StackRadar

CVE-2025-48924

Medium

Advisory

Published 11 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
627
of 17,787 indexed, latest versions
Container images
678
deployed by those charts
Fix available
2 of 3
affected packages

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Carried by container images the latest versions of 627 of 17,787 indexed charts deploy, on 678 images.

Affected packageAffected versionsFixed inImages
commons-lang3maven3.0, 3.1, 3.2, 3.2.1+17 more3.18.0594
commons-langmaven2.1, 2.2, 2.4, 2.5+1 moreno fix listed306
libcommons-lang3-javadeb3.8-23.8-2ubuntu0.1~esm11
OSV records
GHSA-j288-q9x7-2f5vUBUNTU-CVE-2025-48924
Also known as
USN-8364-1

Charts affected

627 by stars
ChartLatestAffected imagesRadar Score
jenkinsjenkinsciOfficialVerified publisher5.9.621See more

jenkins jenkinsci 5.9.62

1 container image this version deploys carries CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:2.568.3-jdk21c1e4c349365f
commons-lang@2.6
no fix listed

Open the chart page →

sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

6,556
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

7,713
jiraatlassian-data-centerVerified publisher2.0.151 of 2See more

jira atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
atlassian/jira-software:11.3.11e5548cd4eea8
commons-lang@2.4
no fix listed

Open the chart page →

1,490
trinotrino1.42.21 of 1See more

trino trino 1.42.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
trinodb/trino:4801565e8cac299
commons-lang@2.6
no fix listed

Open the chart page →

1,309
graylogkong-zVerified publisher3.0.321 of 5See more

graylog kong-z 3.0.32

1 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
graylog/graylog:7.2.0-beta.2-1e8431d59b84d
commons-lang@2.6
no fix listed

Open the chart page →

2,699
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

32,259
nacosygqygq2Verified publisher2.1.101 of 4See more

nacos ygqygq2 2.1.10

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.20e951a1d07bb
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0

Open the chart page →

4,983
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
commons-lang3@3.17.0
3.18.0

Open the chart page →

3,606
dependency-trackevryfs-ossVerified publisher1.5.51 of 3See more

dependency-track evryfs-oss 1.5.5

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
commons-lang3@3.12.0
3.18.0

Open the chart page →

2,503
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
commons-lang3@3.12.0
3.18.0

Open the chart page →

9,683
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
commons-lang3@3.12.0
3.18.0

Open the chart page →

11,933
milvusmilvus-helm5.0.281See more

milvus milvus-helm 5.0.28

1 container image this version deploys carries CVE-2025-48924.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

rocketmqrocketmq12.6.02 of 2See more

rocketmq rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
commons-lang3@3.12.0
3.18.0

Open the chart page →

6,328
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
commons-lang3@3.12.0
3.18.0

Open the chart page →

6,675
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
commons-lang3@3.17.0
3.18.0

Open the chart page →

1,444
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
commons-lang3@3.17.0
3.18.0
graviteeio/apim-management-api:4.12.19-debian27374522cd04
commons-lang3@3.17.0
3.18.0

Open the chart page →

4,806
polarisapache-polarisOfficialVerified publisher1.3.0-incubating1 of 1See more

polaris apache-polaris 1.3.0-incubating

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/polaris:lateste66366e783f1
commons-lang@2.6
no fix listed

Open the chart page →

455
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
commons-lang3@3.13.0
3.18.0

Open the chart page →

1,710
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
commons-lang@2.6
no fix listed

Open the chart page →

10,775
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

3,812
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
commons-lang3@3.12.0
3.18.0

Open the chart page →

7,857
kafkakubelauncherVerified publisher0.1.261 of 1See more

kafka kubelauncher 0.1.26

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned43e1085cd0a8
commons-lang3@3.12.0
3.18.0

Open the chart page →

1,360
neo4jneo4j-helm4.3.2-11 of 1See more

neo4j neo4j-helm 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
commons-lang3@3.9
3.18.0

Open the chart page →

2,640
sonarqube-ltssonarqubeVerified publisher1.0.16+981 of 4See more

sonarqube-lts sonarqube 1.0.16+98

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/sonarqube:8.9.2-community88cd63154d4b
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

4,099
metabasedeliveryheroVerified publisher0.14.41 of 1See more

metabase deliveryhero 0.14.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
commons-lang@2.4
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

2,572
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
commons-lang3@3.17.0
3.18.0

