StackRadar

CVE-2026-91777

High

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,082
of 17,966 indexed, latest versions
Container images
1,079
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind quadratic forward-reference completion

Carried by container images the latest versions of 1,082 of 17,966 indexed charts deploy, on 1,079 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.5.0, 2.5.3, 2.5.4, 2.6.0+121 more2.18.11, 2.21.7, 2.22.3, 3.1.7+1 more1,079
OSV records
GHSA-cxp5-3px4-pw24
Trending
Rank 39 in indexed charts, since 1 Oct 2026. See the ranking →

Charts affected

1,082 by stars
ChartLatestAffected imagesRadar Score
mod-circulation-storagefolio-org0.1.351 of 1See more

mod-circulation-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-circulation-storage:latest6bdddcafbc0f
jackson-databind@2.18.6
2.18.11

Open the chart page →

662
mod-codex-ekbfolio-org0.1.341 of 1See more

mod-codex-ekb folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-codex-ekb:latest235a3fa4adc9
jackson-databind@2.13.2.1
2.18.11

Open the chart page →

2,117
mod-codex-inventoryfolio-org0.1.341 of 1See more

mod-codex-inventory folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-codex-inventory:latest6d53ed758fd1
jackson-databind@2.11.3
2.18.11

Open the chart page →

1,904
mod-codex-muxfolio-org0.1.341 of 1See more

mod-codex-mux folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-codex-mux:latestd4138abfd30d
jackson-databind@2.13.4
2.18.11

Open the chart page →

1,759
mod-configurationfolio-org0.1.341 of 1See more

mod-configuration folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-configuration:latestdd0cdc89670a
jackson-databind@2.18.6
2.18.11

Open the chart page →

716
mod-copycatfolio-org0.1.31 of 1See more

mod-copycat folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-copycat:latest1513fad2b799
jackson-databind@2.18.6
2.18.11

Open the chart page →

1,474
mod-coursesfolio-org0.1.341 of 1See more

mod-courses folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-courses:latest68ca414f5596
jackson-databind@2.18.2
2.18.11

Open the chart page →

1,541
mod-data-exportfolio-org0.1.401 of 1See more

mod-data-export folio-org 0.1.40

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-data-export:latest0cc86bf09755
jackson-databind@2.20.2
2.21.7

Open the chart page →

1,425
mod-data-export-springfolio-org0.1.41 of 1See more

mod-data-export-spring folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-data-export-spring:latestf1d7caf4544b
jackson-databind@3.0.4
3.1.7

Open the chart page →

1,258
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
jackson-databind@3.0.4
3.1.7

Open the chart page →

1,244
mod-data-importfolio-org0.1.381 of 1See more

mod-data-import folio-org 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-data-import:latestec2c3ebe3f2b
jackson-databind@3.1.6
3.1.7

Open the chart page →

11
mod-data-import-converter-storagefolio-org0.1.341 of 1See more

mod-data-import-converter-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-data-import-converter-storage:latest3028f333778f
jackson-databind@2.13.4
2.18.11

Open the chart page →

2,492
mod-ebsconetfolio-org0.1.31 of 1See more

mod-ebsconet folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-ebsconet:latest3ae8cb99daa3
jackson-databind@2.20.2
2.21.7

Open the chart page →

1,210
mod-emailfolio-org0.1.341 of 1See more

mod-email folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-email:latest79ea8e2e7ebf
jackson-databind@2.18.2
2.18.11

Open the chart page →

871
mod-entities-linksfolio-org0.1.11 of 1See more

mod-entities-links folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-entities-links:latest3e2412815c0f
jackson-databind@3.1.5
3.1.7

Open the chart page →

312
mod-erm-usagefolio-org0.1.341 of 1See more

mod-erm-usage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-erm-usage:latest56a8421de884
jackson-databind@3.1.5
3.1.7

Open the chart page →

0
mod-erm-usage-harvesterfolio-org0.1.341 of 1See more

mod-erm-usage-harvester folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-erm-usage-harvester:latest2d6767933c59
jackson-databind@2.18.6
2.18.11

Open the chart page →

567
mod-event-configfolio-org0.1.341 of 1See more

mod-event-config folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-event-config:latest0192adad3897
jackson-databind@3.1.4
3.1.7

Open the chart page →

421
mod-feesfinesfolio-org0.1.341 of 1See more

mod-feesfines folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-feesfines:latestfe3a7049f2fb
jackson-databind@2.18.2
2.18.11

Open the chart page →

667
mod-financefolio-org0.1.341 of 1See more

mod-finance folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-finance:latest14450bc15430
jackson-databind@2.21.4
2.21.7

Open the chart page →

538
mod-finance-storagefolio-org0.1.341 of 1See more

mod-finance-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-finance-storage:latest4bc4057abaea
jackson-databind@3.1.4
3.1.7

Open the chart page →

414
mod-gobifolio-org0.1.341 of 1See more

mod-gobi folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-gobi:latestc58c989dac44
jackson-databind@2.20.1
2.21.7

Open the chart page →

599
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
jackson-databind@3.1.4
3.1.7

