StackRadar

CVE-2024-12397

High

Advisory

Published 12 Dec 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 1
affected package

io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
quarkus-http-coremaven3.0.15.Final, 3.1.0.Final, 4.1.9, 4.2.1+3 more5.3.416
OSV records
GHSA-cxrx-q234-m22m

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
quarkus-http-core@5.0.3.Final
5.3.4

Open the chart page →

6,675
musicocielmusicocielVerified publisher0.0.01 of 3See more

musicociel musicociel 0.0.0

1 of the 3 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
quarkus-http-core@5.0.3.Final
5.3.4

Open the chart page →

4,406
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
quarkus-http-core@4.1.9
5.3.4

Open the chart page →

37,373
keycloakbarravarVerified publisher1.0.41 of 1See more

keycloak barravar 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:24.0.34d6f22991266
quarkus-http-core@5.2.1.Final
5.3.4

Open the chart page →

2,381
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
quarkus-http-core@4.1.9
5.3.4

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
quarkus-http-core@4.1.9
5.3.4

Open the chart page →

6,915
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
quarkus-http-core@5.2.1.Final
5.3.4

Open the chart page →

15,369
apicurioone-acre-fundVerified publisher2.3.03 of 5See more

apicurio one-acre-fund 2.3.0

3 of the 5 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
quarkus-http-core@4.2.1
5.3.4
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
quarkus-http-core@4.2.1
5.3.4
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
quarkus-http-core@4.2.1
5.3.4

Open the chart page →

18,667
keycloakpascaliskeVerified publisher0.2.01 of 1See more

keycloak pascaliske 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.74388e2379b7e
quarkus-http-core@5.3.2
5.3.4

Open the chart page →

2,097
keycloaksb-helm-charts0.3.01 of 2See more

keycloak sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
quarkus-http-core@5.3.2
5.3.4

Open the chart page →

2,590
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
quarkus-http-core@4.1.9
5.3.4

Open the chart page →

6,443
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.009a381c715ab
quarkus-http-core@5.3.2
5.3.4

Open the chart page →

5,063
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
quarkus-http-core@3.1.0.Final
5.3.4

Open the chart page →

12,455
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
quarkus-http-core@3.0.15.Final
5.3.4

Open the chart page →

3,424
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-12397.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
quarkus-http-core@4.1.9
5.3.4

Open the chart page →

6,016

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:20.0054ef67eb7da
quarkus-http-core@4.1.9
5.3.4
2
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
quarkus-http-core@3.0.15.Final
5.3.4
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
quarkus-http-core@3.1.0.Final
5.3.4
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
quarkus-http-core@4.2.1
5.3.4
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
quarkus-http-core@4.2.1
5.3.4
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
quarkus-http-core@4.2.1
5.3.4
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
quarkus-http-core@4.1.9
5.3.4
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
quarkus-http-core@5.2.1.Final
5.3.4
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
quarkus-http-core@5.0.3.Final
5.3.4
1
quay.io/keycloak/keycloak:26.009a381c715ab
quarkus-http-core@5.3.2
5.3.4
1
quay.io/keycloak/keycloak:26.0.74388e2379b7e
quarkus-http-core@5.3.2
5.3.4
1
quay.io/keycloak/keycloak:24.0.34d6f22991266
quarkus-http-core@5.2.1.Final
5.3.4
1
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
quarkus-http-core@5.0.3.Final
5.3.4
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
quarkus-http-core@4.1.9
5.3.4
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
quarkus-http-core@5.3.2
5.3.4
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
quarkus-http-core@4.1.9
5.3.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.