StackRadar

CVE-2026-89425

High

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,076
of 17,985 indexed, latest versions
Container images
1,074
deployed by those charts
Fix available
1 of 1
affected package

jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)

Carried by container images the latest versions of 1,076 of 17,985 indexed charts deploy, on 1,074 images.

Affected packageAffected versionsFixed inImages
jackson-coremaven2.8.1, 2.8.4, 2.8.6, 2.8.7+91 more2.18.11, 2.21.7, 2.22.3, 3.1.7+1 more1,074
OSV records
GHSA-7hhh-6rmp-j9qf
Trending
Rank 30 in indexed charts, since 2 Oct 2026. See the ranking →

Charts affected

1,076 by stars
ChartLatestAffected imagesRadar Score
daveit-at-mOfficialVerified publisher0.2.188 of 9See more

dave it-at-m 0.2.18

8 of the 9 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
jackson-core@2.17.2
2.18.11
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
jackson-core@2.17.2
2.18.11
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
jackson-core@2.17.2
2.18.11
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
jackson-core@2.21.4
2.21.7
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
jackson-core@2.21.2
2.21.7
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
jackson-core@2.21.4
2.21.7
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
jackson-core@2.21.4
2.21.7
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
jackson-core@2.21.4
2.21.7

Open the chart page →

14,467
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
jackson-core@2.19.2
2.21.7

Open the chart page →

2,219
refarch-gatewayit-at-mVerified publisher1.10.01 of 1See more

refarch-gateway it-at-m 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/refarch/refarch-gateway:1.10.0d74e6a31e2fe
jackson-core@2.17.2
2.18.11

Open the chart page →

254
refarch-templatesit-at-mVerified publisher2.3.01 of 1See more

refarch-templates it-at-m 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/refarch/refarch-gateway:1.10.0d74e6a31e2fe
jackson-core@2.17.2
2.18.11

Open the chart page →

254
zammad-ldap-syncit-at-mVerified publisher0.6.51 of 1See more

zammad-ldap-sync it-at-m 0.6.5

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
jackson-core@2.18.2
2.18.11

Open the chart page →

1,552
thehiveittrident-oss0.1.02 of 6See more

thehive ittrident-oss 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
library/cassandra:4.03a4876cc7f18
jackson-core@2.19.2
2.21.7
thehiveproject/cortex:3.1.7f4bc64fb8844
jackson-core@2.11.1
2.18.11

Open the chart page →

6,350
opencloudjacobcolvinVerified publisher0.2.32 of 13See more

opencloud jacobcolvin 0.2.3

2 of the 13 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
jackson-core@2.17.0
2.18.11
quay.io/keycloak/keycloak:26.1.4044a457e0498
jackson-core@2.17.2
2.18.11

Open the chart page →

47,213
jasperjasperVerified publisher1.0.2101 of 2See more

jasper jasper 1.0.210

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
jackson-core@3.1.5
3.1.7

Open the chart page →

10,220
jenkinsjenkins-automation-tool0.1.01 of 1See more

jenkins jenkins-automation-tool 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-core@2.20.1
2.21.7

Open the chart page →

2,887
jenkinsjenkins-automation-tool-by-helm0.1.01 of 1See more

jenkins jenkins-automation-tool-by-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-core@2.20.1
2.21.7

Open the chart page →

2,887
jenkinsjenkins-chartVerified publisher0.1.01 of 1See more

jenkins jenkins-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-core@2.20.1
2.21.7

Open the chart page →

2,887
jx-app-jenkinsjenkins-x0.0.151 of 2See more

jx-app-jenkins jenkins-x 0.0.15

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-core@2.20.1
2.21.7

Open the chart page →

2,887
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jackson-core@2.11.1
2.18.11

Open the chart page →

13,133
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
jackson-core@2.13.4
2.18.11

Open the chart page →

8,394
proxerajfwenischVerified publisher0.12.201 of 1See more

proxera jfwenisch 0.12.20

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
jackson-core@3.1.4
3.1.7

Open the chart page →

304
s3webuijfwenischVerified publisher1.3.41 of 1See more

s3webui jfwenisch 1.3.4

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/s3webui:lateste65f0f3786f5
jackson-core@3.1.6
3.1.7

