StackRadar

CVE-2025-48924

Medium

Advisory

Published 11 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
631
of 17,781 indexed, latest versions
Container images
684
deployed by those charts
Fix available
2 of 3
affected packages

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Carried by container images the latest versions of 631 of 17,781 indexed charts deploy, on 684 images.

Affected packageAffected versionsFixed inImages
commons-lang3maven3.0, 3.1, 3.2, 3.2.1+17 more3.18.0599
commons-langmaven2.1, 2.2, 2.4, 2.5+1 moreno fix listed307
libcommons-lang3-javadeb3.8-23.8-2ubuntu0.1~esm11
OSV records
GHSA-j288-q9x7-2f5vUBUNTU-CVE-2025-48924
Also known as
USN-8364-1

Charts affected

631 by stars
ChartLatestAffected imagesRadar Score
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0

Open the chart page →

52,635
wiremockdeliveryheroVerified publisher1.4.61 of 2See more

wiremock deliveryhero 1.4.6

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
commons-lang3@3.8.1
3.18.0

Open the chart page →

2,140
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
commons-lang3@3.9
3.18.0

Open the chart page →

6,110
hbasedmwm-bigdataVerified publisher0.1.62 of 5See more

hbase dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
gradiant/hdfs:2.7.73b28784ba41f
commons-lang@2.6
commons-lang3@3.3.2
no fix listed
3.18.0

Open the chart page →

13,392
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
commons-lang@2.6
commons-lang3@3.3.2
no fix listed
3.18.0

Open the chart page →

6,882
opentsdbdmwm-bigdataVerified publisher0.1.73 of 6See more

opentsdb dmwm-bigdata 0.1.7

3 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
gradiant/hdfs:2.7.73b28784ba41f
commons-lang@2.6
commons-lang3@3.3.2
no fix listed
3.18.0
gradiant/opentsdb:2.4.0c33d53913869
commons-lang3@3.1
3.18.0

Open the chart page →

17,511
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0

Open the chart page →

8,752
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
commons-lang3@3.5
3.18.0

Open the chart page →

6,531
jenkinsedu2.7.11 of 2See more

jenkins edu 2.7.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
commons-lang@2.6
no fix listed

Open the chart page →

4,423
enavenav-service-architectureVerified publisher0.0.79 of 10See more

enav enav-service-architecture 0.0.7

9 of the 10 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/kafka:3.9.0fbc7d7c428e3
commons-lang3@3.12.0
3.18.0
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-eureka:latest05002092c621
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
commons-lang@2.6
no fix listed

Open the chart page →

15,860
neo4j-communityequinor-charts1.2.51 of 1See more

neo4j-community equinor-charts 1.2.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/neo4j:4.2.4348e3f56faa2
commons-lang3@3.9
3.18.0

Open the chart page →

2,751
pitchforkexpediagroup0.1.41 of 1See more

pitchfork expediagroup 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
expediagroup/pitchfork:1.314f2cf61e7de9
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

3,309
atlas-cmmsf3k-techVerified publisher0.151.51 of 4See more

atlas-cmms f3k-tech 0.151.5

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
commons-lang3@3.13.0
3.18.0

Open the chart page →

5,291
featurehubfeaturehub4.1.63 of 7See more

featurehub featurehub 4.1.6

3 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
featurehub/dacha2:1.9.1c8d5551b5e40
commons-lang3@3.12.0
3.18.0
featurehub/edge:1.9.198ad426737f6
commons-lang3@3.12.0
3.18.0
featurehub/mr:1.9.1477d8bf771a9
commons-lang3@3.12.0
3.18.0

Open the chart page →

8,240
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
commons-lang@2.6
no fix listed

Open the chart page →

11,553
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.4.4c0224a1adf7a
commons-lang3@3.8.1
3.18.0
provectuslabs/kafka-ui:latest8f2ff02d64b0
commons-lang3@3.12.0
3.18.0

