StackRadar

CVE-2025-11143

Low

Advisory

Published 5 Mar 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
245
of 17,781 indexed, latest versions
Container images
226
deployed by those charts
Fix available
1 of 1
affected package

org.eclipse.jetty:jetty-http has different parsing of invalid URIs

Carried by container images the latest versions of 245 of 17,781 indexed charts deploy, on 226 images.

Affected packageAffected versionsFixed inImages
jetty-httpmaven9.4.0.v20161208, 9.4.5.v20170502, 9.4.6.v20170531, 9.4.7.v20170914+65 more12.0.31, 12.1.5226
OSV records
GHSA-wjpw-4j6x-6rwh

Charts affected

245 by stars
ChartLatestAffected imagesRadar Score
tsoragecetic0.4.112 of 8See more

tsorage cetic 0.4.11

2 of the 8 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
jetty-http@9.4.11.v20180605
no fix listed
library/zookeeper:3.5.5b7a76ec06f68
jetty-http@9.4.17.v20190418
no fix listed

Open the chart page →

12,018
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jetty-http@9.4.6.v20170531
no fix listed

Open the chart page →

5,078
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
jetty-http@9.4.14.v20181114
no fix listed

Open the chart page →

9,144
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
jetty-http@9.4.11.v20180605
no fix listed

Open the chart page →

4,601
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
jetty-http@9.4.11.v20180605
no fix listed

Open the chart page →

2,837
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
jetty-http@9.4.8.v20171121
no fix listed

Open the chart page →

7,226
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
jetty-http@9.4.11.v20180605
no fix listed

Open the chart page →

23,665
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
jetty-http@9.4.12.v20180830
no fix listed

Open the chart page →

11,782
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
jetty-http@10.0.12
no fix listed

Open the chart page →

2,503
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
jetty-http@9.4.29.v20200521
no fix listed
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jetty-http@9.4.10.v20180503
no fix listed

Open the chart page →

16,860
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
jetty-http@9.4.44.v20210927
no fix listed

Open the chart page →

5,958
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jetty-http@9.4.33.v20201020
no fix listed
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jetty-http@9.4.33.v20201020
no fix listed
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jetty-http@9.4.33.v20201020
no fix listed
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jetty-http@9.4.33.v20201020
no fix listed
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jetty-http@9.4.33.v20201020
no fix listed
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jetty-http@9.4.33.v20201020
no fix listed
confluentinc/cp-zookeeper:6.1.078c190f4472c
jetty-http@9.4.33.v20201020
no fix listed

Open the chart page →

58,857
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
jetty-http@9.4.54.v20240208
no fix listed

Open the chart page →

5,398
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
jetty-http@9.4.25.v20191220
no fix listed

Open the chart page →

8,986
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
jetty-http@9.4.12.v20180830
no fix listed

Open the chart page →

11,782
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
jetty-http@9.4.20.v20190813
no fix listed

Open the chart page →

19,802
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jetty-http@9.4.51.v20230217
no fix listed

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jetty-http@9.4.51.v20230217
no fix listed

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jetty-http@9.4.51.v20230217
no fix listed

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
jetty-http@9.4.51.v20230217
no fix listed

Open the chart page →

4,033
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
jetty-http@10.0.22
no fix listed

Open the chart page →

12,454
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
jetty-http@9.4.49.v20220914
no fix listed

Open the chart page →

24,296
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
jetty-http@9.4.57.v20241219
no fix listed

Open the chart page →

3,463
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
jetty-http@9.4.39.v20210325
no fix listed

Open the chart page →

1,874
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
jetty-http@9.4.39.v20210325
no fix listed

Open the chart page →

1,760
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
jetty-http@9.4.39.v20210325
no fix listed

Open the chart page →

1,733
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
jetty-http@9.4.39.v20210325
no fix listed

Open the chart page →

1,733
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
jetty-http@9.4.39.v20210325
no fix listed

Open the chart page →

1,733
accumulogaffer2.2.13 of 4See more

accumulo gaffer 2.2.1

3 of the 4 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
jetty-http@9.4.43.v20210629
no fix listed
gchq/hdfs:3.3.35ec58edbb2db
jetty-http@9.4.43.v20210629
no fix listed
library/zookeeper:3.5.5b7a76ec06f68
jetty-http@9.4.17.v20190418
no fix listed