Open the chart page →

98
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
jackson-core@2.18.1
2.18.11

Open the chart page →

7,386
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
jackson-core@2.18.1
2.18.11

Open the chart page →

7,368
spring-boot-chartjhidalgo3-githubVerified publisher4.0.01 of 1See more

spring-boot-chart jhidalgo3-github 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
jhidalgo3/spring-echo-example:lateste08733191ea0
jackson-core@2.11.4
2.18.11

Open the chart page →

1,792
xxl-job-adminjoelee2012Verified publisher1.1.01 of 2See more

xxl-job-admin joelee2012 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
xuxueli/xxl-job-admin:2.4.0640093c35fd6
jackson-core@2.13.5
2.18.11

Open the chart page →

3,225
james-mailserverjondos2.1.21 of 1See more

james-mailserver jondos 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
apache/james:distributed-3.7.2660c0fa12ec2
jackson-core@2.12.3
2.18.11

Open the chart page →

8,283
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
jackson-core@2.17.0
2.18.11

Open the chart page →

68,520
k8sforjavak8sforjava0.1.01 of 1See more

k8sforjava k8sforjava 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
vincentgwzhang/k8sforjava:latesta9139f2cd98f
jackson-core@2.18.2
2.18.11

Open the chart page →

1,600
dynamo-dbk8s-home-lab-repo0.0.31 of 1See more

dynamo-db k8s-home-lab-repo 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.20.01ed00881c937
jackson-core@2.12.7
2.18.11

Open the chart page →

520
k8skeycloak-controllerk8skeycloak-controller0.1.21 of 1See more

k8skeycloak-controller k8skeycloak-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8skeycloak-controller:v0.0.19befc51b1ad6
jackson-core@2.12.5
2.18.11

Open the chart page →

4,168
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
jackson-core@2.17.3
2.18.11

Open the chart page →

7,957
kadeck-teamskadeck1.1.211 of 1See more

kadeck-teams kadeck 1.1.21

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
xeotek/kadeck:6.3.439a3b37a17c5
jackson-core@2.15.0
2.18.11

Open the chart page →

3,972
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
jackson-core@2.13.3
2.18.11

Open the chart page →

7,700
jenkinskallakruparaju-jenkins1.0.01 of 1See more

jenkins kallakruparaju-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-core@2.20.1
2.21.7

Open the chart page →

2,887
kanbanapp-demokanbanapp-demo0.3.01 of 3See more

kanbanapp-demo kanbanapp-demo 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
jackson-core@2.9.9
2.18.11

Open the chart page →

7,532
kannikakannika0.19.01 of 3See more

kannika kannika 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
quay.io/kannika/kannika-api:0.19.05e5a3b3a911e
jackson-core@3.1.5
3.1.7

Open the chart page →

976
keyauthoritykeyauthorityVerified publisher0.2.271 of 5See more

keyauthority keyauthority 0.2.27

1 of the 5 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
keyauthoritydh/keycloak:26.7.1-r1903c69d4ee97
jackson-core@2.21.2
2.21.7

Open the chart page →

1,933
keycloak-operatorkeycloak-operator-by-kubitus-project1.0.202610010000071 of 1See more

keycloak-operator keycloak-operator-by-kubitus-project 1.0.20261001000007

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:26.7.406a13deb3919
jackson-core@2.21.5
2.21.7

Open the chart page →

122
xwikikeyporttech0.2.01 of 2See more

xwiki keyporttech 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
library/xwiki:lts-postgres-tomcat9b8142bce157
jackson-core@2.22.2
2.22.3

Open the chart page →

1,563
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
jackson-core@2.14.1
2.18.11

Open the chart page →

69,601
klagklagVerified publisher0.3.171 of 1See more

klag klag 0.3.17

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
themoah/klag:0.2.187178531ebe86
jackson-core@2.21.6
2.21.7

