StackRadar

CVE-2024-57699

High

Advisory

Published 6 Feb 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
34
of 17,781 indexed, latest versions
Container images
34
deployed by those charts
Fix available
1 of 1
affected package

Netplex Json-smart Uncontrolled Recursion vulnerability

Carried by container images the latest versions of 34 of 17,781 indexed charts deploy, on 34 images.

Affected packageAffected versionsFixed inImages
json-smartmaven2.5.0, 2.5.12.5.234
OSV records
GHSA-pq2g-wx69-c263

Charts affected

34 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.11.1a7a2076b167e
json-smart@2.5.0
2.5.2

Open the chart page →

6,168
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
json-smart@2.5.1
2.5.2
apache/hertzbeat-collector:1.8.0a2bab1be574c
json-smart@2.5.1
2.5.2

Open the chart page →

14,000
hazelcasthazelcastVerified publisher5.10.21 of 2See more

hazelcast hazelcast 5.10.2

1 of the 2 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
json-smart@2.5.1
2.5.2

Open the chart page →

2,634
oesopsmxVerified publisher4.0.323 of 25See more

oes opsmx 4.0.32

3 of the 25 container images this version deploys carry CVE-2024-57699.

Open the chart page →

107,811
nifid4nVerified publisher2.0.01 of 5See more

nifi d4n 2.0.0

1 of the 5 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
json-smart@2.5.0
2.5.2

Open the chart page →

5,398
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
json-smart@2.5.0
2.5.2

Open the chart page →

52,635
atlas-cmmsf3k-techVerified publisher0.151.51 of 4See more

atlas-cmms f3k-tech 0.151.5

1 of the 4 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
json-smart@2.5.0
2.5.2

Open the chart page →

5,291
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
json-smart@2.5.1
2.5.2

Open the chart page →

12,019
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
json-smart@2.5.0
2.5.2

Open the chart page →

1,692
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
json-smart@2.5.1
2.5.2

Open the chart page →

31,844
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
json-smart@2.5.1
2.5.2

Open the chart page →

7,432
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
json-smart@2.5.0
2.5.2

Open the chart page →

854
zunivers-ninjaalexpressoVerified publisher1.31.21 of 2See more

zunivers-ninja alexpresso 1.31.2

1 of the 2 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
library/neo4j:5.18.18f01f7bb053e
json-smart@2.5.0
2.5.2

Open the chart page →

1,165
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
json-smart@2.5.0
2.5.2

Open the chart page →

1,073
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
json-smart@2.5.0
2.5.2

Open the chart page →

4,578
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
json-smart@2.5.0
2.5.2

Open the chart page →

5,398
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
json-smart@2.5.0
2.5.2

Open the chart page →

3,888
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
json-smart@2.5.0
2.5.2

Open the chart page →

49,025
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
json-smart@2.5.0
2.5.2

Open the chart page →

5,261
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
openbas/platform:2.0.5d986d80b0a75
json-smart@2.5.1
2.5.2

Open the chart page →

25,017
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
json-smart@2.5.1
2.5.2

Open the chart page →

5,320
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
json-smart@2.5.0
2.5.2

Open the chart page →

63,461
mock-oidclabs64io-helm-chartsVerified publisher0.1.01 of 1See more

mock-oidc labs64io-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
ghcr.io/navikt/mock-oauth2-server:2.1.1065d4ed47ce09
json-smart@2.5.1
2.5.2

Open the chart page →

703
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
json-smart@2.5.1
2.5.2

Open the chart page →

3,131
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
json-smart@2.5.0
2.5.2

Open the chart page →

30,363
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
json-smart@2.5.1
2.5.2

Open the chart page →

2,141
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
json-smart@2.5.1
2.5.2

Open the chart page →

5,826
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
json-smart@2.5.0
2.5.2

Open the chart page →

6,037
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
json-smart@2.5.0
2.5.2

Open the chart page →

2,024
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
json-smart@2.5.0
2.5.2

Open the chart page →

1,190
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
json-smart@2.5.0
2.5.2

Open the chart page →

1,753
rada-platformrada-platform0.1.02 of 7See more

rada-platform rada-platform 0.1.0

2 of the 7 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
json-smart@2.5.1
2.5.2
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
json-smart@2.5.0
2.5.2

Open the chart page →

21,211
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
json-smart@2.5.1
2.5.2

Open the chart page →

2,634
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2024-57699.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
json-smart@2.5.0
2.5.2

Open the chart page →

9,381

Container images carrying it

34 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/nifi-registry:1.26.07cdfd8deec92
json-smart@2.5.0
2.5.2
2
hazelcast/management-center:5.5.2991ddb27c251
json-smart@2.5.1
2.5.2
2
library/neo4j:5.20.052d3dec8d455
json-smart@2.5.0
2.5.2
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
json-smart@2.5.0
2.5.2
2
1dev/server:11.9.0cd5b12fe5471
json-smart@2.5.0
2.5.2
1
adityaprasadpathak/myapp:3.07e3b9777362c
json-smart@2.5.1
2.5.2
1
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
json-smart@2.5.0
2.5.2
1
apache/hertzbeat:1.8.075d48a62748f
json-smart@2.5.1
2.5.2
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
json-smart@2.5.1
2.5.2
1
apache/nifi-registry:1.27.063b8e3e40742
json-smart@2.5.1
2.5.2
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
json-smart@2.5.0
2.5.2
1
castlemock/castlemock:latestb7f3f1527ba9
json-smart@2.5.0
2.5.2
1
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
json-smart@2.5.0
2.5.2
1
gotson/komga:1.22.0ba892ab3e082
json-smart@2.5.1
2.5.2
1
graylog/graylog:6.1.1019de1aff48c2
json-smart@2.5.0
2.5.2
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
json-smart@2.5.0
2.5.2
1
library/neo4j:5.18.18f01f7bb053e
json-smart@2.5.0
2.5.2
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
json-smart@2.5.1
2.5.2
1
openbas/platform:2.0.5d986d80b0a75
json-smart@2.5.1
2.5.2
1
opennms/sentinel:36.0.288869082a14f
json-smart@2.5.0
2.5.2
1
opensearchproject/data-prepper:2.8.057c25fa01d3c
json-smart@2.5.0
2.5.2
1
opensearchproject/opensearch:2.15.01963b3ece46d
json-smart@2.5.0
2.5.2
1
opensearchproject/opensearch:2.14.0466a49f379bb
json-smart@2.5.0
2.5.2
1
opensearchproject/opensearch:2.12.0645d3d9390ad
json-smart@2.5.0
2.5.2
1
resurfaceio/resurface:3.7.84d5cda2f64109
json-smart@2.5.1
2.5.2
1
treskon/portrait:DEV-latest88e813f22347
json-smart@2.5.1
2.5.2
1
trinodb/trino:45038c6f24ab1a4
json-smart@2.5.1
2.5.2
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
json-smart@2.5.0
2.5.2
1
ghcr.io/navikt/mock-oauth2-server:2.1.1065d4ed47ce09
json-smart@2.5.1
2.5.2
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
json-smart@2.5.0
2.5.2
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
json-smart@2.5.1
2.5.2
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
json-smart@2.5.0
2.5.2
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
json-smart@2.5.0
2.5.2
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
json-smart@2.5.0
2.5.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.