StackRadar

CVE-2025-48924

Medium

Advisory

Published 11 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
633
of 17,790 indexed, latest versions
Container images
685
deployed by those charts
Fix available
2 of 3
affected packages

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Carried by container images the latest versions of 633 of 17,790 indexed charts deploy, on 685 images.

Affected packageAffected versionsFixed inImages
commons-lang3maven3.0, 3.1, 3.2, 3.2.1+17 more3.18.0599
commons-langmaven2.1, 2.2, 2.4, 2.5+1 moreno fix listed309
libcommons-lang3-javadeb3.8-23.8-2ubuntu0.1~esm11
OSV records
GHSA-j288-q9x7-2f5vUBUNTU-CVE-2025-48924
Also known as
USN-8364-1

Charts affected

633 by stars
ChartLatestAffected imagesRadar Score
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
commons-lang3@3.12.0
3.18.0

Open the chart page →

6,878
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
commons-lang3@3.12.0
3.18.0

Open the chart page →

5,942
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
commons-lang3@3.12.0
3.18.0

Open the chart page →

5,899
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
commons-lang@2.6
no fix listed

Open the chart page →

41,444
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
commons-lang3@3.9
3.18.0

Open the chart page →

3,635
nexus2novum-rgi-charts0.1.11 of 1See more

nexus2 novum-rgi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
sonatype/nexus:oss6bc88b51d4d7
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

3,220
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

5,826
ojp-serverojp0.1.51 of 1See more

ojp-server ojp 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rrobetti/ojp:0.1.0-beta1141bd88232b
commons-lang3@3.5
3.18.0

Open the chart page →

2,631
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

8,547
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

9,062
apicurioone-acre-fundVerified publisher2.3.03 of 5See more

apicurio one-acre-fund 2.3.0

3 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
commons-lang@2.6
commons-lang3@3.13.0
no fix listed
3.18.0
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
commons-lang3@3.12.0
3.18.0
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
commons-lang3@3.12.0
3.18.0

Open the chart page →

18,667
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

6,096
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vespaengine/vespa:8.526.1569b160f58211
commons-lang3@3.16.0
3.18.0

Open the chart page →

6,392
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
commons-lang@2.6
no fix listed

Open the chart page →

2,422
mockserveropen-charts1.1.01 of 1See more

mockserver open-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
mockserver/mockserver:5.15.00f9ef78c9489
commons-lang3@3.12.0
3.18.0

Open the chart page →

1,258
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
commons-lang3@3.5
3.18.0

Open the chart page →

63,280
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

88,653
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
woojoong/wowza:latestec230db19652
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

42,655
omec-control-planeopencord0.1.312 of 8See more

omec-control-plane opencord 0.1.31

2 of the 8 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/cassandra:2.1.20cb079c0d7a57
commons-lang3@3.1
3.18.0
omecproject/c3po-hssdb:master-latest28a90cc26716
commons-lang3@3.1
3.18.0

Open the chart page →

40,825
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0

Open the chart page →

12,942
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

38,902
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
atomix/atomix:3.1.127738ff4f5c63
commons-lang3@3.7
3.18.0
voltha/voltha-onos:5.1.8e038acb950d3
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

41,101
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
commons-lang@2.6
commons-lang3@3.16.0
no fix listed
3.18.0

Open the chart page →

2,064
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
andrianrf/backoffice-be:latest6036614803d4
commons-lang3@3.12.0
3.18.0
andrianrf/iso-client:latestba560086ce15
commons-lang3@3.12.0
3.18.0
andrianrf/iso-server:latest7da47f525c7d
commons-lang3@3.12.0
3.18.0

Open the chart page →

35,116
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
commons-lang3@3.17.0
3.18.0

Open the chart page →

7,866
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,612
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,573
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,556
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,460
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,105
openwhiskopenwhisk1.0.02 of 10See more

openwhisk openwhisk 1.0.0

2 of the 10 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/zookeeper:3.43882d9493d38
commons-lang@2.6
no fix listed
openwhisk/invoker:1.0.0f5831ec85525
commons-lang3@3.8.1
3.18.0

Open the chart page →

36,252
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
commons-lang3@3.17.0
3.18.0