Open the chart page →

591
cratedbkrateo0.1.41 of 1See more

cratedb krateo 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/crate:5.9.66318aab35613
jackson-core@2.17.2
2.18.11

Open the chart page →

1,265
kron-aapm-agentkron-aapm-agent1.1.01 of 1See more

kron-aapm-agent kron-aapm-agent 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.1.07feef7d2ab42
jackson-core@2.11.3
2.18.11

Open the chart page →

9,237
dinsrokronkltdVerified publisher0.1.71 of 2See more

dinsro kronkltd 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
duck1123/dinsro:latest9568c5961d5d
jackson-core@2.14.2
2.18.11

Open the chart page →

1,953
fileserverkronkltdVerified publisher0.3.101 of 1See more

fileserver kronkltd 0.3.10

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
duck1123/lnd-fileserver:latest9d6fb247b714
jackson-core@2.13.3
2.18.11

Open the chart page →

3,987
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
duck1123/cert-downloader:latest0e29f19fa67c
jackson-core@2.13.3
2.18.11

Open the chart page →

5,920
aapm-servicekron-pam-aapm-helmcharts1.2.91 of 1See more

aapm-service kron-pam-aapm-helmcharts 1.2.9

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
krontechnology/aapm-service:1.2.3b964408930a5
jackson-core@2.18.9
2.18.11

Open the chart page →

2,967
kron-aapm-agentkron-pam-aapm-helmcharts1.2.61 of 1See more

kron-aapm-agent kron-pam-aapm-helmcharts 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.8.508e04ea66dfd
jackson-core@2.18.9
2.18.11

Open the chart page →

3,075
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
jackson-core@2.13.4
2.18.11

Open the chart page →

4,759
tapm-componentkubebb5.7.12 of 3See more

tapm-component kubebb 5.7.1

2 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
refar/apm-api:v5.7.1241373fa2972
jackson-core@2.11.1
2.18.11
refar/apm-operator-server:v5.7.1e5490f050f9f
jackson-core@2.11.1
2.18.11

Open the chart page →

10,430
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
jackson-core@2.13.3
2.18.11

Open the chart page →

6,583
sonarqubekubesphereVerified publisher6.7.01 of 3See more

sonarqube kubesphere 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
library/sonarqube:8.9-communityeb2f0be32efd
jackson-core@2.12.1
2.18.11

Open the chart page →

2,381
skywalkingkubesphere-carryon-experimental0.6.02 of 5See more

skywalking kubesphere-carryon-experimental 0.6.0

2 of the 5 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:6.5.0c1ee839ccad0
jackson-core@2.9.5
2.18.11
apache/skywalking-ui:6.5.0a84f9d9b8067
jackson-core@2.8.10
2.18.11

Open the chart page →

13,620
clickhousekubesphere-carryon-test0.1.11 of 2See more

clickhouse kubesphere-carryon-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
radondb/zookeeper:3.6.216981604f1a0
jackson-core@2.10.3
2.18.11

Open the chart page →

6,978
hertzbeatkubesphere-carryon-test1.4.11 of 4See more

hertzbeat kubesphere-carryon-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-89425.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
jackson-core@2.10.5
2.18.11

