StackRadar

CVE-2026-91777

High

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,055
of 17,985 indexed, latest versions
Container images
1,055
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind quadratic forward-reference completion

Carried by container images the latest versions of 1,055 of 17,985 indexed charts deploy, on 1,055 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.5.0, 2.5.3, 2.5.4, 2.6.0+120 more2.18.11, 2.21.7, 2.22.3, 3.1.7+1 more1,055
OSV records
GHSA-cxp5-3px4-pw24
Trending
Rank 7 in indexed charts, since 1 Oct 2026. See the ranking →

Charts affected

1,055 by stars
ChartLatestAffected imagesRadar Score
ikigaiikigai-chartVerified publisher0.0.92 of 58See more

ikigai ikigai-chart 0.0.9

2 of the 58 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
jackson-databind@2.14.2
2.18.11
library/zookeeper:3.8-temurin55d1e5b2e601
jackson-databind@2.15.2
2.18.11

Open the chart page →

115,955
freeipaimprowisedVerified publisher0.4.11 of 1See more

freeipa improwised 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
jackson-databind@2.11.4
2.18.11

Open the chart page →

1,329
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
jackson-databind@2.17.1
2.18.11

Open the chart page →

5,839
fpga-operatorinaccelVerified publisher2.8.21 of 7See more

fpga-operator inaccel 2.8.2

1 of the 7 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
jackson-databind@2.13.5
2.18.11

Open the chart page →

5,865
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
jackson-databind@2.6.7.3
2.18.11

Open the chart page →

6,231
neo4jinseefrlab3.2.01 of 1See more

neo4j inseefrlab 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
library/neo4j:4.4.43c9fea42bd5a
jackson-databind@2.12.4
2.18.11

Open the chart page →

2,249
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
jackson-databind@2.13.4
2.18.11

Open the chart page →

1,840
pinotinseefrlab0.2.02 of 2See more

pinot inseefrlab 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
jackson-databind@2.10.0
2.18.11
library/zookeeper:3.5.5b7a76ec06f68
jackson-databind@2.9.8
2.18.11

Open the chart page →

10,971
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
jackson-databind@2.13.0
2.18.11

Open the chart page →

2,800
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
jackson-databind@2.18.3
2.18.11

Open the chart page →

4,155
daveit-at-mOfficialVerified publisher0.2.188 of 9See more

dave it-at-m 0.2.18

8 of the 9 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
jackson-databind@2.15.0
2.18.11
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
jackson-databind@2.21.4
2.21.7
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
jackson-databind@2.21.4
2.21.7
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
jackson-databind@2.21.4
2.21.7
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
jackson-databind@2.21.2
2.21.7
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
jackson-databind@2.21.4
2.21.7
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
jackson-databind@2.21.4
2.21.7
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
jackson-databind@2.21.4
2.21.7

Open the chart page →

14,467
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
jackson-databind@2.19.2
2.21.7

Open the chart page →

2,219
refarch-gatewayit-at-mVerified publisher1.10.01 of 1See more

refarch-gateway it-at-m 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/refarch/refarch-gateway:1.10.0d74e6a31e2fe
jackson-databind@3.1.5
3.1.7

Open the chart page →

254
refarch-templatesit-at-mVerified publisher2.3.01 of 1See more

refarch-templates it-at-m 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/refarch/refarch-gateway:1.10.0d74e6a31e2fe
jackson-databind@3.1.5
3.1.7

Open the chart page →

254
zammad-ldap-syncit-at-mVerified publisher0.6.51 of 1See more

zammad-ldap-sync it-at-m 0.6.5

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
jackson-databind@2.18.2
2.18.11

Open the chart page →

1,552
thehiveittrident-oss0.1.02 of 6See more

thehive ittrident-oss 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
library/cassandra:4.03a4876cc7f18
jackson-databind@2.19.2
2.21.7
thehiveproject/cortex:3.1.7f4bc64fb8844
jackson-databind@2.11.1
2.18.11

Open the chart page →

6,350
opencloudjacobcolvinVerified publisher0.2.32 of 13See more

opencloud jacobcolvin 0.2.3

2 of the 13 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
jackson-databind@2.17.0
2.18.11
quay.io/keycloak/keycloak:26.1.4044a457e0498
jackson-databind@2.17.2
2.18.11

Open the chart page →

47,213
jasperjasperVerified publisher1.0.2101 of 2See more

jasper jasper 1.0.210

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
jackson-databind@3.1.5
3.1.7

Open the chart page →

10,220
jenkinsjenkins-automation-tool0.1.01 of 1See more

jenkins jenkins-automation-tool 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.7

Open the chart page →

2,887
jenkinsjenkins-automation-tool-by-helm0.1.01 of 1See more

jenkins jenkins-automation-tool-by-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.7

Open the chart page →

2,887
jenkinsjenkins-chartVerified publisher0.1.01 of 1See more

jenkins jenkins-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.7

Open the chart page →

2,887
jx-app-jenkinsjenkins-x0.0.151 of 2See more

jx-app-jenkins jenkins-x 0.0.15

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.7

Open the chart page →

2,887
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jackson-databind@2.11.1
2.18.11

Open the chart page →

13,133
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
jackson-databind@2.13.4
2.18.11

Open the chart page →

8,394
proxerajfwenischVerified publisher0.12.201 of 1See more

proxera jfwenisch 0.12.20

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
jackson-databind@2.21.4
2.21.7