Open the chart page →

2,005
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
commons-lang3@3.8.1
3.18.0

Open the chart page →

26,364
trinoopstty0.2.141 of 1See more

trino opstty 0.2.14

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
trinodb/trino:4815b5e0a97f599
commons-lang@2.6
no fix listed

Open the chart page →

1,158
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
commons-lang@2.6
commons-lang3@3.13.0
no fix listed
3.18.0

Open the chart page →

72,547
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

1,754
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
commons-lang3@3.12.0
3.18.0

Open the chart page →

27,702
keycloakpascaliskeVerified publisher0.2.01 of 1See more

keycloak pascaliske 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.74388e2379b7e
commons-lang3@3.14.0
3.18.0

Open the chart page →

2,097
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

6,237
spring-boot-openshiftpiominVerified publisher0.3.111 of 1See more

spring-boot-openshift piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
commons-lang3@3.12.0
3.18.0

Open the chart page →

7,622
jmxproxypndaproject0.1.01 of 1See more

jmxproxy pndaproject 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gradiant/jmxproxy:3.4.045eceb1bc55c
commons-lang3@3.6
3.18.0

Open the chart page →

4,178
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
pcarrascoponce/planner:v1.0981fc482442c
commons-lang3@3.12.0
3.18.0

Open the chart page →

27,659
flink-kubernetes-operatorpresto-loadbalancer1.10.01 of 1See more

flink-kubernetes-operator presto-loadbalancer 1.10.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
commons-lang3@3.16.0
3.18.0

Open the chart page →

3,319
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
commons-lang@2.6
commons-lang3@3.2
no fix listed
3.18.0

Open the chart page →

9,613
trinopresto-loadbalancer0.2.101 of 2See more

trino presto-loadbalancer 0.2.10

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
trinodb/trino:4796af989b0846d
commons-lang@2.6
no fix listed

Open the chart page →

2,264
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
commons-lang3@3.12.0
3.18.0

Open the chart page →

1,996
jenkinsquench-jenkinsVerified publisher0.0.81 of 1See more

jenkins quench-jenkins 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/jenkinsdigest-pinnede92dba4e78c5
commons-lang@2.6
no fix listed

Open the chart page →

79
rada-platformrada-platform0.1.02 of 7See more

rada-platform rada-platform 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
commons-lang3@3.14.0
3.18.0

Open the chart page →

21,291

Container images carrying it

685 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
commons-lang3@3.12.0
3.18.0
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
commons-lang@2.6
commons-lang3@3.10
no fix listed
3.18.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
commons-lang@2.6
no fix listed
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
commons-lang@2.6
no fix listed
1
ghcr.io/openccu/openccu:3.89.9.20260914eaeefd355dca
commons-lang@2.6
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
commons-lang3@3.8.1
3.18.0
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
commons-lang3@3.13.0
3.18.0
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
commons-lang3@3.14.0
3.18.0
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
commons-lang3@3.12.0
3.18.0
1
ghcr.io/quenchworks/images/jenkinse92dba4e78c5
commons-lang@2.6
no fix listed
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
commons-lang3@3.2.1
3.18.0
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
commons-lang3@3.17.0
3.18.0
1
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
commons-lang3@3.12.0
3.18.0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
commons-lang3@3.4
3.18.0
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime4d3a8042c761
commons-lang3@3.13.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
commons-lang3@3.13.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
commons-lang3@3.13.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.54.4_localb2b97137aef5
commons-lang3@3.13.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
commons-lang3@3.12.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
commons-lang3@3.12.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:improve-testing-performance8e9d15ed71c7
commons-lang3@3.12.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestfacdfba6d4e4
commons-lang3@3.12.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
commons-lang3@3.17.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
commons-lang3@3.12.0
3.18.0
1
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
commons-lang3@3.17.0
3.18.0
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
commons-lang3@3.17.0
3.18.0
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
commons-lang3@3.17.0
3.18.0
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
commons-lang3@3.12.0
3.18.0
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
commons-lang3@3.9
3.18.0
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
commons-lang3@3.9
3.18.0
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
commons-lang3@3.9
3.18.0
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
commons-lang3@3.9
3.18.0
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
commons-lang3@3.12.0
3.18.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.