StackRadar

CVE-2025-48924

Medium

Advisory

Published 11 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
631
of 17,781 indexed, latest versions
Container images
684
deployed by those charts
Fix available
2 of 3
affected packages

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Carried by container images the latest versions of 631 of 17,781 indexed charts deploy, on 684 images.

Affected packageAffected versionsFixed inImages
commons-lang3maven3.0, 3.1, 3.2, 3.2.1+17 more3.18.0599
commons-langmaven2.1, 2.2, 2.4, 2.5+1 moreno fix listed307
libcommons-lang3-javadeb3.8-23.8-2ubuntu0.1~esm11
OSV records
GHSA-j288-q9x7-2f5vUBUNTU-CVE-2025-48924
Also known as
USN-8364-1

Charts affected

631 by stars
ChartLatestAffected imagesRadar Score
radar-mockserverradar-baseVerified publisher0.1.31 of 1See more

radar-mockserver radar-base 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-5.15.00f9ef78c9489
commons-lang3@3.12.0
3.18.0

Open the chart page →

1,257
radar-push-endpointradar-baseVerified publisher0.6.81 of 2See more

radar-push-endpoint radar-base 0.6.8

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
radarbase/radar-push-endpoint:0.4.0e1758508e033
commons-lang3@3.14.0
3.18.0

Open the chart page →

3,018
iparedhat-cop1.3.91 of 1See more

ipa redhat-cop 1.3.9

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
commons-lang3@3.12.0
3.18.0

Open the chart page →

951
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

4,203
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
commons-lang3@3.8.1
3.18.0

Open the chart page →

29,227
reportportalreportportal5.7.23 of 8See more

reportportal reportportal 5.7.2

3 of the 8 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
commons-lang3@3.9
3.18.0
reportportal/service-authorization:5.7.09e73114dbd15
commons-lang@2.4
commons-lang3@3.9
no fix listed
3.18.0
reportportal/service-jobs:5.7.2dc166c58485a
commons-lang3@3.12.0
3.18.0

Open the chart page →

25,737
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

3,051
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
commons-lang3@3.0
3.18.0

Open the chart page →

2,209
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
commons-lang@2.6
no fix listed

Open the chart page →

3,978
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
commons-lang3@3.12.0
3.18.0

Open the chart page →

1,597
keycloaksb-helm-charts0.3.01 of 2See more

keycloak sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
commons-lang3@3.14.0
3.18.0

Open the chart page →

2,590
smartquerysearchhub0.1.01 of 1See more

smartquery searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
commerceexperts/smartquery-service:2.2.09e33ad89baf6
commons-lang3@3.9
3.18.0

Open the chart page →

1,528
smartsuggestsearchhub0.1.01 of 1See more

smartsuggest searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
commons-lang3@3.9
3.18.0

Open the chart page →

1,235
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

4,245
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
commons-lang@2.4
commons-lang3@3.5
no fix listed
3.18.0

Open the chart page →

8,098
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
commons-lang3@3.8.1
3.18.0

Open the chart page →

10,967
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
commons-lang3@3.14.0
3.18.0

Open the chart page →

5,456
shenyushenyu0.6.32 of 2See more

shenyu shenyu 0.6.3

2 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.5.1e2be712fc4f4
commons-lang3@3.12.0
3.18.0
apache/shenyu-bootstrap:2.5.11bd5756f6273
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.272 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

2 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
commons-lang3@3.3.2
3.18.0
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
commons-lang@2.6
commons-lang3@3.3.2
no fix listed
3.18.0

Open the chart page →

12,513
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
commons-lang3@3.17.0
3.18.0

Open the chart page →

1,690
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

6,443
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

4,946
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

5,856
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
commons-lang3@3.2.1
3.18.0

Open the chart page →

6,949
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
commons-lang@2.6
commons-lang3@3.1
no fix listed
3.18.0

Open the chart page →

6,907
hetzner-iroboslamdev0.0.51 of 1See more

hetzner-irobo slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
slamdev/hetzner-irobo:0.0.13ca20c184c55
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

3,754
stewardsoftwaremillVerified publisher0.1.121 of 1See more

steward softwaremill 0.1.12

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
fthomas/scala-steward:latest367afe974b7a
commons-lang3@3.14.0
3.18.0

Open the chart page →

589
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
commons-lang@2.6
commons-lang3@3.8
no fix listed
3.18.0

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
commons-lang@2.4
commons-lang3@3.8
no fix listed
3.18.0

Open the chart page →

13,079
smtp-fake-serversomeblackmagic0.1.01 of 1See more

smtp-fake-server someblackmagic 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
someblackmagic/smtp-fake-server:latest0d63ba37a560
commons-lang3@3.11
3.18.0

Open the chart page →

4,278
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
commons-lang@2.6
commons-lang3@3.7
no fix listed
3.18.0

Open the chart page →

3,164
retail-store-sample-cart-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-cart-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
commons-lang3@3.17.0
3.18.0

Open the chart page →

1,068
retail-store-sample-orders-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-orders-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
commons-lang3@3.17.0
3.18.0

