StackRadar

CVE-2026-91776

High

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,051
of 17,985 indexed, latest versions
Container images
1,061
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind retains every unknown raw type ID

Carried by container images the latest versions of 1,051 of 17,985 indexed charts deploy, on 1,061 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.0.5, 2.2.3, 2.3.0, 2.3.3+121 more2.18.11, 2.21.7, 2.22.3, 3.1.7+1 more1,061
OSV records
GHSA-wv8q-qhhj-9h54
Trending
Rank 37 in indexed charts, since 1 Oct 2026. See the ranking →

Charts affected

1,051 by stars
ChartLatestAffected imagesRadar Score
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-databind@2.18.3
2.18.11

Open the chart page →

4,559
radar-mockserverradar-baseVerified publisher0.1.31 of 1See more

radar-mockserver radar-base 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-5.15.00f9ef78c9489
jackson-databind@2.14.1
2.18.11

Open the chart page →

1,363
radar-outputradar-baseVerified publisher1.2.101 of 1See more

radar-output radar-base 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
jackson-databind@2.20.2
2.21.7

Open the chart page →

2,845
radar-push-endpointradar-baseVerified publisher0.6.81 of 2See more

radar-push-endpoint radar-base 0.6.8

1 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
radarbase/radar-push-endpoint:0.4.0e1758508e033
jackson-databind@2.16.1
2.18.11

Open the chart page →

3,344
radar-upload-connect-backendradar-baseVerified publisher0.9.11 of 1See more

radar-upload-connect-backend radar-base 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
jackson-databind@2.19.2
2.21.7

Open the chart page →

2,857
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-databind@2.18.3
2.18.11

Open the chart page →

2,188
pagesranjinigogga1.0.01 of 3See more

pages ranjinigogga 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagesrebecca-pages1.0.01 of 3See more

pages rebecca-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
authentication-serviceredestroyder0.2.21 of 1See more

authentication-service redestroyder 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
redestroyder/authorization-service:0.0.1740364a619fd
jackson-databind@2.13.1
2.18.11

Open the chart page →

2,698
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
jackson-databind@2.13.1
2.18.11

Open the chart page →

2,719
iparedhat-cop1.3.91 of 1See more

ipa redhat-cop 1.3.9

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
jackson-databind@2.15.2
2.18.11

Open the chart page →

1,062
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
jackson-databind@2.17.1
2.18.11

Open the chart page →

4,649
reportportalreportportal5.7.23 of 8See more

reportportal reportportal 5.7.2

3 of the 8 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
jackson-databind@2.10.2
2.18.11
reportportal/service-authorization:5.7.09e73114dbd15
jackson-databind@2.10.2
2.18.11
reportportal/service-jobs:5.7.2dc166c58485a
jackson-databind@2.11.4
2.18.11

Open the chart page →

26,082
pagesroccohiggins-pages1.0.01 of 3See more

pages roccohiggins-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagesronan-pages1.0.01 of 3See more

pages ronan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
routr-connectroutr0.4.32 of 10See more

routr-connect routr 0.4.3

2 of the 10 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
fonoster/routr-edgeport:2.13.6d08a8a574a50
jackson-databind@2.9.6
2.18.11
fonoster/routr-requester:2.13.6e0c823506eb2
jackson-databind@2.9.6
2.18.11

Open the chart page →

11,608
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
jackson-databind@2.21.4
2.21.7

Open the chart page →

40,868
languagetoolrubxkubeVerified publisher0.1.01 of 1See more

languagetool rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
meyay/languagetool:6.8410a1f1a893b
jackson-databind@2.22.2
2.22.3

Open the chart page →

41
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
jackson-databind@3.1.2
3.1.7

Open the chart page →

7,102
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
jackson-databind@2.22.0
2.22.3

Open the chart page →

2,007
housekeepersaashousekeeper1.0.01 of 14See more

housekeeper saashousekeeper 1.0.0

1 of the 14 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
saashousekeeper/event-tracking:1.0.0d8786cea5bc4
jackson-databind@2.13.2.2
2.18.11

Open the chart page →

4,470
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
jackson-databind@2.12.2
2.18.11

Open the chart page →

4,075
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
jackson-databind@2.13.3
2.18.11

Open the chart page →

16,907
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
jackson-databind@2.13.3
2.18.11

Open the chart page →

8,484
helm-chart-examplesalaboy0.1.01 of 1See more

helm-chart-example salaboy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
jackson-databind@2.11.1
2.18.11

