StackRadar

CVE-2024-13009

High

Advisory

Published 8 May 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
175
of 17,781 indexed, latest versions
Container images
164
deployed by those charts
Fix available
1 of 1
affected package

**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request

Carried by container images the latest versions of 175 of 17,781 indexed charts deploy, on 164 images.

Affected packageAffected versionsFixed inImages
jetty-servermaven9.4.0.v20161208, 9.4.5.v20170502, 9.4.6.v20170531, 9.4.8.v20171121+37 more9.4.57.v20241219164
OSV records
GHSA-q4rv-gq96-w7c5

Charts affected

175 by stars
ChartLatestAffected imagesRadar Score
akto-protectionakto0.1.02 of 4See more

akto-protection akto 0.1.0

2 of the 4 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
jetty-server@9.4.51.v20230217
9.4.57.v20241219
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
jetty-server@9.4.51.v20230217
9.4.57.v20241219

Open the chart page →

11,285
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
jetty-server@9.4.15.v20190215
9.4.57.v20241219

Open the chart page →

11,553
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
jetty-server@9.4.24.v20191120
9.4.57.v20241219

Open the chart page →

5,277
apimap-apiapimapOfficialVerified publisher1.8.111 of 1See more

apimap-api apimap 1.8.11

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
apimap/api:v1.8.11ae2b3ab00177
jetty-server@9.4.49.v20220914
9.4.57.v20241219

Open the chart page →

2,231
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
jetty-server@9.4.48.v20220622
9.4.57.v20241219

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
jetty-server@9.4.40.v20210413
9.4.57.v20241219

Open the chart page →

8,866
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
jetty-server@9.4.51.v20230217
9.4.57.v20241219
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
jetty-server@9.4.51.v20230217
9.4.57.v20241219

Open the chart page →

14,728
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
jetty-server@9.4.11.v20180605
9.4.57.v20241219

Open the chart page →

7,936
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
jetty-server@9.4.53.v20231009
9.4.57.v20241219

Open the chart page →

9,412
tsoragecetic0.4.112 of 8See more

tsorage cetic 0.4.11

2 of the 8 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
jetty-server@9.4.11.v20180605
9.4.57.v20241219
library/zookeeper:3.5.5b7a76ec06f68
jetty-server@9.4.17.v20190418
9.4.57.v20241219

Open the chart page →

12,018
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jetty-server@9.4.6.v20170531
9.4.57.v20241219

Open the chart page →

5,078
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
jetty-server@9.4.14.v20181114
9.4.57.v20241219

Open the chart page →

9,144
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
jetty-server@9.4.11.v20180605
9.4.57.v20241219

Open the chart page →

4,601
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
jetty-server@9.4.11.v20180605
9.4.57.v20241219

Open the chart page →

2,837
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
jetty-server@9.4.8.v20171121
9.4.57.v20241219

Open the chart page →

7,226
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
jetty-server@9.4.11.v20180605
9.4.57.v20241219

Open the chart page →

23,665
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
jetty-server@9.4.12.v20180830
9.4.57.v20241219

Open the chart page →

11,782
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
jetty-server@9.4.11.v20180605
9.4.57.v20241219
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jetty-server@9.4.10.v20180503
9.4.57.v20241219

Open the chart page →

16,860
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
jetty-server@9.4.44.v20210927
9.4.57.v20241219

Open the chart page →

5,958
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jetty-server@9.4.33.v20201020
9.4.57.v20241219
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jetty-server@9.4.33.v20201020
9.4.57.v20241219
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jetty-server@9.4.33.v20201020
9.4.57.v20241219
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jetty-server@9.4.33.v20201020
9.4.57.v20241219
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jetty-server@9.4.33.v20201020
9.4.57.v20241219
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jetty-server@9.4.33.v20201020
9.4.57.v20241219
confluentinc/cp-zookeeper:6.1.078c190f4472c
jetty-server@9.4.33.v20201020
9.4.57.v20241219

Open the chart page →

58,857
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
jetty-server@9.4.54.v20240208
9.4.57.v20241219

Open the chart page →

5,398
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
jetty-server@9.4.25.v20191220
9.4.57.v20241219

Open the chart page →

8,986
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
jetty-server@9.4.12.v20180830
9.4.57.v20241219

Open the chart page →

11,782
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
jetty-server@9.4.20.v20190813
9.4.57.v20241219

Open the chart page →

19,802
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jetty-server@9.4.51.v20230217
9.4.57.v20241219

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jetty-server@9.4.51.v20230217
9.4.57.v20241219

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jetty-server@9.4.51.v20230217
9.4.57.v20241219

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jetty-server@9.4.51.v20230217
9.4.57.v20241219