Open the chart page →

15,562
temporalglasskubeVerified publisher0.45.2-gk.11 of 14See more

temporal glasskube 0.45.2-gk.1

1 of the 14 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
commons-lang3@3.1
3.18.0

Open the chart page →

16,346
hbasegradiant-bigdataVerified publisher0.1.62 of 5See more

hbase gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
gradiant/hdfs:2.7.73b28784ba41f
commons-lang@2.6
commons-lang3@3.3.2
no fix listed
3.18.0

Open the chart page →

13,392
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

6,165
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

4,679
hawkhawk1.1.51 of 4See more

hawk hawk 1.1.5

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
commons-lang3@3.13.0
3.18.0

Open the chart page →

13,610
seata-serverheidaodageshiwoVerified publisher1.0.01 of 1See more

seata-server heidaodageshiwo 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
seataio/seata-server:1.5.1ee1ed55f4144
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

5,624
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
commons-lang3@3.17.0
3.18.0

Open the chart page →

8,716
iceberg-resticeberg-rest-fixture0.0.11 of 2See more

iceberg-rest iceberg-rest-fixture 0.0.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
commons-lang3@3.14.0
3.18.0

Open the chart page →

3,470
traccarjeffrescVerified publisher0.2.01 of 2See more

traccar jeffresc 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
traccar/traccar:6.7-alpine621c8d6d46fd
commons-lang3@3.17.0
3.18.0

Open the chart page →

1,341
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
salehmir/jesse:1.10.101afa95f979e9
commons-lang3@3.13.0
3.18.0

Open the chart page →

3,421
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
commons-lang3@3.8.1
3.18.0

Open the chart page →

9,318
ipfix-generatorjfwenischVerified publisher0.3.16-feature-helm-package.01 of 1See more

ipfix-generator jfwenisch 0.3.16-feature-helm-package.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
commons-lang3@3.17.0
3.18.0

Open the chart page →

697
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

7,387
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
commons-lang3@3.12.0
3.18.0

Open the chart page →

2,067
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
commons-lang3@3.12.0
3.18.0
kafkakraft/kafka-controller:3.7.0f261ad288fce
commons-lang3@3.8.1
3.18.0
kafkakraft/kafkakraft:3.7.02e4b593b878b
commons-lang3@3.8.1
3.18.0

Open the chart page →

14,130
kokukokuVerified publisher1.0.02 of 7See more

koku koku 1.0.0

2 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
commons-lang3@3.17.0
3.18.0

Open the chart page →

12,019
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

7,710
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0

Open the chart page →

13,479
metabasemetabase-helmVerified publisher2.7.11 of 1See more

metabase metabase-helm 2.7.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
metabase/metabase:v0.46.09ebdc664a6b2
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

2,221
hadoopmiuler1.2.21 of 1See more

hadoop miuler 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

5,772
clowder2ncsaVerified publisher1.9.72 of 12See more

clowder2 ncsa 1.9.7

2 of the 12 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
commons-lang3@3.12.0
3.18.0
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

37,373
glowrootnovum-rgi-charts1.0.101 of 2See more

glowroot novum-rgi-charts 1.0.10

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
commons-lang@2.6
no fix listed

Open the chart page →

2,308
openccuopenccuVerified publisher3.89.81 of 1See more

openccu openccu 3.89.8

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
commons-lang@2.6
no fix listed

Open the chart page →

1,916
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
commons-lang3@3.14.0
3.18.0

Open the chart page →

1,692
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
commons-lang3@3.12.0
3.18.0

Open the chart page →

7,576
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
commons-lang3@3.12.0
3.18.0

Open the chart page →

31,844
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
commons-lang@2.6
no fix listed

Open the chart page →

2,476
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
commons-lang3@3.5
3.18.0

Open the chart page →

4,621
kafka-managerradar-baseVerified publisher2.3.11 of 1See more

kafka-manager radar-base 2.3.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
radarbase/kafka-manager:1.3.3.181d2af7dd5a4e
commons-lang3@3.4
3.18.0

