StackRadar

CVE-2025-48924

Medium

Advisory

Published 11 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
631
of 17,781 indexed, latest versions
Container images
684
deployed by those charts
Fix available
2 of 3
affected packages

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Carried by container images the latest versions of 631 of 17,781 indexed charts deploy, on 684 images.

Affected packageAffected versionsFixed inImages
commons-lang3maven3.0, 3.1, 3.2, 3.2.1+17 more3.18.0599
commons-langmaven2.1, 2.2, 2.4, 2.5+1 moreno fix listed307
libcommons-lang3-javadeb3.8-23.8-2ubuntu0.1~esm11
OSV records
GHSA-j288-q9x7-2f5vUBUNTU-CVE-2025-48924
Also known as
USN-8364-1

Charts affected

631 by stars
ChartLatestAffected imagesRadar Score
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
commons-lang3@3.14.0
3.18.0

Open the chart page →

7,802
imageboxkyso1.0.01 of 1See more

imagebox kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
kyso/imagebox:latest68091eace89c
commons-lang@2.4
no fix listed

Open the chart page →

3,833
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
commons-lang@2.4
commons-lang3@3.3.2
no fix listed
3.18.0

Open the chart page →

26,356
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
commons-lang3@3.8.1
3.18.0

Open the chart page →

2,427
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
commons-lang@2.6
no fix listed

Open the chart page →

4,423
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
commons-lang3@3.17.0
3.18.0

Open the chart page →

3,131
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
commons-lang3@3.12.0
3.18.0

Open the chart page →

6,634
kafka-connect-wrapperlsmhun0.1.01 of 1See more

kafka-connect-wrapper lsmhun 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
commons-lang3@3.8.1
3.18.0

Open the chart page →

2,391
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

7,929
elastictranscoderluiscajl0.46.01 of 4See more

elastictranscoder luiscajl 0.46.0

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
elastictranscoder/transcoder:627e21dcb4a0327029e6
commons-lang3@3.12.0
3.18.0

Open the chart page →

58,160
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
commons-lang3@3.11
3.18.0

Open the chart page →

24,400
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
hugohg34/planner:0.0.2171f61e8d7e2
commons-lang3@3.12.0
3.18.0

Open the chart page →

29,588
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0

Open the chart page →

2,589
activemqmicroboxlabs3.8.01 of 1See more

activemq microboxlabs 3.8.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
commons-lang3@3.14.0
3.18.0

Open the chart page →

1,494
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
commons-lang3@3.9
3.18.0

Open the chart page →

4,257
miot-modulithmicroboxlabs0.6.01 of 1See more

miot-modulith microboxlabs 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
commons-lang@2.6
no fix listed

Open the chart page →

1,414
modulariotmicroboxlabs0.9.01 of 4See more

modulariot microboxlabs 0.9.0

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
commons-lang@2.6
no fix listed

Open the chart page →

2,256
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

4,599
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
commons-lang3@3.12.0
3.18.0

Open the chart page →

12,847
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
commons-lang3@3.12.0
3.18.0

Open the chart page →

11,188
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
commons-lang@2.6
commons-lang3@3.7
no fix listed
3.18.0

Open the chart page →

15,855
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
commons-lang3@3.4
3.18.0

Open the chart page →

43,341
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

10,603
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

3,083
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
commons-lang3@3.8.1
3.18.0

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
commons-lang3@3.8.1
3.18.0

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
commons-lang3@3.8.1
3.18.0

Open the chart page →

12,108
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
commons-lang3@3.8.1
3.18.0

Open the chart page →

16,198
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
commons-lang3@3.8.1
3.18.0

Open the chart page →

11,479
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
commons-lang3@3.8.1
3.18.0

Open the chart page →

19,226
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
commons-lang3@3.14.0
3.18.0

Open the chart page →

30,363
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

15,675
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
commons-lang@2.6
commons-lang3@3.8
no fix listed
3.18.0

Open the chart page →

5,663
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
commons-lang3@3.14.0
3.18.0

Open the chart page →

2,141
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
commons-lang3@3.9
3.18.0

Open the chart page →

9,149
Practica_4_helmmy-heml-appVerified publisher0.1.01 of 7See more

Practica_4_helm my-heml-app 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
adagber/planner:v1.0e5c1ed097752
commons-lang3@3.12.0
3.18.0

Open the chart page →

27,721
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0

Open the chart page →

1,783
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ncsa/datawolf:4.7.0af6649d59150
commons-lang3@3.12.0
3.18.0

Open the chart page →

4,989
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
commons-lang3@3.14.0
3.18.0

