jackson-core@2.18.2
2.18.11

Open the chart page →

1,745
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
jackson-core@2.15.0
2.18.11

Open the chart page →

4,707
miot-calendarmicroboxlabs0.1.01 of 1See more

miot-calendar microboxlabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-calendar:latest-jvm7abd9085613a
jackson-core@2.20.1
2.21.7

Open the chart page →

2,209
miot-modulithmicroboxlabs0.6.01 of 1See more

miot-modulith microboxlabs 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-srv:latestd4782373f842
jackson-core@2.21.5
2.21.7

Open the chart page →

1,675
modulariotmicroboxlabs0.11.01 of 4See more

modulariot microboxlabs 0.11.0

1 of the 4 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-srv:latestf368323486ac
jackson-core@2.21.5
2.21.7

Open the chart page →

2,489
microcks-operatormicrocksVerified publisher0.0.111 of 1See more

microcks-operator microcks 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-core@2.19.2
2.21.7

Open the chart page →

1,538
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
jackson-core@2.15.2
2.18.11

Open the chart page →

3,834
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
jackson-core@2.15.2
2.18.11

Open the chart page →

5,348
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
jackson-core@2.15.2
2.18.11

Open the chart page →

4,801
streamsmicroslacVerified publisher0.1.05 of 6See more

streams microslac 0.1.0

5 of the 6 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.6.024cdd3a7fa89
jackson-core@2.14.2
2.18.11
confluentinc/cp-ksqldb-cli:7.6.0118cec1c87e2
jackson-core@2.14.2
2.18.11
confluentinc/ksqldb-server:latest1a3266adff1a
jackson-core@2.13.4
2.18.11
microslac/kafka-connect:latesta90091a1f524
jackson-core@2.15.3
2.18.11
provectuslabs/kafka-ui:latest8f2ff02d64b0
jackson-core@2.15.2
2.18.11

Open the chart page →

21,561
middleware-odigosmiddleware-labsVerified publisher0.2.411 of 6See more

middleware-odigos middleware-labs 0.2.41

1 of the 6 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
jackson-core@2.14.1
2.18.11

Open the chart page →

11,042
middleware-visionmiddleware-labsVerified publisher0.2.651 of 6See more

middleware-vision middleware-labs 0.2.65

1 of the 6 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
jackson-core@2.14.1
2.18.11

Open the chart page →

11,031
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
jackson-core@2.13.3
2.18.11

Open the chart page →

73,343
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
jackson-core@2.13.1
2.18.11

Open the chart page →

11,888

Container images carrying it

1,073 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
jackson-core@2.20.0
2.21.7
1
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
jackson-core@2.21.4
2.21.7
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-core@2.21.2
2.21.7
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jackson-core@2.15.3
2.18.11
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
jackson-core@2.19.2
2.21.7
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jackson-core@2.10.1
2.18.11
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
jackson-core@2.14.1
2.18.11
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
jackson-core@2.15.3
2.18.11
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
jackson-core@2.15.3
2.18.11
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
jackson-core@2.15.3
2.18.11
1
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
jackson-core@3.1.4
3.1.7
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
jackson-core@3.1.4
3.1.7
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
jackson-core@2.17.2
2.18.11
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
jackson-core@2.13.5
2.18.11
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
jackson-core@2.12.3
2.18.11
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
jackson-core@2.22.0
2.22.3
1
quay.io/streamshub/console-operator:0.11.0e40bbfeae125
jackson-core@2.19.2
2.21.7
1
quay.io/strimzi/operator:latest39cae00160b3
jackson-core@2.22.2
2.22.3
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-core@2.16.2
2.18.11
1
quay.io/strimzi/operator:0.32.0c5e0e5dca750
jackson-core@2.13.4
2.18.11
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-core@2.14.2
2.18.11
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-core@2.17.2
2.18.11
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.1126450354eba9
jackson-core@2.18.0
2.18.11
1

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.