Open the chart page →

4,000
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

3,958
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
commons-lang3@3.12.0
3.18.0

Open the chart page →

6,639
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
commons-lang3@3.17.0
3.18.0

Open the chart page →

7,432
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
commons-lang3@3.12.0
3.18.0

Open the chart page →

9,837
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
commons-lang3@3.12.0
3.18.0

Open the chart page →

10,120

Container images carrying it

684 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
commons-lang3@3.14.0
3.18.0
1
airbyte/cron:0.40.17caf4f551c546
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
airbyte/cron:2.2.0d97b67a1346d
commons-lang3@3.14.0
3.18.0
1
airbyte/worker:2.2.08060b88b29c8
commons-lang3@3.14.0
3.18.0
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
aktosecurity/akto-api-protection:localbcd7382c9c1b
commons-lang3@3.12.0
3.18.0
1
aktosecurity/data-ingestion-service213aded7adc5
commons-lang3@3.8.1
3.18.0
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-lang3@3.8.1
3.18.0
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
commons-lang3@3.13.0
3.18.0
1
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
commons-lang3@3.12.0
3.18.0
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
commons-lang3@3.14.0
3.18.0
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0
1
andrianrf/backoffice-be:latest6036614803d4
commons-lang3@3.12.0
3.18.0
1
andrianrf/iso-client:latestba560086ce15
commons-lang3@3.12.0
3.18.0
1
andrianrf/iso-server:latest7da47f525c7d
commons-lang3@3.12.0
3.18.0
1
anguda/ant-media:2.5c435285fc241
commons-lang3@3.9
3.18.0
1
apache/activemq-artemis:2.37.0bae523439ee3
commons-lang3@3.16.0
3.18.0
1
apache/bookkeeper:4.14.5a7d9970c148f
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
1
apache/camel-k:1.10.43bb13d14f64a
commons-lang3@3.8.1
3.18.0
1
apache/drill:1.21.11f96558fd292
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0
1
apache/druid:29.0.10cef139b6bf1
commons-lang@2.5
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/hadoop:3af361b20bec0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/hertzbeat:1.8.075d48a62748f
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
apacheignite/ignite:2.7.0d7deab68b8fa
commons-lang@2.6
no fix listed
1
apache/iotdb:0.11.28647309f95d1
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
apache/iotdb:0.13.3-nodeafa47bf1692a
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
apache/kafka:3.9.0fbc7d7c428e3
commons-lang3@3.12.0
3.18.0
1
apache/nifi-registry:1.14.0090b7f87ec7f
commons-lang3@3.5
3.18.0
1
apache/nifi-registry:1.27.063b8e3e40742
commons-lang3@3.14.0
3.18.0
1
apache/nifi-registry:0.8.0974efa2f21da
commons-lang3@3.5
3.18.0
1
apachepinot/pinot:latest-jdk110018bb04ced7
commons-lang@2.6
commons-lang3@3.5
no fix listed
3.18.0
1
apache/polaris:lateste66366e783f1
commons-lang@2.6
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
1
apachepulsar/pulsar:3.0.79c9947de139d
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.9.0d056c89b7131
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apachepulsar/pulsar:2.8.2d538416d5afe
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apache/ranger:2.7.076c176e8a0e4
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
apache/rocketmq:5.3.0434d8398f996
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
1
apache/rocketmq:4.9.35ac2a4e0f627
commons-lang3@3.4
3.18.0
1
apache/rocketmq-exporter:0.0.2c8fb51195444
commons-lang3@3.12.0
3.18.0
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
commons-lang3@3.4
3.18.0
1
apache/shenyu-admin:2.5.1e2be712fc4f4
commons-lang3@3.12.0
3.18.0
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
apache/skywalking-oap-server:9.2.0133d35d2c263
commons-lang3@3.12.0
3.18.0
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
commons-lang@2.4
commons-lang3@3.7
no fix listed
3.18.0
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
commons-lang3@3.12.0
3.18.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.