Open the chart page →

513
mod-inventoryfolio-org0.1.361 of 1See more

mod-inventory folio-org 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-inventory:latest53518ba29668
jackson-databind@2.21.6
2.21.7

Open the chart page →

33
mod-inventory-storagefolio-org0.1.371 of 1See more

mod-inventory-storage folio-org 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-inventory-storage:latestf92ff0a3ca40
jackson-databind@3.1.5
3.1.7

Open the chart page →

81
mod-inventory-updatefolio-org0.1.21 of 1See more

mod-inventory-update folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-inventory-update:latestba84812b4d58
jackson-databind@2.18.2
2.18.11

Open the chart page →

883
mod-invoicefolio-org0.1.351 of 1See more

mod-invoice folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-invoice:latest45b7b13e81e1
jackson-databind@3.1.4
3.1.7

Open the chart page →

571
mod-invoice-storagefolio-org0.1.341 of 1See more

mod-invoice-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-invoice-storage:latest0bc720abcb78
jackson-databind@2.21.5
2.21.7

Open the chart page →

226
mod-kb-ebsco-javafolio-org0.1.351 of 1See more

mod-kb-ebsco-java folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-kb-ebsco-java:latestfe66c7497864
jackson-databind@2.22.2
2.22.3

Open the chart page →

0
mod-ldpfolio-org0.1.331 of 1See more

mod-ldp folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-ldp:latestb55696fd9065
jackson-databind@2.15.4
2.18.11

Open the chart page →

1,929
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
jackson-databind@2.18.7
2.18.11

Open the chart page →

1,787
mod-loginfolio-org0.1.341 of 1See more

mod-login folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-login:latest88de493f86db
jackson-databind@2.16.1
2.18.11

Open the chart page →

1,160
mod-login-samlfolio-org0.1.341 of 1See more

mod-login-saml folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-login-saml:latest5f3358ccaa0f
jackson-databind@2.21.2
2.21.7

Open the chart page →

1,097
mod-marccatfolio-org0.1.301 of 1See more

mod-marccat folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-marccat:latest1b57d690d568
jackson-databind@2.9.4
2.18.11

Open the chart page →

6,993
mod-notesfolio-org0.1.341 of 1See more

mod-notes folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-notes:latest998ac4782e0d
jackson-databind@2.21.5
2.21.7

Open the chart page →

157
mod-notifyfolio-org0.1.341 of 1See more

mod-notify folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-notify:latesta8c1a90005fc
jackson-databind@3.1.4
3.1.7

Open the chart page →

272
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
jackson-databind@2.11.1
2.18.11

Open the chart page →

1,735
mod-oai-pmhfolio-org0.1.341 of 1See more

mod-oai-pmh folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-oai-pmh:latest5cd5ef063f2a
jackson-databind@2.18.2
2.18.11

Open the chart page →

966
mod-ordersfolio-org0.1.341 of 1See more

mod-orders folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-orders:latestfc4528220fb8
jackson-databind@3.1.4
3.1.7

Open the chart page →

458
mod-orders-storagefolio-org0.1.351 of 1See more

mod-orders-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-orders-storage:latestceeaacc3bf16
jackson-databind@3.1.4
3.1.7

Open the chart page →

443
mod-organizationsfolio-org0.1.341 of 1See more

mod-organizations folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-organizations:latest7dc9ccf3d937
jackson-databind@2.18.6
2.18.11

Open the chart page →

814
mod-organizations-storagefolio-org0.1.341 of 1See more

mod-organizations-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-organizations-storage:lateste46892405fde
jackson-databind@2.21.4
2.21.7

Open the chart page →

670
mod-password-validatorfolio-org0.1.341 of 1See more

mod-password-validator folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-password-validator:latestb31d75f2bf7b
jackson-databind@3.1.4
3.1.7

Open the chart page →

395
mod-patronfolio-org0.1.341 of 1See more

mod-patron folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-patron:latest5f213acfe2f8
jackson-databind@2.18.2
2.18.11

Open the chart page →

832
mod-patron-blocksfolio-org0.1.341 of 1See more

mod-patron-blocks folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-patron-blocks:latestde7318069a67
jackson-databind@2.21.5
2.21.7

Open the chart page →

360
mod-permissionsfolio-org0.1.351 of 1See more

mod-permissions folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-permissions:latest5363e98c6299
jackson-databind@2.18.6
2.18.11

Open the chart page →

1,223
mod-pubsubfolio-org0.1.341 of 1See more

mod-pubsub folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-pubsub:latest0a4fa4ad5d72
jackson-databind@2.18.6
2.18.11

Open the chart page →

1,017
mod-quick-marcfolio-org0.1.351 of 1See more

mod-quick-marc folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-quick-marc:latest4d70ebda4d00
jackson-databind@2.21.5
2.21.7

Open the chart page →

63
mod-remote-storagefolio-org0.1.321 of 1See more

mod-remote-storage folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-remote-storage:latest4f12177123dc
jackson-databind@2.21.4
2.21.7

