StackRadar

CVE-2026-91777

High

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,082
of 17,966 indexed, latest versions
Container images
1,079
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind quadratic forward-reference completion

Carried by container images the latest versions of 1,082 of 17,966 indexed charts deploy, on 1,079 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.5.0, 2.5.3, 2.5.4, 2.6.0+121 more2.18.11, 2.21.7, 2.22.3, 3.1.7+1 more1,079
OSV records
GHSA-cxp5-3px4-pw24
Trending
Rank 39 in indexed charts, since 1 Oct 2026. See the ranking →

Charts affected

1,082 by stars
ChartLatestAffected imagesRadar Score
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
jackson-databind@2.15.2
2.18.11

Open the chart page →

2,363
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
jackson-databind@2.17.0
2.18.11

Open the chart page →

6,077
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jackson-databind@2.13.0
2.18.11

Open the chart page →

8,654
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
jackson-databind@2.14.2
2.18.11

Open the chart page →

9,942
apicurioone-acre-fundVerified publisher2.3.03 of 5See more

apicurio one-acre-fund 2.3.0

3 of the 5 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
jackson-databind@2.15.2
2.18.11
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
jackson-databind@2.15.2
2.18.11
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
jackson-databind@2.15.2
2.18.11

Open the chart page →

19,298
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
jackson-databind@2.14.0-rc1
2.18.11

Open the chart page →

6,568
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
vespaengine/vespa:8.526.1569b160f58211
jackson-databind@2.18.3
2.18.11

Open the chart page →

7,423
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
jackson-databind@2.15.2
2.18.11

Open the chart page →

2,683
mockserveropen-charts1.1.01 of 1See more

mockserver open-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
mockserver/mockserver:5.15.00f9ef78c9489
jackson-databind@2.14.1
2.18.11

Open the chart page →

1,363
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
jackson-databind@2.9.5
2.18.11

Open the chart page →

65,199
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
jackson-databind@2.7.3
2.18.11

Open the chart page →

264,687
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
woojoong/wowza:latestec230db19652
jackson-databind@2.9.0
2.18.11

Open the chart page →

44,158
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
jackson-databind@2.10.2
2.18.11

Open the chart page →

13,375
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
jackson-databind@2.7.3
2.18.11

Open the chart page →

98,978
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
jackson-databind@2.9.5
2.18.11

Open the chart page →

6,368
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
atomix/atomix:3.1.127738ff4f5c63
jackson-databind@2.9.6
2.18.11
voltha/voltha-onos:5.1.8e038acb950d3
jackson-databind@2.10.0
2.18.11

Open the chart page →

42,195
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
jackson-databind@2.21.3
2.21.7

Open the chart page →

2,322
bpjstk-serviceopenshift1.0.05 of 6See more

bpjstk-service openshift 1.0.0

5 of the 6 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
andrianrf/backoffice-be:latest6036614803d4
jackson-databind@2.13.5
2.18.11
andrianrf/bpjstk-service:latest46abe878d9d8
jackson-databind@2.11.2
2.18.11
andrianrf/bpjstk-simulator:latestb63fdb51d39d
jackson-databind@2.11.2
2.18.11
andrianrf/iso-client:latestba560086ce15
jackson-databind@2.11.2
2.18.11
andrianrf/iso-server:latest7da47f525c7d
jackson-databind@2.11.0
2.18.11

Open the chart page →

35,705
cp-cmfopenshift2.4.11 of 1See more

cp-cmf openshift 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
confluentinc/cp-cmf:2.4.1f466f8649aa8
jackson-databind@2.21.5
2.21.7

Open the chart page →

284
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
jackson-databind@2.18.3
2.18.11

Open the chart page →

7,857
redhat-springboot-restopenshift0.0.11 of 1See more

redhat-springboot-rest openshift 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
jackson-databind@2.13.5
2.18.11

Open the chart page →

3,121
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
jackson-databind@2.13.2.2
2.18.11

Open the chart page →

13,906
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
jackson-databind@2.13.2.2
2.18.11

Open the chart page →

12,046
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
jackson-databind@2.13.2.2
2.18.11

Open the chart page →

13,866
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
jackson-databind@2.13.2.2
2.18.11

Open the chart page →

13,849
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
jackson-databind@2.13.2.2
2.18.11

Open the chart page →

13,754
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
jackson-databind@2.13.2.2
2.18.11

Open the chart page →

13,394
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
jackson-databind@2.21.4
2.21.7

Open the chart page →

2,280
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
openwhisk/invoker:1.0.0f5831ec85525
jackson-databind@2.10.1
2.18.11

Open the chart page →

103,891
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
jackson-databind@2.18.3
2.18.11

Open the chart page →

2,331
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
jackson-databind@2.9.9.3
2.18.11

Open the chart page →

26,913
opsmx-autopilotopsmxVerified publisher2.0.01 of 2See more

opsmx-autopilot opsmx 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
opsmxdev/ubi8-autopilot:v2.9.10-202006181240c7e4ea797f11
jackson-databind@2.9.4
2.18.11

Open the chart page →

39,929
rest-appopsmxVerified publisher0.1.01 of 1See more

rest-app opsmx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
opsmx11/restapp:0.1.0c76b995be1fb
jackson-databind@2.9.7
2.18.11

Open the chart page →

5,596
trinoopstty0.2.141 of 1See more

trino opstty 0.2.14

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
trinodb/trino:4815b5e0a97f599
jackson-databind@2.21.3
2.21.7

Open the chart page →

1,329
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
jackson-databind@2.16.1
2.18.11

