StackRadar

CVE-2025-48924

Medium

Advisory

Published 11 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
631
of 17,781 indexed, latest versions
Container images
684
deployed by those charts
Fix available
2 of 3
affected packages

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Carried by container images the latest versions of 631 of 17,781 indexed charts deploy, on 684 images.

Affected packageAffected versionsFixed inImages
commons-lang3maven3.0, 3.1, 3.2, 3.2.1+17 more3.18.0599
commons-langmaven2.1, 2.2, 2.4, 2.5+1 moreno fix listed307
libcommons-lang3-javadeb3.8-23.8-2ubuntu0.1~esm11
OSV records
GHSA-j288-q9x7-2f5vUBUNTU-CVE-2025-48924
Also known as
USN-8364-1

Charts affected

631 by stars
ChartLatestAffected imagesRadar Score
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
commons-lang3@3.12.0
3.18.0

Open the chart page →

5,873
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
commons-lang@2.6
no fix listed

Open the chart page →

41,427
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
commons-lang3@3.9
3.18.0

Open the chart page →

3,633
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

5,826
ojp-serverojp0.1.51 of 1See more

ojp-server ojp 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rrobetti/ojp:0.1.0-beta1141bd88232b
commons-lang3@3.5
3.18.0

Open the chart page →

2,587
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

8,540
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

9,005
apicurioone-acre-fundVerified publisher2.3.03 of 5See more

apicurio one-acre-fund 2.3.0

3 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
commons-lang@2.6
commons-lang3@3.13.0
no fix listed
3.18.0
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
commons-lang3@3.12.0
3.18.0
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
commons-lang3@3.12.0
3.18.0

Open the chart page →

18,667
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

6,037
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vespaengine/vespa:8.526.1569b160f58211
commons-lang3@3.16.0
3.18.0

Open the chart page →

6,338
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
commons-lang@2.6
no fix listed

Open the chart page →

2,421
mockserveropen-charts1.1.01 of 1See more

mockserver open-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
mockserver/mockserver:5.15.00f9ef78c9489
commons-lang3@3.12.0
3.18.0

Open the chart page →

1,257
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
commons-lang3@3.5
3.18.0

Open the chart page →

63,223
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

88,546
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
woojoong/wowza:latestec230db19652
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

42,614
omec-control-planeopencord0.1.312 of 8See more

omec-control-plane opencord 0.1.31

2 of the 8 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/cassandra:2.1.20cb079c0d7a57
commons-lang3@3.1
3.18.0
omecproject/c3po-hssdb:master-latest28a90cc26716
commons-lang3@3.1
3.18.0

Open the chart page →

40,715
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0

Open the chart page →

12,927
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

38,865
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
atomix/atomix:3.1.127738ff4f5c63
commons-lang3@3.7
3.18.0
voltha/voltha-onos:5.1.8e038acb950d3
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

41,044
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
commons-lang@2.6
commons-lang3@3.16.0
no fix listed
3.18.0

Open the chart page →

2,024
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
andrianrf/backoffice-be:latest6036614803d4
commons-lang3@3.12.0
3.18.0
andrianrf/iso-client:latestba560086ce15
commons-lang3@3.12.0
3.18.0
andrianrf/iso-server:latest7da47f525c7d
commons-lang3@3.12.0
3.18.0

Open the chart page →

34,671
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
commons-lang3@3.17.0
3.18.0

Open the chart page →

7,792
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,100
openwhiskopenwhisk1.0.02 of 10See more

openwhisk openwhisk 1.0.0

2 of the 10 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/zookeeper:3.43882d9493d38
commons-lang@2.6
no fix listed
openwhisk/invoker:1.0.0f5831ec85525
commons-lang3@3.8.1
3.18.0

Open the chart page →

36,215
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
commons-lang3@3.17.0
3.18.0

Open the chart page →

2,003
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
commons-lang3@3.8.1
3.18.0

Open the chart page →

26,339
trinoopstty0.2.121 of 1See more

trino opstty 0.2.12

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
trinodb/trino:4815b5e0a97f599
commons-lang@2.6
no fix listed

Open the chart page →

1,158
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
commons-lang@2.6
commons-lang3@3.13.0
no fix listed
3.18.0

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

1,753
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
commons-lang3@3.12.0
3.18.0

Open the chart page →

27,537
keycloakpascaliskeVerified publisher0.2.01 of 1See more

keycloak pascaliske 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.74388e2379b7e
commons-lang3@3.14.0
3.18.0

Open the chart page →

2,097
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

6,237
spring-boot-openshiftpiominVerified publisher0.3.111 of 1See more

spring-boot-openshift piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
commons-lang3@3.12.0
3.18.0

Open the chart page →

7,576
jmxproxypndaproject0.1.01 of 1See more

jmxproxy pndaproject 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gradiant/jmxproxy:3.4.045eceb1bc55c
commons-lang3@3.6
3.18.0

Open the chart page →

4,177
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
pcarrascoponce/planner:v1.0981fc482442c
commons-lang3@3.12.0
3.18.0