Open the chart page →

4,033
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
jetty-server@9.4.49.v20220914
9.4.57.v20241219

Open the chart page →

24,296
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
jetty-server@9.4.39.v20210325
9.4.57.v20241219

Open the chart page →

1,874
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
jetty-server@9.4.39.v20210325
9.4.57.v20241219

Open the chart page →

1,760
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
jetty-server@9.4.39.v20210325
9.4.57.v20241219

Open the chart page →

1,733
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
jetty-server@9.4.39.v20210325
9.4.57.v20241219

Open the chart page →

1,733
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
jetty-server@9.4.39.v20210325
9.4.57.v20241219

Open the chart page →

1,733
accumulogaffer2.2.13 of 4See more

accumulo gaffer 2.2.1

3 of the 4 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
jetty-server@9.4.19.v20190610
9.4.57.v20241219
gchq/hdfs:3.3.35ec58edbb2db
jetty-server@9.4.43.v20210629
9.4.57.v20241219
library/zookeeper:3.5.5b7a76ec06f68
jetty-server@9.4.17.v20190418
9.4.57.v20241219

Open the chart page →

16,892
gaffer-road-trafficgaffer2.2.12 of 8See more

gaffer-road-traffic gaffer 2.2.1

2 of the 8 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
jetty-server@9.4.43.v20210629
9.4.57.v20241219
library/zookeeper:3.5.5b7a76ec06f68
jetty-server@9.4.17.v20190418
9.4.57.v20241219

Open the chart page →

9,342
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jetty-server@9.4.53.v20231009
9.4.57.v20241219

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jetty-server@9.4.53.v20231009
9.4.57.v20241219

Open the chart page →

11,961
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
jetty-server@9.4.43.v20210629
9.4.57.v20241219

Open the chart page →

2,887
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
jetty-server@9.4.36.v20210114
9.4.57.v20241219

Open the chart page →

26,944
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-server@9.4.43.v20210629
9.4.57.v20241219

Open the chart page →

4,547
zookeepergengxiankun-charts0.2.01 of 1See more

zookeeper gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
library/zookeeper:3.6.24c8a6d3b2338
jetty-server@9.4.24.v20191120
9.4.57.v20241219

Open the chart page →

1,913
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.82 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

2 of the 5 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
jetty-server@9.4.11.v20180605
9.4.57.v20241219
jingking/geonetwork-hnap:4.2.843e74ab234e1
jetty-server@9.4.11.v20180605
9.4.57.v20241219

Open the chart page →

34,754
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jetty-server@9.4.53.v20231009
9.4.57.v20241219

Open the chart page →

49,025
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
jetty-server@9.4.11.v20180605
9.4.57.v20241219

Open the chart page →

15,722
ubooquityhalkeye0.1.11 of 1See more

ubooquity halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-server@9.4.0.v20161208
9.4.57.v20241219

Open the chart page →

4,303
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
jetty-server@9.4.43.v20210629
9.4.57.v20241219

Open the chart page →

6,102
hbasehbase0.1.72 of 4See more

hbase hbase 0.1.7

2 of the 4 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jetty-server@9.4.46.v20220331
9.4.57.v20241219
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jetty-server@9.4.43.v20210629
9.4.57.v20241219

Open the chart page →

10,540
helm-airportshelm-airports0.1.01 of 7See more

helm-airports helm-airports 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-server@9.4.43.v20210629
9.4.57.v20241219

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-13009.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-server@9.4.43.v20210629
9.4.57.v20241219

Open the chart page →

4,547

Container images carrying it

164 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-server@9.4.30.v20200611
9.4.57.v20241219
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
jetty-server@9.4.56.v20240826
9.4.57.v20241219
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
jetty-server@9.4.56.v20240826
9.4.57.v20241219
1
ghcr.io/kubelauncher/zookeeper7826e9caa461
jetty-server@9.4.56.v20240826
9.4.57.v20241219
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jetty-server@9.4.43.v20210629
9.4.57.v20241219
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jetty-server@9.4.53.v20231009
9.4.57.v20241219
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
jetty-server@9.4.48.v20220622
9.4.57.v20241219
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
jetty-server@9.4.53.v20231009
9.4.57.v20241219
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
jetty-server@9.4.53.v20231009
9.4.57.v20241219
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-server@9.4.12.v20180830
9.4.57.v20241219
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
jetty-server@9.4.51.v20230217
9.4.57.v20241219
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
jetty-server@9.4.48.v20220622
9.4.57.v20241219
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jetty-server@9.4.11.v20180605
9.4.57.v20241219
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jetty-server@9.4.51.v20230217
9.4.57.v20241219
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.