Open the chart page →

16,892
gaffer-road-trafficgaffer2.2.12 of 8See more

gaffer-road-traffic gaffer 2.2.1

2 of the 8 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
jetty-http@9.4.43.v20210629
no fix listed
library/zookeeper:3.5.5b7a76ec06f68
jetty-http@9.4.17.v20190418
no fix listed

Open the chart page →

9,342
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jetty-http@9.4.53.v20231009
no fix listed

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
jetty-http@9.4.53.v20231009
no fix listed

Open the chart page →

11,961
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
jetty-http@9.4.43.v20210629
no fix listed

Open the chart page →

2,887
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
jetty-http@9.4.36.v20210114
no fix listed

Open the chart page →

26,944
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
no fix listed

Open the chart page →

4,547
zookeepergengxiankun-charts0.2.01 of 1See more

zookeeper gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
library/zookeeper:3.6.24c8a6d3b2338
jetty-http@9.4.24.v20191120
no fix listed

Open the chart page →

1,913
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.82 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

2 of the 5 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
jetty-http@9.4.11.v20180605
no fix listed
jingking/geonetwork-hnap:4.2.843e74ab234e1
jetty-http@9.4.18.v20190429
no fix listed

Open the chart page →

34,754
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jetty-http@9.4.53.v20231009
no fix listed

Open the chart page →

49,025
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
jetty-http@9.4.11.v20180605
no fix listed

Open the chart page →

15,722
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
jetty-http@9.4.51.v20230217
no fix listed

Open the chart page →

4,556
ubooquityhalkeye0.1.11 of 1See more

ubooquity halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-http@9.4.0.v20161208
no fix listed

Open the chart page →

4,303
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
jetty-http@9.4.43.v20210629
no fix listed

Open the chart page →

6,102
hbasehbase0.1.72 of 4See more

hbase hbase 0.1.7

2 of the 4 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jetty-http@9.4.46.v20220331
no fix listed
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jetty-http@9.4.43.v20210629
no fix listed

Open the chart page →

10,540
helm-airportshelm-airports0.1.01 of 7See more

helm-airports helm-airports 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
no fix listed

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
no fix listed

Open the chart page →

4,547
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
no fix listed

Open the chart page →

5,573
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jetty-http@9.4.43.v20210629
no fix listed

Open the chart page →

4,547
metabasehelm-charts-nr0.14.41 of 1See more

metabase helm-charts-nr 0.14.4

1 of the 1 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
jetty-http@9.4.48.v20220622
no fix listed

Open the chart page →

2,572
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
jetty-http@9.4.20.v20190813
no fix listed

Open the chart page →

2,140
cruise-controlhelm-cruise-controlVerified publisher2.1.11 of 2See more

cruise-control helm-cruise-control 2.1.1

1 of the 2 container images this version deploys carry CVE-2025-11143.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
jetty-http@9.4.56.v20240826
no fix listed

Open the chart page →

1,453

Container images carrying it

226 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
jetty-http@9.4.56.v20240826
no fix listed
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jetty-http@9.4.46.v20220331
no fix listed
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jetty-http@9.4.43.v20210629
no fix listed
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jetty-http@9.4.30.v20200611
no fix listed
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
jetty-http@9.4.7.v20170914
no fix listed
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
jetty-http@11.0.26
no fix listed
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
jetty-http@9.4.56.v20240826
no fix listed
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
jetty-http@9.4.56.v20240826
no fix listed
1
ghcr.io/kubelauncher/zookeeper7826e9caa461
jetty-http@9.4.56.v20240826
no fix listed
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jetty-http@9.4.43.v20210629
no fix listed
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
jetty-http@9.4.7.v20170914
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
jetty-http@9.4.53.v20231009
no fix listed
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
jetty-http@9.4.43.v20210629
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
jetty-http@9.4.53.v20231009
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
jetty-http@9.4.53.v20231009
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
jetty-http@10.0.20
no fix listed
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-http@9.4.12.v20180830
no fix listed
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
jetty-http@9.4.12.v20180830
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jetty-http@9.4.44.v20210927
no fix listed
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
jetty-http@12.0.25
12.0.31
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
jetty-http@9.4.51.v20230217
no fix listed
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
jetty-http@12.0.16
12.0.31
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
jetty-http@9.4.48.v20220622
no fix listed
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jetty-http@9.4.11.v20180605
no fix listed
1
quay.io/strimzi/operator:0.45.158c727cd2e68
jetty-http@9.4.57.v20241219
no fix listed
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
jetty-http@9.4.51.v20230217
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.