StackRadar

CVE-2025-48924

Medium

Advisory

Published 11 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
623
of 17,787 indexed, latest versions
Container images
676
deployed by those charts
Fix available
2 of 3
affected packages

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Carried by container images the latest versions of 623 of 17,787 indexed charts deploy, on 676 images.

Affected packageAffected versionsFixed inImages
commons-lang3maven3.0, 3.1, 3.2, 3.2.1+17 more3.18.0593
commons-langmaven2.1, 2.2, 2.4, 2.5+1 moreno fix listed305
libcommons-lang3-javadeb3.8-23.8-2ubuntu0.1~esm11
OSV records
GHSA-j288-q9x7-2f5vUBUNTU-CVE-2025-48924
Also known as
USN-8364-1

Charts affected

623 by stars
ChartLatestAffected imagesRadar Score
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
commons-lang3@3.12.0
3.18.0

Open the chart page →

2,453
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

5,277
apimap-apiapimapOfficialVerified publisher1.8.111 of 1See more

apimap-api apimap 1.8.11

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apimap/api:v1.8.11ae2b3ab00177
commons-lang3@3.12.0
3.18.0

Open the chart page →

2,231
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
commons-lang3@3.11
3.18.0
opensearchproject/opensearch:2.1.04254021a8c71
commons-lang@2.6
commons-lang3@3.10
no fix listed
3.18.0

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.03 of 4See more

james-kompose appscode 0.1.0

3 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
commons-lang3@3.11
3.18.0
opensearchproject/opensearch:2.1.04254021a8c71
commons-lang@2.6
commons-lang3@3.10
no fix listed
3.18.0
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

16,975
platform-apiappscodeVerified publisher2026.9.111 of 3See more

platform-api appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
commons-lang3@3.12.0
3.18.0

Open the chart page →

37,268
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
commons-lang@2.6
commons-lang3@3.10
no fix listed
3.18.0

Open the chart page →

8,866
arlas-aiasarlas-stackVerified publisher28.8.02 of 22See more

arlas-aias arlas-stack 28.8.0

2 of the 22 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
commons-lang3@3.9
3.18.0
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
commons-lang3@3.17.0
3.18.0

Open the chart page →

40,238
automatedconfigurationassist-iot-automated-configuration1.0.03 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

3 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
commons-lang3@3.8.1
3.18.0
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
commons-lang3@3.8.1
3.18.0
provectuslabs/kafka-ui:latest8f2ff02d64b0
commons-lang3@3.12.0
3.18.0

Open the chart page →

14,728
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

13,352
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

7,936
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
commons-lang@2.4
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

4,145
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
commons-lang3@3.12.0
3.18.0

Open the chart page →

9,412
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-lang3@3.12.0
3.18.0

Open the chart page →

9,722
keycloakbarravarVerified publisher1.0.41 of 1See more

keycloak barravar 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:24.0.34d6f22991266
commons-lang3@3.14.0
3.18.0

Open the chart page →

2,381
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0

Open the chart page →

5,806
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
commons-lang3@3.14.0
3.18.0

Open the chart page →

4,292
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
commons-lang3@3.12.0
3.18.0

Open the chart page →

13,459
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
commons-lang3@3.17.0
3.18.0

Open the chart page →

1,816
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
commons-lang3@3.17.0
3.18.0

Open the chart page →

26,996
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
commons-lang3@3.11
3.18.0
library/cassandra:3.11.65aa8400b4b3b
commons-lang3@3.1
3.18.0

Open the chart page →

19,229
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
commons-lang@2.6
commons-lang3@3.13.0
no fix listed
3.18.0

Open the chart page →

8,323
gotenbergbysamioVerified publisher0.2.01 of 1See more

gotenberg bysamio 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8-chromiuma40f92d7419a
commons-lang3@3.12.0
3.18.0

Open the chart page →

8,978
geoservercamptocamp20.0.36 of 12See more

geoserver camptocamp2 0.0.3

6 of the 12 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
commons-lang@2.6
no fix listed
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
commons-lang@2.5
commons-lang3@3.10
no fix listed
3.18.0
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
commons-lang@2.5
commons-lang3@3.10
no fix listed
3.18.0
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
commons-lang@2.5
commons-lang3@3.10
no fix listed
3.18.0
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
commons-lang@2.5
commons-lang3@3.10
no fix listed
3.18.0
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
commons-lang@2.5
commons-lang3@3.10
no fix listed
3.18.0