Open the chart page →

8,149

Container images carrying it

1,074 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
jackson-core@2.11.0
2.18.11
80
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
jackson-core@2.20.1
2.21.7
20
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
jackson-core@2.14.1
2.18.11
13
codeurjc/server:v1.0310bea5b1ee7
jackson-core@2.13.4
2.18.11
8
wurstmeister/kafka:latest2d4bbf9cc83d
jackson-core@2.10.5
2.18.11
7
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
jackson-core@2.21.2
2.21.7
7
library/zookeeper:3.5.5b7a76ec06f68
jackson-core@2.9.8
2.18.11
6
solsson/kafka:latest41e5d8f6f290
jackson-core@2.13.3
2.18.11
5
gradiant/hbase-base:2.0.1a1ee6de94c04
jackson-core@2.9.2
2.18.11
4
guacamole/guacamole:1.6.0f344085e618b
jackson-core@2.19.0
2.21.7
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
jackson-core@2.13.2
2.18.11
4
mastercloudapps/planner:v1.2340a950b311b2
jackson-core@2.13.0
2.18.11
4
mastercloudapps/server:v2.23f3d24dfe2686
jackson-core@2.13.4
2.18.11
4
oscarsotosanchez/toposervice:v1.0d4d020e9f272
jackson-core@2.11.3
2.18.11
4
provectuslabs/kafka-ui:latest8f2ff02d64b0
jackson-core@2.15.2
2.18.11
4
quay.io/keycloak/keycloak:26.7.482a77884f3af
jackson-core@2.21.5
2.21.7
4
quay.io/strimzi/operator:0.37.052f376e64b9b
jackson-core@2.15.2
2.18.11
4
apache/shenyu-admin:2.4.2e8b7c4ddd069
jackson-core@2.10.1
2.18.11
3
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
jackson-core@2.10.1
2.18.11
3
codeurjc/planner:v1.0800cf520c245
jackson-core@2.13.0
2.18.11
3
gchq/hdfs:3.3.35ec58edbb2db
jackson-core@2.13.2
2.18.11
3
hazelcast/hazelcast:5.5.05dd5d31c7a06
jackson-core@2.17.2
2.18.11
3
jacobalberty/unifi:v10.0.162896c0ab82d33
jackson-core@2.17.3
2.18.11
3
library/solr:8.11.18c5f7881cebb
jackson-core@2.12.3
2.18.11
3
library/zookeeper:3.9.57d0f24ebb67b
jackson-core@2.15.2
2.18.11
3
library/zookeeper:3.6.180ad2170ad62
jackson-core@2.10.3
2.18.11
3
lmenezes/cerebro:0.9.47d9e2b77e459
jackson-core@2.10.5
2.18.11
3
mockserver/mockserver:5.15.0:mockserver-5.15.00f9ef78c9489
jackson-core@2.14.1
2.18.11
3
pavanelthepu/todo-api:1.0.2f47658e3b24c
jackson-core@2.12.3
2.18.11
3
signoz/zookeeper:3.7.1fcc4a3288154
jackson-core@2.13.2
2.18.11
3
supertokens/supertokens-postgresql:3.1418d34c781347
jackson-core@2.10.0
2.18.11
3
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
jackson-core@2.21.2
2.21.7
3
ghcr.io/quenchworks/images/keycloak6d08670cfdb6
jackson-core@2.21.5
2.21.7
3
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.6_local:latest8b9208c09d76
jackson-core@2.18.9
2.18.11
3
quay.io/keycloak/keycloak-operator:26.7.406a13deb3919
jackson-core@2.21.5
2.21.7
3
airbyte/workload-launcher:2.3.00e18b1abcda6
jackson-core@2.21.5
2.21.7
2
alexandreroman/hello:latest4b79473442be
jackson-core@2.9.8
2.18.11
2
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
jackson-core@2.10.5
2.18.11
2
apache/druid:37.0.00116fb802786
jackson-core@2.19.2
2.21.7
2
apache/fineract:1.12.1a83cf1980609
jackson-core@2.18.3
2.18.11
2
apache/iotdb:0.13.3-nodeafa47bf1692a
jackson-core@2.10.5
2.18.11
2
apache/kafka:4.3.177e3df905404
jackson-core@2.21.2
2.21.7
2
apache/nifi-registry:1.26.07cdfd8deec92
jackson-core@2.17.0
2.18.11
2
apachepulsar/pulsar:2.6.14db6ff0b4045
jackson-core@2.11.1
2.18.11
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jackson-core@2.9.5
2.18.11
2
apache/rocketmq:5.4.0319cd8a81ed1
jackson-core@2.18.1
2.18.11
2
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
jackson-core@2.10.1
2.18.11
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
jackson-core@2.18.3
2.18.11
2
apache/skywalking-oap-server:8.1.0-es7641237e0299b
jackson-core@2.9.5
2.18.11
2
apache/skywalking-ui:8.1.067d50e4deff4
jackson-core@2.9.10
2.18.11
2

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.