Open the chart page →

2,968
pagessamanvithkaranth1.0.01 of 3See more

pages samanvithkaranth 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagessarubits-pages1.0.01 of 3See more

pages sarubits-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
jackson-databind@2.15.2
2.18.11

Open the chart page →

1,719
keycloaksb-helm-charts0.3.01 of 2See more

keycloak sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
jackson-databind@2.17.2
2.18.11

Open the chart page →

2,628
keycloak-operatorschichtelVerified publisher0.8.61 of 1See more

keycloak-operator schichtel 0.8.6

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:26.7.33172bf49511c
jackson-databind@2.21.5
2.21.7

Open the chart page →

95
photonschichtelVerified publisher0.2.01 of 1See more

photon schichtel 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
rtuszik/photon-docker:2.4.021549c60f9e6
jackson-databind@2.22.1
2.22.3

Open the chart page →

3,265
smartquerysearchhub0.1.01 of 1See more

smartquery searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
commerceexperts/smartquery-service:2.2.09e33ad89baf6
jackson-databind@2.13.5
2.18.11

Open the chart page →

1,602
smartsuggestsearchhub0.1.01 of 1See more

smartsuggest searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
jackson-databind@2.15.3
2.18.11

Open the chart page →

1,321
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
jackson-databind@2.13.5
2.18.11

Open the chart page →

4,350
pagessekharpkube1.0.01 of 3See more

pages sekharpkube 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
jackson-databind@2.9.9
2.18.11

Open the chart page →

8,160
keycloakself-hosters-by-nightVerified publisher0.1.11 of 1See more

keycloak self-hosters-by-night 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.60aae0de7fca8
jackson-databind@2.21.2
2.21.7

Open the chart page →

662
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
jackson-databind@2.9.10.1
2.18.11

Open the chart page →

11,540
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
jackson-databind@2.17.0
2.18.11

Open the chart page →

5,821
shenyushenyu0.6.32 of 2See more

shenyu shenyu 0.6.3

2 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.5.1e2be712fc4f4
jackson-databind@2.13.3
2.18.11
apache/shenyu-bootstrap:2.5.11bd5756f6273
jackson-databind@2.13.2.1
2.18.11

Open the chart page →

9,070
shenyushenyu-helm-chart-test2.4.272 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

2 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
jackson-databind@2.10.1
2.18.11
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
jackson-databind@2.10.1
2.18.11

Open the chart page →

12,693
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
jackson-databind@2.21.2
2.21.7

Open the chart page →

5,789
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
jackson-databind@2.13.2.1
2.18.11

Open the chart page →

3,039
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
jackson-databind@2.18.2
2.18.11

Open the chart page →

1,915
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
jackson-databind@2.13.4.2
2.18.11

Open the chart page →

6,686
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
jackson-databind@2.14.1
2.18.11

Open the chart page →

5,023
simple-apisimple-api0.1.11 of 2See more

simple-api simple-api 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
jkaninda/simple-api:latestce4122d4c789
jackson-databind@2.15.4
2.18.11

Open the chart page →

1,839
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
jackson-databind@2.13.3
2.18.11

Open the chart page →

6,187
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2026-91776.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
jackson-databind@2.9.10
2.18.11

