StackRadar

CVE-2024-47072

High

Advisory

Published 7 Nov 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.020
80th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
71
deployed by those charts
Fix available
1 of 1
affected package

XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 71 images.

Affected packageAffected versionsFixed inImages
xstreammaven1.3.1, 1.4.3, 1.4.4, 1.4.7+8 more1.4.2171
OSV records
GHSA-hfq9-hggm-c56q

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
xstream@1.4.18
1.4.21

Open the chart page →

5,856
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
xstream@1.4.13
1.4.21

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
xstream@1.4.11.1
1.4.21

Open the chart page →

13,079
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
xstream@1.3.1
1.4.21

Open the chart page →

11,841
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
xstream@1.4.11.1
1.4.21

Open the chart page →

12,513
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
xstream@1.4.20
1.4.21

Open the chart page →

6,016

Container images carrying it

71 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
xstream@1.4.19
1.4.21
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
xstream@1.4.19
1.4.21
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
xstream@1.4.19
1.4.21
1
microcks/microcks:0.8.0e3a3e0c67b09
xstream@1.3.1
1.4.21
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
xstream@1.4.20
1.4.21
1
openhab/openhab:3.2.0d0aa4af452c1
xstream@1.4.18
1.4.21
1
owasp/dependency-track:3.8.0efc65e702ee1
xstream@1.4.11.1
1.4.21
1
pedrocesarti/jmeter-docker:3.314851f144f57
xstream@1.4.10
1.4.21
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
xstream@1.4.19
1.4.21
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
xstream@1.4.19
1.4.21
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
xstream@1.4.18
1.4.21
1
seataio/seata-server:latest703b5de7f1a6
xstream@1.4.20
1.4.21
1
seataio/seata-server:1.5.1ee1ed55f4144
xstream@1.4.19
1.4.21
1
sonatype/nexus3:3.58.1586060431b64
xstream@1.4.20
1.4.21
1
wavefronthq/proxy:9.2d1064d28f6eb
xstream@1.4.11.1
1.4.21
1
woojoong/wowza:latestec230db19652
xstream@1.4.7
1.4.21
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
xstream@1.4.11.1
1.4.21
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
xstream@1.4.12
1.4.21
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
xstream@1.4.19
1.4.21
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
xstream@1.4.20
1.4.21
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
xstream@1.4.20
1.4.21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.