Open the chart page →

27,558
flink-kubernetes-operatorpresto-loadbalancer1.10.01 of 1See more

flink-kubernetes-operator presto-loadbalancer 1.10.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
commons-lang3@3.16.0
3.18.0

Open the chart page →

3,277
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
commons-lang@2.6
commons-lang3@3.2
no fix listed
3.18.0

Open the chart page →

9,606
trinopresto-loadbalancer0.2.101 of 2See more

trino presto-loadbalancer 0.2.10

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
trinodb/trino:4796af989b0846d
commons-lang@2.6
no fix listed

Open the chart page →

2,264
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
commons-lang3@3.12.0
3.18.0

Open the chart page →

1,995
jenkinsquench-jenkinsVerified publisher0.0.81 of 1See more

jenkins quench-jenkins 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/jenkinsdigest-pinnede92dba4e78c5
commons-lang@2.6
no fix listed

Open the chart page →

79
rada-platformrada-platform0.1.02 of 7See more

rada-platform rada-platform 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
commons-lang3@3.14.0
3.18.0

Open the chart page →

21,211
mockserverradar-baseVerified publisher5.15.01 of 1See more

mockserver radar-base 5.15.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-5.15.00f9ef78c9489
commons-lang3@3.12.0
3.18.0

Open the chart page →

1,257
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

5,269
radar-integrationradar-baseVerified publisher0.9.01 of 1See more

radar-integration radar-base 0.9.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
commons-lang3@3.6
3.18.0

Open the chart page →

2,855

Container images carrying it

684 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
commons-lang3@3.14.0
3.18.0
1
airbyte/cron:0.40.17caf4f551c546
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
airbyte/cron:2.2.0d97b67a1346d
commons-lang3@3.14.0
3.18.0
1
airbyte/worker:2.2.08060b88b29c8
commons-lang3@3.14.0
3.18.0
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
aktosecurity/akto-api-protection:localbcd7382c9c1b
commons-lang3@3.12.0
3.18.0
1
aktosecurity/data-ingestion-service213aded7adc5
commons-lang3@3.8.1
3.18.0
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-lang3@3.8.1
3.18.0
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
commons-lang3@3.13.0
3.18.0
1
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
commons-lang3@3.12.0
3.18.0
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
commons-lang3@3.14.0
3.18.0
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0
1
andrianrf/backoffice-be:latest6036614803d4
commons-lang3@3.12.0
3.18.0
1
andrianrf/iso-client:latestba560086ce15
commons-lang3@3.12.0
3.18.0
1
andrianrf/iso-server:latest7da47f525c7d
commons-lang3@3.12.0
3.18.0
1
anguda/ant-media:2.5c435285fc241
commons-lang3@3.9
3.18.0
1
apache/activemq-artemis:2.37.0bae523439ee3
commons-lang3@3.16.0
3.18.0
1
apache/bookkeeper:4.14.5a7d9970c148f
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
1
apache/camel-k:1.10.43bb13d14f64a
commons-lang3@3.8.1
3.18.0
1
apache/drill:1.21.11f96558fd292
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0
1
apache/druid:29.0.10cef139b6bf1
commons-lang@2.5
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/hadoop:3af361b20bec0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/hertzbeat:1.8.075d48a62748f
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
apacheignite/ignite:2.7.0d7deab68b8fa
commons-lang@2.6
no fix listed
1
apache/iotdb:0.11.28647309f95d1
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
apache/iotdb:0.13.3-nodeafa47bf1692a
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
apache/kafka:3.9.0fbc7d7c428e3
commons-lang3@3.12.0
3.18.0
1
apache/nifi-registry:1.14.0090b7f87ec7f
commons-lang3@3.5
3.18.0
1
apache/nifi-registry:1.27.063b8e3e40742
commons-lang3@3.14.0
3.18.0
1
apache/nifi-registry:0.8.0974efa2f21da
commons-lang3@3.5
3.18.0
1
apachepinot/pinot:latest-jdk110018bb04ced7
commons-lang@2.6
commons-lang3@3.5
no fix listed
3.18.0
1
apache/polaris:lateste66366e783f1
commons-lang@2.6
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
1
apachepulsar/pulsar:3.0.79c9947de139d
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.9.0d056c89b7131
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.8.2d538416d5afe
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apache/ranger:2.7.076c176e8a0e4
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
apache/rocketmq:5.3.0434d8398f996
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/rocketmq:4.9.35ac2a4e0f627
commons-lang3@3.4
3.18.0
1
apache/rocketmq-exporter:0.0.2c8fb51195444
commons-lang3@3.12.0
3.18.0
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
commons-lang3@3.4
3.18.0
1
apache/shenyu-admin:2.5.1e2be712fc4f4
commons-lang3@3.12.0
3.18.0
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apache/skywalking-oap-server:9.2.0133d35d2c263
commons-lang3@3.12.0
3.18.0
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
commons-lang@2.4
commons-lang3@3.7
no fix listed
3.18.0
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
commons-lang3@3.12.0
3.18.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.