Open the chart page →

304
s3webuijfwenischVerified publisher1.3.41 of 1See more

s3webui jfwenisch 1.3.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/s3webui:lateste65f0f3786f5
jackson-databind@3.1.6
3.1.7

Open the chart page →

98
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
jackson-databind@2.18.1
2.18.11

Open the chart page →

7,386
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
jackson-databind@2.18.1
2.18.11

Open the chart page →

7,368
spring-boot-chartjhidalgo3-githubVerified publisher4.0.01 of 1See more

spring-boot-chart jhidalgo3-github 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
jhidalgo3/spring-echo-example:lateste08733191ea0
jackson-databind@2.11.4
2.18.11

Open the chart page →

1,792
xxl-job-adminjoelee2012Verified publisher1.1.01 of 2See more

xxl-job-admin joelee2012 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
xuxueli/xxl-job-admin:2.4.0640093c35fd6
jackson-databind@2.13.5
2.18.11

Open the chart page →

3,225
james-mailserverjondos2.1.21 of 1See more

james-mailserver jondos 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
apache/james:distributed-3.7.2660c0fa12ec2
jackson-databind@2.13.2.2
2.18.11

Open the chart page →

8,283
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
jackson-databind@2.17.0
2.18.11

Open the chart page →

68,520
k8sforjavak8sforjava0.1.01 of 1See more

k8sforjava k8sforjava 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
vincentgwzhang/k8sforjava:latesta9139f2cd98f
jackson-databind@2.18.2
2.18.11

Open the chart page →

1,600
dynamo-dbk8s-home-lab-repo0.0.31 of 1See more

dynamo-db k8s-home-lab-repo 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.20.01ed00881c937
jackson-databind@2.12.7
2.18.11

Open the chart page →

520
k8skeycloak-controllerk8skeycloak-controller0.1.21 of 1See more

k8skeycloak-controller k8skeycloak-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8skeycloak-controller:v0.0.19befc51b1ad6
jackson-databind@2.12.5
2.18.11

Open the chart page →

4,168
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
jackson-databind@2.17.3
2.18.11

Open the chart page →

7,957
kadeck-teamskadeck1.1.211 of 1See more

kadeck-teams kadeck 1.1.21

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
xeotek/kadeck:6.3.439a3b37a17c5
jackson-databind@2.15.0
2.18.11

Open the chart page →

3,972
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
jackson-databind@2.13.3
2.18.11

Open the chart page →

7,700
jenkinskallakruparaju-jenkins1.0.01 of 1See more

jenkins kallakruparaju-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.7

Open the chart page →

2,887
kanbanapp-demokanbanapp-demo0.3.01 of 3See more

kanbanapp-demo kanbanapp-demo 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
jackson-databind@2.9.9
2.18.11

Open the chart page →

7,532
kannikakannika0.19.01 of 3See more

kannika kannika 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
quay.io/kannika/kannika-api:0.19.05e5a3b3a911e
jackson-databind@2.21.6
2.21.7

Open the chart page →

976
keyauthoritykeyauthorityVerified publisher0.2.271 of 5See more

keyauthority keyauthority 0.2.27

1 of the 5 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
keyauthoritydh/keycloak:26.7.1-r1903c69d4ee97
jackson-databind@2.21.2
2.21.7

Open the chart page →

1,933
keycloak-operatorkeycloak-operator-by-kubitus-project1.0.202610010000071 of 1See more

keycloak-operator keycloak-operator-by-kubitus-project 1.0.20261001000007

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:26.7.406a13deb3919
jackson-databind@2.21.5
2.21.7

Open the chart page →

122
xwikikeyporttech0.2.01 of 2See more

xwiki keyporttech 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
library/xwiki:lts-postgres-tomcat9b8142bce157
jackson-databind@2.22.2
2.22.3

Open the chart page →

1,563
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
jackson-databind@2.14.1
2.18.11

Open the chart page →

69,601
cratedbkrateo0.1.41 of 1See more

cratedb krateo 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/crate:5.9.66318aab35613
jackson-databind@2.17.2
2.18.11

Open the chart page →

1,265
kron-aapm-agentkron-aapm-agent1.1.01 of 1See more

kron-aapm-agent kron-aapm-agent 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.1.07feef7d2ab42
jackson-databind@2.11.3
2.18.11

Open the chart page →

9,237
dinsrokronkltdVerified publisher0.1.71 of 2See more

dinsro kronkltd 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
duck1123/dinsro:latest9568c5961d5d
jackson-databind@2.14.2
2.18.11

Open the chart page →

1,953
aapm-servicekron-pam-aapm-helmcharts1.2.91 of 1See more

aapm-service kron-pam-aapm-helmcharts 1.2.9

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
krontechnology/aapm-service:1.2.3b964408930a5
jackson-databind@2.18.9
2.18.11

Open the chart page →

2,967
kron-aapm-agentkron-pam-aapm-helmcharts1.2.61 of 1See more

kron-aapm-agent kron-pam-aapm-helmcharts 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.8.508e04ea66dfd
jackson-databind@2.18.9
2.18.11

Open the chart page →

3,075

Container images carrying it

1,055 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/strimzi/operator:0.45.158c727cd2e68
jackson-databind@2.16.2
2.18.11
1
quay.io/strimzi/operator:0.32.0c5e0e5dca750
jackson-databind@2.13.4.1
2.18.11
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jackson-databind@2.14.2
2.18.11
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jackson-databind@2.17.2
2.18.11
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.1126450354eba9
jackson-databind@2.13.5
2.18.11
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.