Open the chart page →

15,369
polyglotncsaVerified publisher0.1.114 of 18See more

polyglot ncsa 0.1.1

14 of the 18 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
commons-lang@2.5
commons-lang3@3.4
no fix listed
3.18.0
ncsapolyglot/converters-avconv:latestc44b22eb58bb
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-ffmpeg:latest48c852c1204b
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-flac:latest072cf5bc6f99
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-gdal:latestf746049515c1
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-ghostscript:latestf350da56dd55
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-htmldoc:latest317dd9e56922
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-imagemagick:latestd244ea8c32ac
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-txt2html:latest30ee96508c0b
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
commons-lang3@3.4
3.18.0
ncsapolyglot/converters-zip:latestf889fe30e2c7
commons-lang3@3.4
3.18.0
ncsapolyglot/polyglot:2.4.097a8c01c076e
commons-lang3@3.4
3.18.0

Open the chart page →

55,726
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
commons-lang3@3.9
3.18.0

Open the chart page →

2,640
ma1sdnetsocVerified publisher0.2.11 of 1See more

ma1sd netsoc 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

3,582
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
commons-lang3@3.12.0
3.18.0

Open the chart page →

5,875
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
commons-lang3@3.8.1
3.18.0

Open the chart page →

4,547
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
commons-lang3@3.12.0
3.18.0

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
commons-lang3@3.12.0
3.18.0

Open the chart page →

5,916

Container images carrying it

684 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
commons-lang3@3.14.0
3.18.0
1
airbyte/cron:0.40.17caf4f551c546
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
airbyte/cron:2.2.0d97b67a1346d
commons-lang3@3.14.0
3.18.0
1
airbyte/worker:2.2.08060b88b29c8
commons-lang3@3.14.0
3.18.0
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
aktosecurity/akto-api-protection:localbcd7382c9c1b
commons-lang3@3.12.0
3.18.0
1
aktosecurity/data-ingestion-service213aded7adc5
commons-lang3@3.8.1
3.18.0
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-lang3@3.8.1
3.18.0
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
commons-lang3@3.13.0
3.18.0
1
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
commons-lang3@3.12.0
3.18.0
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
commons-lang3@3.14.0
3.18.0
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0
1
andrianrf/backoffice-be:latest6036614803d4
commons-lang3@3.12.0
3.18.0
1
andrianrf/iso-client:latestba560086ce15
commons-lang3@3.12.0
3.18.0
1
andrianrf/iso-server:latest7da47f525c7d
commons-lang3@3.12.0
3.18.0
1
anguda/ant-media:2.5c435285fc241
commons-lang3@3.9
3.18.0
1
apache/activemq-artemis:2.37.0bae523439ee3
commons-lang3@3.16.0
3.18.0
1
apache/bookkeeper:4.14.5a7d9970c148f
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
1
apache/camel-k:1.10.43bb13d14f64a
commons-lang3@3.8.1
3.18.0
1
apache/drill:1.21.11f96558fd292
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0
1
apache/druid:29.0.10cef139b6bf1
commons-lang@2.5
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/hadoop:3af361b20bec0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/hertzbeat:1.8.075d48a62748f
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
apacheignite/ignite:2.7.0d7deab68b8fa
commons-lang@2.6
no fix listed
1
apache/iotdb:0.11.28647309f95d1
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
apache/iotdb:0.13.3-nodeafa47bf1692a
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
apache/kafka:3.9.0fbc7d7c428e3
commons-lang3@3.12.0
3.18.0
1
apache/nifi-registry:1.14.0090b7f87ec7f
commons-lang3@3.5
3.18.0
1
apache/nifi-registry:1.27.063b8e3e40742
commons-lang3@3.14.0
3.18.0
1
apache/nifi-registry:0.8.0974efa2f21da
commons-lang3@3.5
3.18.0
1
apachepinot/pinot:latest-jdk110018bb04ced7
commons-lang@2.6
commons-lang3@3.5
no fix listed
3.18.0
1
apache/polaris:lateste66366e783f1
commons-lang@2.6
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
1
apachepulsar/pulsar:3.0.79c9947de139d
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.9.0d056c89b7131
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.8.2d538416d5afe
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apache/ranger:2.7.076c176e8a0e4
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
apache/rocketmq:5.3.0434d8398f996
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/rocketmq:4.9.35ac2a4e0f627
commons-lang3@3.4
3.18.0
1
apache/rocketmq-exporter:0.0.2c8fb51195444
commons-lang3@3.12.0
3.18.0
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
commons-lang3@3.4
3.18.0
1
apache/shenyu-admin:2.5.1e2be712fc4f4
commons-lang3@3.12.0
3.18.0
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apache/skywalking-oap-server:9.2.0133d35d2c263
commons-lang3@3.12.0
3.18.0
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
commons-lang@2.4
commons-lang3@3.7
no fix listed
3.18.0
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
commons-lang3@3.12.0
3.18.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.