Open the chart page →

1,424
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
jackson-databind@2.18.2
2.18.11

Open the chart page →

229,002
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
jackson-databind@2.17.0
2.18.11

Open the chart page →

1,435
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
jackson-databind@2.14.1
2.18.11
mastercloudapps/planner:v1.2340a950b311b2
jackson-databind@2.13.0
2.18.11
mastercloudapps/server:v2.23f3d24dfe2686
jackson-databind@2.13.4.2
2.18.11

Open the chart page →

29,261
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
jackson-databind@2.10.0
2.18.11

Open the chart page →

20,594
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagespages-10.1.01 of 1See more

pages pages-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:1.04d2eb25b9225
jackson-databind@2.11.4
2.18.11

Open the chart page →

10,699
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-91777.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.18.11

Open the chart page →

20,785

Container images carrying it

1,079 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
5200710/hadoop:3.2.3-java8092d3088a5fb
jackson-databind@2.12.7.1
2.18.11
1
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
jackson-databind@2.10.5.1
2.18.11
1
acryldata/datahub-frontend-react:v1.7.0.199513cc1c45e
jackson-databind@2.21.5
2.21.7
1
acryldata/datahub-upgrade:v1.7.0.1c3db54d8fb94
jackson-databind@2.21.2
2.21.7
1
adagber/planner:v1.0e5c1ed097752
jackson-databind@2.13.0
2.18.11
1
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
jackson-databind@2.19.4
2.21.7
1
adeptiainc/adeptia-connect-migration:4.8.1f1087da3da0b
jackson-databind@2.21.1
2.21.7
1
adityaprasadpathak/myapp:3.07e3b9777362c
jackson-databind@2.17.1
2.18.11
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
jackson-databind@2.17.2
2.18.11
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
jackson-databind@2.17.1
2.18.11
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
jackson-databind@2.18.4
2.18.11
1
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
jackson-databind@2.17.0
2.18.11
1
airbyte/bootloader:2.3.0205b99d17c1a
jackson-databind@2.21.5
2.21.7
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
jackson-databind@2.20.1
2.21.7
1
airbyte/cron:2.3.0bf4835757eaa
jackson-databind@2.21.5
2.21.7
1
airbyte/cron:0.40.17caf4f551c546
jackson-databind@2.13.4.2
2.18.11
1
airbyte/server:2.3.039141ed8ce5e
jackson-databind@2.21.5
2.21.7
1
airbyte/worker:2.3.0f2e33fbc53d1
jackson-databind@2.21.5
2.21.7
1
airbyte/workload-api-server:2.3.0434b4a811156
jackson-databind@2.21.5
2.21.7
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
jackson-databind@2.12.3
2.18.11
1
aktosecurity/akto-api-protection:localbcd7382c9c1b
jackson-databind@2.16.1
2.18.11
1
aktosecurity/akto-api-security-dashboard:latest3ecdd301cdbd
jackson-databind@2.18.9
2.18.11
1
aktosecurity/akto-threat-detection-backend:1.18.4b12ce3e2dc71
jackson-databind@2.18.9
2.18.11
1
aktosecurity/akto-threat-detection-backend:latestdffb8c3676ef
jackson-databind@2.18.9
2.18.11
1
aktosecurity/data-ingestion-service213aded7adc5
jackson-databind@2.16.1
2.18.11
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
jackson-databind@2.16.1
2.18.11
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
jackson-databind@2.18.9
2.18.11
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
jackson-databind@2.18.9
2.18.11
1
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
jackson-databind@2.16.1
2.18.11
1
alfio/alf.io:2.0-M5-26060c836a081446
jackson-databind@2.21.2
2.21.7
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux88c10693fe71a
jackson-databind@2.18.2
2.18.11
1
amartinm82/planner:v2.01184353ff57b
jackson-databind@2.11.3
2.18.11
1
amazon/dynamodb-local:1.20.01ed00881c937
jackson-databind@2.12.7
2.18.11
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
jackson-databind@2.8.11.3
2.18.11
1
andrianrf/backoffice-be:latest6036614803d4
jackson-databind@2.13.5
2.18.11
1
andrianrf/bpjstk-service:latest46abe878d9d8
jackson-databind@2.11.2
2.18.11
1
andrianrf/bpjstk-simulator:latestb63fdb51d39d
jackson-databind@2.11.2
2.18.11
1
andrianrf/iso-client:latestba560086ce15
jackson-databind@2.11.2
2.18.11
1
andrianrf/iso-server:latest7da47f525c7d
jackson-databind@2.11.0
2.18.11
1
anguda/ant-media:2.5c435285fc241
jackson-databind@2.9.6
2.18.11
1
anthonyraymond/joal:2.1.37fc942567c564
jackson-databind@2.13.3
2.18.11
1
apache/bookkeeper:4.14.5a7d9970c148f
jackson-databind@2.11.0
2.18.11
1
apache/camel-k:1.10.43bb13d14f64a
jackson-databind@2.13.4
2.18.11
1
apache/drill:1.21.11f96558fd292
jackson-databind@2.14.1
2.18.11
1
apache/druid:29.0.10cef139b6bf1
jackson-databind@2.13.4.2
2.18.11
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
jackson-databind@2.21.3
2.21.7
1
apache/hadoop:3af361b20bec0
jackson-databind@2.12.7.1
2.18.11
1
apache/hertzbeat:1.8.075d48a62748f
jackson-databind@2.18.2
2.18.11
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
jackson-databind@2.18.2
2.18.11
1
apacheignite/ignite:2.7.0d7deab68b8fa
jackson-databind@2.9.6
2.18.11
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.