StackRadar

CVE-2025-1247

High

Advisory

Published 13 Feb 2025In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
5
deployed by those charts
Fix available
2 of 2
affected packages

Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.

Affected packageAffected versionsFixed inImages
quarkus-restmaven3.11.1, 3.12.2, 3.15.13.15.3.15
quarkus-rest-deploymentmaven3.11.1, 3.15.13.15.3.14
OSV records
GHSA-phg3-gv66-q38x

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
damap-chartdamapVerified publisher0.3.01 of 5See more

damap-chart damap 0.3.0

1 of the 5 container images this version deploys carry CVE-2025-1247.

Container imageDigestPackageFixed in
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
quarkus-rest@3.11.1
quarkus-rest-deployment@3.11.1
3.15.3.1
3.15.3.1

Open the chart page →

13,936
keycloakpascaliskeVerified publisher0.2.01 of 1See more

keycloak pascaliske 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-1247.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.74388e2379b7e
quarkus-rest@3.15.1
quarkus-rest-deployment@3.15.1
3.15.3.1
3.15.3.1

Open the chart page →

2,097
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-1247.

Container imageDigestPackageFixed in
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
quarkus-rest@3.12.2
3.15.3.1

Open the chart page →

21,211
keycloaksb-helm-charts0.3.01 of 2See more

keycloak sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-1247.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
quarkus-rest@3.15.1
quarkus-rest-deployment@3.15.1
3.15.3.1
3.15.3.1

Open the chart page →

2,590
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2025-1247.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.009a381c715ab
quarkus-rest@3.15.1
quarkus-rest-deployment@3.15.1
3.15.3.1
3.15.3.1

Open the chart page →

5,063

Container images carrying it

5 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
quarkus-rest@3.11.1
quarkus-rest-deployment@3.11.1
3.15.3.1
3.15.3.1
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
quarkus-rest@3.12.2
3.15.3.1
1
quay.io/keycloak/keycloak:26.009a381c715ab
quarkus-rest@3.15.1
quarkus-rest-deployment@3.15.1
3.15.3.1
3.15.3.1
1
quay.io/keycloak/keycloak:26.0.74388e2379b7e
quarkus-rest@3.15.1
quarkus-rest-deployment@3.15.1
3.15.3.1
3.15.3.1
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
quarkus-rest@3.15.1
quarkus-rest-deployment@3.15.1
3.15.3.1
3.15.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.