Open the chart page →

7,005

Container images carrying it

1,061 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
folioci/mod-courses:latest68ca414f5596
jackson-databind@2.18.2
2.18.11
1
folioci/mod-data-export:latest0cc86bf09755
jackson-databind@2.20.2
2.21.7
1
folioci/mod-data-export-spring:latestf1d7caf4544b
jackson-databind@3.0.4
3.1.7
1
folioci/mod-data-export-worker:latest1ad1811c9b37
jackson-databind@3.0.4
3.1.7
1
folioci/mod-data-import:latestec2c3ebe3f2b
jackson-databind@3.1.6
3.1.7
1
folioci/mod-data-import-converter-storage:latest3028f333778f
jackson-databind@2.13.4
2.18.11
1
folioci/mod-ebsconet:latest3ae8cb99daa3
jackson-databind@2.20.2
2.21.7
1
folioci/mod-email:latest79ea8e2e7ebf
jackson-databind@2.18.2
2.18.11
1
folioci/mod-entities-links:latest3e2412815c0f
jackson-databind@3.1.5
3.1.7
1
folioci/mod-erm-usage:latest56a8421de884
jackson-databind@3.1.5
3.1.7
1
folioci/mod-erm-usage-harvester:latest2d6767933c59
jackson-databind@2.18.6
2.18.11
1
folioci/mod-event-config:latest0192adad3897
jackson-databind@3.1.4
3.1.7
1
folioci/mod-feesfines:latestfe3a7049f2fb
jackson-databind@2.18.2
2.18.11
1
folioci/mod-finance:latest14450bc15430
jackson-databind@2.21.4
2.21.7
1
folioci/mod-finance-storage:latest4bc4057abaea
jackson-databind@3.1.4
3.1.7
1
folioci/mod-gobi:latestc58c989dac44
jackson-databind@2.20.1
2.21.7
1
folioci/mod-inn-reach:latestcc8584e43382
jackson-databind@3.1.4
3.1.7
1
folioci/mod-inventory:latest53518ba29668
jackson-databind@2.21.6
2.21.7
1
folioci/mod-inventory-storage:latestf92ff0a3ca40
jackson-databind@3.1.5
3.1.7
1
folioci/mod-inventory-update:latestba84812b4d58
jackson-databind@2.18.2
2.18.11
1
folioci/mod-invoice:latest45b7b13e81e1
jackson-databind@3.1.4
3.1.7
1
folioci/mod-invoice-storage:latest0bc720abcb78
jackson-databind@2.21.5
2.21.7
1
folioci/mod-kb-ebsco-java:latestfe66c7497864
jackson-databind@2.22.2
2.22.3
1
folioci/mod-ldp:latestb55696fd9065
jackson-databind@2.15.4
2.18.11
1
folioci/mod-licenses:latestcfd6109bf477
jackson-databind@2.18.7
2.18.11
1
folioci/mod-login:latest88de493f86db
jackson-databind@2.16.1
2.18.11
1
folioci/mod-login-saml:latest5f3358ccaa0f
jackson-databind@2.21.2
2.21.7
1
folioci/mod-marccat:latest1b57d690d568
jackson-databind@2.9.4
2.18.11
1
folioci/mod-notes:latest998ac4782e0d
jackson-databind@2.21.5
2.21.7
1
folioci/mod-notify:latesta8c1a90005fc
jackson-databind@3.1.4
3.1.7
1
folioci/mod-oa:latestae3b069d4ba5
jackson-databind@2.11.1
2.18.11
1
folioci/mod-oai-pmh:latest5cd5ef063f2a
jackson-databind@2.18.2
2.18.11
1
folioci/mod-orders:latestfc4528220fb8
jackson-databind@3.1.4
3.1.7
1
folioci/mod-orders-storage:latestceeaacc3bf16
jackson-databind@3.1.4
3.1.7
1
folioci/mod-organizations:latest7dc9ccf3d937
jackson-databind@2.18.6
2.18.11
1
folioci/mod-organizations-storage:lateste46892405fde
jackson-databind@2.21.4
2.21.7
1
folioci/mod-password-validator:latestb31d75f2bf7b
jackson-databind@3.1.4
3.1.7
1
folioci/mod-patron:latest5f213acfe2f8
jackson-databind@2.18.2
2.18.11
1
folioci/mod-patron-blocks:latestde7318069a67
jackson-databind@2.21.5
2.21.7
1
folioci/mod-permissions:latest5363e98c6299
jackson-databind@2.18.6
2.18.11
1
folioci/mod-pubsub:latest0a4fa4ad5d72
jackson-databind@2.18.6
2.18.11
1
folioci/mod-quick-marc:latest4d70ebda4d00
jackson-databind@2.21.5
2.21.7
1
folioci/mod-remote-storage:latest4f12177123dc
jackson-databind@2.21.4
2.21.7
1
folioci/mod-rtac:latestc959b2d6142f
jackson-databind@2.18.2
2.18.11
1
folioci/mod-search:latest44d7ee9acdf6
jackson-databind@3.1.5
3.1.7
1
folioci/mod-sender:latestd88a675dddf0
jackson-databind@2.18.2
2.18.11
1
folioci/mod-serials-management:latest571fa1ffe8c9
jackson-databind@2.11.1
2.18.11
1
folioci/mod-service-interaction:latestf53c327a48e8
jackson-databind@2.11.1
2.18.11
1
folioci/mod-source-record-manager:latesta940caf026ee
jackson-databind@2.21.5
2.21.7
1
folioci/mod-source-record-storage:latesta1434881eeb7
jackson-databind@2.21.6
2.21.7
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.