StackRadar

CVE-2024-29371

High

Advisory

Published 17 Dec 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
61
of 17,781 indexed, latest versions
Container images
60
deployed by those charts
Fix available
1 of 1
affected package

jose4j is vulnerable to DoS via compressed JWE content

Carried by container images the latest versions of 61 of 17,781 indexed charts deploy, on 60 images.

Affected packageAffected versionsFixed inImages
jose4jmaven0.5.5, 0.6.3, 0.6.5, 0.7.0+11 more0.9.660
OSV records
GHSA-3677-xxcr-wjqv

Charts affected

61 by stars
ChartLatestAffected imagesRadar Score
apicurioone-acre-fundVerified publisher2.3.02 of 5See more

apicurio one-acre-fund 2.3.0

2 of the 5 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
jose4j@0.9.2
0.9.6
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
jose4j@0.9.2
0.9.6

Open the chart page →

18,667
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
jose4j@0.9.3
0.9.6

Open the chart page →

5,269
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
jose4j@0.7.9
0.9.6

Open the chart page →

6,443
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
jose4j@0.6.3
0.9.6

Open the chart page →

13,605
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jose4j@0.6.5
0.9.6

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jose4j@0.6.5
0.9.6

Open the chart page →

8,806
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jose4j@0.7.6
0.9.6

Open the chart page →

12,455
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
jose4j@0.9.4
0.9.6

Open the chart page →

1,733
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
jose4j@0.7.9
0.9.6

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jose4j@0.7.2
0.9.6

Open the chart page →

28,605
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-29371.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jose4j@0.7.11
0.9.6

Open the chart page →

6,016

Container images carrying it

60 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
jose4j@0.9.4
0.9.6
1
treskon/portrait:DEV-latest88e813f22347
jose4j@0.7.0
0.9.6
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
jose4j@0.9.4
0.9.6
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
jose4j@0.9.4
0.9.6
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jose4j@0.9.4
0.9.6
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
jose4j@0.7.12
0.9.6
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
jose4j@0.9.3
0.9.6
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jose4j@0.7.2
0.9.6
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
jose4j@0.7.9
0.9.6
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jose4j@0.7.11
0.9.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.