Open the chart page →

572
mod-rtacfolio-org0.1.341 of 1See more

mod-rtac folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
folioci/mod-rtac:latestc959b2d6142f
jackson-databind@2.18.2
2.18.11

Open the chart page →

669

Container images carrying it

1,079 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
saashousekeeper/event-tracking:1.0.0d8786cea5bc4
jackson-databind@2.13.2.2
2.18.11
1
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
jackson-databind@2.11.1
2.18.11
1
salehmir/jesse:1.10.101afa95f979e9
jackson-databind@2.16.1
2.18.11
1
scmmanager/scm-manager:3.12.1bfb766050f34
jackson-databind@2.21.1
2.21.7
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
jackson-databind@2.13.0
2.18.11
1
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
jackson-databind@2.9.9
2.18.11
1
seataio/seata-server:latest703b5de7f1a6
jackson-databind@2.13.5
2.18.11
1
seataio/seata-server:1.5.1ee1ed55f4144
jackson-databind@2.11.4
2.18.11
1
seldonio/apife:0.2.7ba81b17f00eb
jackson-databind@2.8.11.2
2.18.11
1
seldonio/apife:0.3.1eea0d3f578ca
jackson-databind@2.9.9
2.18.11
1
seldonio/cluster-manager:0.2.729e362bb1ba2
jackson-databind@2.8.11.2
2.18.11
1
sharque/panopticum:v8.4.7b032e41f6af5
jackson-databind@2.21.5
2.21.7
1
siakhooi/query:1.0.0f1f4b5b1b870
jackson-databind@3.1.0
3.1.7
1
signald/signald:0.18.20ffad7ccc2eb
jackson-databind@2.13.0
2.18.11
1
signald/signald:0.23.2edbff058278c
jackson-databind@2.14.1
2.18.11
1
slagattollas/planner-practica:latestcecd95e31486
jackson-databind@2.11.3
2.18.11
1
slagattollas/toposervice-practica:latestdc63973dae0d
jackson-databind@2.11.3
2.18.11
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
jackson-databind@2.9.10.6
2.18.11
1
slamdev/hetzner-irobo:0.0.13ca20c184c55
jackson-databind@2.12.5
2.18.11
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
jackson-databind@2.6.5
2.18.11
1
snowplow/iglu-server:0.12.0-distroless5a38033f07c1
jackson-databind@2.14.1
2.18.11
1
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
jackson-databind@2.9.10.6
2.18.11
1
softwaremill/bootzooka:latest845b5e8f8056
jackson-databind@3.1.1
3.1.7
1
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
jackson-databind@2.16.2
2.18.11
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
jackson-databind@2.11.3
2.18.11
1
sonatype/nexus:oss6bc88b51d4d7
jackson-databind@2.11.3
2.18.11
1
sonatype/nexus3:3.53.04bd975493104
jackson-databind@2.14.1
2.18.11
1
sonatype/nexus3:3.58.1586060431b64
jackson-databind@2.14.1
2.18.11
1
sonatype/nexus3:3.96.0-ubia1f2dbdc4c94
jackson-databind@3.2.1
3.2.3
1
sonatype/nexus3:3.96.3a406f4e9dc14
jackson-databind@3.2.1
3.2.3
1
sonatype/nexus3:3.96.3-ubicead2aaf041f
jackson-databind@3.2.1
3.2.3
1
sslhep/hive-metastore:3.1.39e80af083079
jackson-databind@2.7.8
2.18.11
1
stanislovesid/oracle-host-app:14fe1ed26e194
jackson-databind@2.12.5
2.18.11
1
stardog/stardog:latest2714e5c4b3c1
jackson-databind@2.18.3
2.18.11
1
strangebee/thehive:5.8.0-1a7f7b05fba24
jackson-databind@2.22.2
2.22.3
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
jackson-databind@2.15.0
2.18.11
1
structurizr/onpremises:2025.11.094b5ffb5119c8
jackson-databind@2.20.0
2.21.7
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jackson-databind@2.15.0
2.18.11
1
sysnet4admin/colosseum-agg:logbc25b152d88e
jackson-databind@2.18.2
2.18.11
1
tchiotludo/akhq:0.28.0c2824dc2ae44
jackson-databind@3.1.3
3.1.7
1
thehiveproject/cortex:3.1.7f4bc64fb8844
jackson-databind@2.11.1
2.18.11
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jackson-databind@2.8.11
2.18.11
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
jackson-databind@2.13.2
2.18.11
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
jackson-databind@2.13.2
2.18.11
1
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
jackson-databind@2.21.6
2.21.7
1
thingsboard/tbmq-node:2.4.070661025dba5
jackson-databind@2.21.6
2.21.7
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
jackson-databind@2.13.2
2.18.11
1
thingsboard/tb-node:3.4.1645f43b688f7
jackson-databind@2.13.2
2.18.11
1
thingsboard/tb-node:3.6.0f40a542832c4
jackson-databind@2.13.4.2
2.18.11
1
thingsboard/tb-postgres:latest2d17e4e36edc
jackson-databind@2.18.4
2.18.11
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.