Open the chart page →

3,606
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
commons-lang3@3.12.0
3.18.0

Open the chart page →

5,357
grayloggroundhog2k0.13.101 of 1See more

graylog groundhog2k 0.13.10

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
graylog/graylog:7.1.9598bd41fefd5
commons-lang@2.6
no fix listed

Open the chart page →

1,074
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
commons-lang3@3.8.1
3.18.0

Open the chart page →

3,395
temporallemontechVerified publisher0.37.01 of 13See more

temporal lemontech 0.37.0

1 of the 13 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
commons-lang3@3.1
3.18.0

Open the chart page →

14,893
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

10,732
sparkmicrosoft1.0.42 of 3See more

spark microsoft 1.0.4

2 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
commons-lang@2.6
commons-lang3@3.5
no fix listed
3.18.0
dbanda/spark:2.4.6d0e6367876ae
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

13,738
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
commons-lang@2.6
commons-lang3@3.10
no fix listed
3.18.0

Open the chart page →

6,048
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
commons-lang3@3.4
3.18.0
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

14,184
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
commons-lang3@3.14.0
3.18.0

Open the chart page →

7,268
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
commons-lang3@3.9
3.18.0

Open the chart page →

2,283
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

12,111
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
commons-lang@2.6
no fix listed

Open the chart page →

1,500
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
commons-lang@2.5
commons-lang3@3.5
no fix listed
3.18.0

Open the chart page →

8,636
nexus-iq-serversonatypeVerified publisher207.1.01 of 1See more

nexus-iq-server sonatype 207.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
sonatype/nexus-iq-server:1.207.1a70014ed10b1
commons-lang@2.6
no fix listed

Open the chart page →

38
thehivestrangebee-helmOfficialVerified publisher1.0.63 of 7See more

thehive strangebee-helm 1.0.6

3 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
commons-lang3@3.11
3.18.0
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
commons-lang3@3.17.0
3.18.0
strangebee/thehive:5.7.6-1e77b713124dd
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

16,210
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.11.1a7a2076b167e
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

6,168
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
commons-lang@2.5
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

7,930
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
commons-lang3@3.12.0
3.18.0

Open the chart page →

27,267
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
commons-lang@2.6
no fix listed

Open the chart page →

13,953
guacamolehalkeye0.2.11 of 3See more

guacamole halkeye 0.2.1

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
guacamole/guacamole:1.1.0333a7f40c145
commons-lang3@3.9
3.18.0

Open the chart page →

4,839
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
apache/hertzbeat-collector:1.8.0a2bab1be574c
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0

Open the chart page →

14,000
kubernetes-loggingkubernetes-logging4.8.02 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

2 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0
opensearchproject/opensearch:2.10.0c8f3ebd2a934
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

10,530
musicocielmusicocielVerified publisher0.0.01 of 3See more

musicociel musicociel 0.0.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
commons-lang3@3.12.0
3.18.0

Open the chart page →

4,406

Container images carrying it

678 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
commons-lang3@3.12.0
3.18.0
1
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
commons-lang3@3.17.0
3.18.0
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
commons-lang3@3.9
3.18.0
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
commons-lang3@3.12.0
3.18.0
1
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
commons-lang3@3.12.0
3.18.0
1
quay.io/keycloak/keycloak:26.009a381c715ab
commons-lang3@3.14.0
3.18.0
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
quay.io/keycloak/keycloak:26.0.74388e2379b7e
commons-lang3@3.14.0
3.18.0
1
quay.io/keycloak/keycloak:24.0.34d6f22991266
commons-lang3@3.14.0
3.18.0
1
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
commons-lang3@3.12.0
3.18.0
1
quay.io/keycloak/keycloak:26.3.36a7217a100bd
commons-lang3@3.17.0
3.18.0
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
commons-lang3@3.14.0
3.18.0
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
commons-lang3@3.9
3.18.0
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
commons-lang@2.6
commons-lang3@3.7
no fix listed
3.18.0
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
commons-lang@2.6
commons-lang3@3.13.0
no fix listed
3.18.0
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
commons-lang3@3.13.0
3.18.0
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
commons-lang3@3.13.0
3.18.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
commons-lang3@3.8.1
3.18.0
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
commons-lang3@3.12.0
3.18.0
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
commons-lang3@3.9
3.18.0
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
commons-lang3@3.16.0
3.18.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.