CVE-2018-1336
HighAdvisory
Published 17 Oct 2018In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.206
- 97th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 6
- of 17,781 indexed, latest versions
- Container images
- 8
- deployed by those charts
- Fix available
- 1 of 1
- affected package
In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 8 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| tomcat-embed-coremaven | 8.5.4, 8.5.11, 8.5.14, 8.5.15+2 more | 8.5.31 | 8 |
- OSV records
- GHSA-m59c-jpc8-m2x4
Charts affected
6 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| skywalkingkubesphere-testVerified publisher | 3.1.0 | 1 of 4See more | 18,042 |
| event-store-servicechoerodon | 0.8.0 | 1 of 2See more | 9,808 |
| my-chartfleet-web-app | 0.1.0 | 2 of 6See more | 24,296 |
| ibm-microclimateibm-charts | 0.1.0 | 2 of 8See more | 57,669 |
| sonarqubestakaterVerified publisher | 0.10.3 | 1 of 2See more | 11,841 |
| streamastreama | 1.0.1 | 1 of 2See more | 8,554 |
Container images carrying it
8 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| apache/ | 67d50e4deff4 | tomcat-embed-core | 8.5.31 | 1 |
| choerodon/ | 3c94c97f6f69 | tomcat-embed-core | 8.5.31 | 1 |
| ibmcom/ | ab3fd1fdfa18 | tomcat-embed-core | 8.5.31 | 1 |
| ibmcom/ | e17bdccc5030 | tomcat-embed-core | 8.5.31 | 1 |
| just1not2/ | 8a2305192dec | tomcat-embed-core | 8.5.31 | 1 |
| library/ | 0ae5169e3d0f | tomcat-embed-core | 8.5.31 | 1 |
| richardchesterwood/ | 518f946b9f05 | tomcat-embed-core | 8.5.31 | 1 |
| richardchesterwood/ | 36c43961214c | tomcat-embed-core | 8.5.31 | 1 |