Open the chart page →

1,223
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
commons-lang3@3.9
3.18.0

Open the chart page →

28,165
cerebrostakaterVerified publisher0.5.11 of 2See more

cerebro stakater 0.5.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
lmenezes/cerebro:0.8.13e860068e403
commons-lang3@3.6
3.18.0

Open the chart page →

2,956
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
commons-lang@2.6
no fix listed

Open the chart page →

2,476
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
commons-lang3@3.9
3.18.0

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
commons-lang3@3.9
3.18.0

Open the chart page →

11,554
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
commons-lang@2.6
no fix listed

Open the chart page →

11,841
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
commons-lang@2.4
commons-lang3@3.17.0
no fix listed
3.18.0

Open the chart page →

3,153
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
commons-lang3@3.10
3.18.0

Open the chart page →

14,493
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-lang@2.6
commons-lang3@3.10
no fix listed
3.18.0

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-lang@2.6
commons-lang3@3.10
no fix listed
3.18.0

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

13,767
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

8,554
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.009a381c715ab
commons-lang3@3.14.0
3.18.0

Open the chart page →

5,063
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

18,756
languagetool-serverszpadel-chartsVerified publisher0.4.01 of 1See more

languagetool-server szpadel-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
commons-lang3@3.12.0
3.18.0

Open the chart page →

808
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

4,240
clickhousetemp-charts0.7.11 of 3See more

clickhouse temp-charts 0.7.1

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/zookeeper:3.6.180ad2170ad62
commons-lang@2.6
no fix listed

Open the chart page →

8,707

Container images carrying it

684 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
commons-lang3@3.14.0
3.18.0
1
airbyte/cron:0.40.17caf4f551c546
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
airbyte/cron:2.2.0d97b67a1346d
commons-lang3@3.14.0
3.18.0
1
airbyte/worker:2.2.08060b88b29c8
commons-lang3@3.14.0
3.18.0
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
aktosecurity/akto-api-protection:localbcd7382c9c1b
commons-lang3@3.12.0
3.18.0
1
aktosecurity/data-ingestion-service213aded7adc5
commons-lang3@3.8.1
3.18.0
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-lang3@3.8.1
3.18.0
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
commons-lang3@3.13.0
3.18.0
1
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
commons-lang3@3.12.0
3.18.0
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
commons-lang3@3.14.0
3.18.0
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0
1
andrianrf/backoffice-be:latest6036614803d4
commons-lang3@3.12.0
3.18.0
1
andrianrf/iso-client:latestba560086ce15
commons-lang3@3.12.0
3.18.0
1
andrianrf/iso-server:latest7da47f525c7d
commons-lang3@3.12.0
3.18.0
1
anguda/ant-media:2.5c435285fc241
commons-lang3@3.9
3.18.0
1
apache/activemq-artemis:2.37.0bae523439ee3
commons-lang3@3.16.0
3.18.0
1
apache/bookkeeper:4.14.5a7d9970c148f
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
1
apache/camel-k:1.10.43bb13d14f64a
commons-lang3@3.8.1
3.18.0
1
apache/drill:1.21.11f96558fd292
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0
1
apache/druid:29.0.10cef139b6bf1
commons-lang@2.5
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/hadoop:3af361b20bec0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/hertzbeat:1.8.075d48a62748f
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
apacheignite/ignite:2.7.0d7deab68b8fa
commons-lang@2.6
no fix listed
1
apache/iotdb:0.11.28647309f95d1
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
apache/iotdb:0.13.3-nodeafa47bf1692a
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
apache/kafka:3.9.0fbc7d7c428e3
commons-lang3@3.12.0
3.18.0
1
apache/nifi-registry:1.14.0090b7f87ec7f
commons-lang3@3.5
3.18.0
1
apache/nifi-registry:1.27.063b8e3e40742
commons-lang3@3.14.0
3.18.0
1
apache/nifi-registry:0.8.0974efa2f21da
commons-lang3@3.5
3.18.0
1
apachepinot/pinot:latest-jdk110018bb04ced7
commons-lang@2.6
commons-lang3@3.5
no fix listed
3.18.0
1
apache/polaris:lateste66366e783f1
commons-lang@2.6
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
1
apachepulsar/pulsar:3.0.79c9947de139d
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.9.0d056c89b7131
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.8.2d538416d5afe
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apache/ranger:2.7.076c176e8a0e4
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
apache/rocketmq:5.3.0434d8398f996
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/rocketmq:4.9.35ac2a4e0f627
commons-lang3@3.4
3.18.0
1
apache/rocketmq-exporter:0.0.2c8fb51195444
commons-lang3@3.12.0
3.18.0
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
commons-lang3@3.4
3.18.0
1
apache/shenyu-admin:2.5.1e2be712fc4f4
commons-lang3@3.12.0
3.18.0
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apache/skywalking-oap-server:9.2.0133d35d2c263
commons-lang3@3.12.0
3.18.0
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
commons-lang@2.4
commons-lang3@3.7
no fix listed
3.18.0
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
commons-lang3@3.12.0
3.18.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.