Open the chart page →

88,335
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

5,886
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

1,073
metabasecasemark2.16.111 of 1See more

metabase casemark 2.16.11

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

1,215
cassandra-clustercassandra-clusterVerified publisher0.1.01 of 1See more

cassandra-cluster cassandra-cluster 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/cassandra:3.11.10b095ff3248c6
commons-lang3@3.1
3.18.0

Open the chart page →

9,473
temporalcastaiVerified publisher0.54.21 of 14See more

temporal castai 0.54.2

1 of the 14 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
commons-lang3@3.1
3.18.0

Open the chart page →

16,198
tsoragecetic0.4.112 of 8See more

tsorage cetic 0.4.11

2 of the 8 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
commons-lang3@3.1
3.18.0
library/cassandra:3.11.598531a31f213
commons-lang3@3.1
3.18.0

Open the chart page →

12,018
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
commons-lang@2.6
no fix listed

Open the chart page →

9,808
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
commons-lang3@3.9
3.18.0

Open the chart page →

6,447
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
commons-lang3@3.1
3.18.0

Open the chart page →

5,078
cosbenchcloudnativeapp1.0.11 of 1See more

cosbench cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
zenko/zenko-cosbench:0.0.6386a1f48ec0e
commons-lang@2.5
no fix listed

Open the chart page →

4,906
gocdcloudnativeapp1.9.22 of 2See more

gocd cloudnativeapp 1.9.2

2 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
commons-lang3@3.8.1
3.18.0
gocd/gocd-server:v19.3.02da45cb09d57
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

9,144
hazelcastcloudnativeapp1.3.11 of 1See more

hazelcast cloudnativeapp 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
hazelcast/hazelcast:3.11.2ca7d5589744f
commons-lang@2.6
no fix listed

Open the chart page →

4,982
hazelcast-jetcloudnativeapp1.1.01 of 1See more

hazelcast-jet cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:3.0df495e64ea65
commons-lang@2.6
no fix listed

Open the chart page →

5,326
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
commons-lang@2.6
commons-lang3@3.7
no fix listed
3.18.0

Open the chart page →

2,837
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

7,226
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
commons-lang@2.6
no fix listed

Open the chart page →

6,497
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
commons-lang@2.6
no fix listed

Open the chart page →

23,665
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
commons-lang@2.6
commons-lang3@3.5
no fix listed
3.18.0

Open the chart page →

14,066
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
commons-lang@2.6
no fix listed

Open the chart page →

22,442
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0

Open the chart page →

7,168
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0

Open the chart page →

5,238
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

4,578
clamapicnieg2.0.51 of 2See more

clamapi cnieg 2.0.5

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
audig/clamapi:2.1.62c3fe34ee430
commons-lang3@3.10
3.18.0

Open the chart page →

4,671
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
commons-lang3@3.12.0
3.18.0

Open the chart page →

2,503
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
commons-lang@2.6
commons-lang3@3.7
no fix listed
3.18.0

Open the chart page →

16,860
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
commons-lang3@3.8.1
3.18.0

Open the chart page →

5,958

Container images carrying it

676 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
commons-lang3@3.8.1
3.18.0
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
commons-lang3@3.13.0
3.18.0
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
commons-lang3@3.14.0
3.18.0
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
commons-lang3@3.12.0
3.18.0
1
ghcr.io/quenchworks/images/jenkinse92dba4e78c5
commons-lang@2.6
no fix listed
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
commons-lang3@3.2.1
3.18.0
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
commons-lang3@3.17.0
3.18.0
1
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
commons-lang3@3.12.0
3.18.0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
commons-lang3@3.4
3.18.0
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime4d3a8042c761
commons-lang3@3.13.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
commons-lang3@3.13.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
commons-lang3@3.13.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.54.4_localb2b97137aef5
commons-lang3@3.13.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
commons-lang3@3.12.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:improve-testing-performance8e9d15ed71c7
commons-lang3@3.12.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestfacdfba6d4e4
commons-lang3@3.12.0
3.18.0
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
commons-lang3@3.12.0
3.18.0
1
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
commons-lang3@3.17.0
3.18.0
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
commons-lang3@3.17.0
3.18.0
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
commons-lang3@3.17.0
3.18.0
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
commons-lang3@3.12.0
3.18.0
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
commons-lang3@3.9
3.18.0
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
commons-lang3@3.9
3.18.0
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
commons-lang3@3.9
3.18.0
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
commons-lang3@3.9
3.18.0
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
commons-lang3@3.12.0
3.18.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.