StackRadar

CVE-2025-48924

Medium

Advisory

Published 11 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
631
of 17,781 indexed, latest versions
Container images
684
deployed by those charts
Fix available
2 of 3
affected packages

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Carried by container images the latest versions of 631 of 17,781 indexed charts deploy, on 684 images.

Affected packageAffected versionsFixed inImages
commons-lang3maven3.0, 3.1, 3.2, 3.2.1+17 more3.18.0599
commons-langmaven2.1, 2.2, 2.4, 2.5+1 moreno fix listed307
libcommons-lang3-javadeb3.8-23.8-2ubuntu0.1~esm11
OSV records
GHSA-j288-q9x7-2f5vUBUNTU-CVE-2025-48924
Also known as
USN-8364-1

Charts affected

631 by stars
ChartLatestAffected imagesRadar Score
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0

Open the chart page →

52,635
wiremockdeliveryheroVerified publisher1.4.61 of 2See more

wiremock deliveryhero 1.4.6

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
commons-lang3@3.8.1
3.18.0

Open the chart page →

2,140
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
commons-lang3@3.9
3.18.0

Open the chart page →

6,110
hbasedmwm-bigdataVerified publisher0.1.62 of 5See more

hbase dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
gradiant/hdfs:2.7.73b28784ba41f
commons-lang@2.6
commons-lang3@3.3.2
no fix listed
3.18.0

Open the chart page →

13,392
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
commons-lang@2.6
commons-lang3@3.3.2
no fix listed
3.18.0

Open the chart page →

6,882
opentsdbdmwm-bigdataVerified publisher0.1.73 of 6See more

opentsdb dmwm-bigdata 0.1.7

3 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
gradiant/hdfs:2.7.73b28784ba41f
commons-lang@2.6
commons-lang3@3.3.2
no fix listed
3.18.0
gradiant/opentsdb:2.4.0c33d53913869
commons-lang3@3.1
3.18.0

Open the chart page →

17,511
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0

Open the chart page →

8,752
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
commons-lang3@3.5
3.18.0

Open the chart page →

6,531
jenkinsedu2.7.11 of 2See more

jenkins edu 2.7.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
commons-lang@2.6
no fix listed

Open the chart page →

4,423
enavenav-service-architectureVerified publisher0.0.79 of 10See more

enav enav-service-architecture 0.0.7

9 of the 10 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/kafka:3.9.0fbc7d7c428e3
commons-lang3@3.12.0
3.18.0
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-eureka:latest05002092c621
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
commons-lang@2.6
no fix listed
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
commons-lang@2.6
no fix listed

Open the chart page →

15,860
neo4j-communityequinor-charts1.2.51 of 1See more

neo4j-community equinor-charts 1.2.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/neo4j:4.2.4348e3f56faa2
commons-lang3@3.9
3.18.0

Open the chart page →

2,751
pitchforkexpediagroup0.1.41 of 1See more

pitchfork expediagroup 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
expediagroup/pitchfork:1.314f2cf61e7de9
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

3,309
atlas-cmmsf3k-techVerified publisher0.151.51 of 4See more

atlas-cmms f3k-tech 0.151.5

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
commons-lang3@3.13.0
3.18.0

Open the chart page →

5,291
featurehubfeaturehub4.1.63 of 7See more

featurehub featurehub 4.1.6

3 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
featurehub/dacha2:1.9.1c8d5551b5e40
commons-lang3@3.12.0
3.18.0
featurehub/edge:1.9.198ad426737f6
commons-lang3@3.12.0
3.18.0
featurehub/mr:1.9.1477d8bf771a9
commons-lang3@3.12.0
3.18.0

Open the chart page →

8,240
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
commons-lang@2.6
no fix listed

Open the chart page →

11,553
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.4.4c0224a1adf7a
commons-lang3@3.8.1
3.18.0
provectuslabs/kafka-ui:latest8f2ff02d64b0
commons-lang3@3.12.0
3.18.0

Open the chart page →

15,562
temporalglasskubeVerified publisher0.45.2-gk.11 of 14See more

temporal glasskube 0.45.2-gk.1

1 of the 14 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
commons-lang3@3.1
3.18.0

Open the chart page →

16,346
hbasegradiant-bigdataVerified publisher0.1.62 of 5See more

hbase gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
commons-lang@2.6
commons-lang3@3.6
no fix listed
3.18.0
gradiant/hdfs:2.7.73b28784ba41f
commons-lang@2.6
commons-lang3@3.3.2
no fix listed
3.18.0

Open the chart page →

13,392
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

6,165
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

4,679
hawkhawk1.1.51 of 4See more

hawk hawk 1.1.5

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
commons-lang3@3.13.0
3.18.0

Open the chart page →

13,610
seata-serverheidaodageshiwoVerified publisher1.0.01 of 1See more

seata-server heidaodageshiwo 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
seataio/seata-server:1.5.1ee1ed55f4144
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

5,624
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
commons-lang3@3.17.0
3.18.0

Open the chart page →

8,716
iceberg-resticeberg-rest-fixture0.0.11 of 2See more

iceberg-rest iceberg-rest-fixture 0.0.1

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
commons-lang3@3.14.0
3.18.0

Open the chart page →

3,470
traccarjeffrescVerified publisher0.2.01 of 2See more

traccar jeffresc 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
traccar/traccar:6.7-alpine621c8d6d46fd
commons-lang3@3.17.0
3.18.0

Open the chart page →

1,341
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
salehmir/jesse:1.10.101afa95f979e9
commons-lang3@3.13.0
3.18.0

Open the chart page →

3,421
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
commons-lang3@3.8.1
3.18.0

Open the chart page →

9,318
ipfix-generatorjfwenischVerified publisher0.3.16-feature-helm-package.01 of 1See more

ipfix-generator jfwenisch 0.3.16-feature-helm-package.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
commons-lang3@3.17.0
3.18.0

Open the chart page →

697
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0

Open the chart page →

7,387
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
commons-lang3@3.12.0
3.18.0

Open the chart page →

2,067
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
commons-lang3@3.12.0
3.18.0
kafkakraft/kafka-controller:3.7.0f261ad288fce
commons-lang3@3.8.1
3.18.0
kafkakraft/kafkakraft:3.7.02e4b593b878b
commons-lang3@3.8.1
3.18.0

Open the chart page →

14,130
kokukokuVerified publisher1.0.02 of 7See more

koku koku 1.0.0

2 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
commons-lang3@3.17.0
3.18.0

Open the chart page →

12,019
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0

Open the chart page →

7,710
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0

Open the chart page →

13,479
metabasemetabase-helmVerified publisher2.7.11 of 1See more

metabase metabase-helm 2.7.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
metabase/metabase:v0.46.09ebdc664a6b2
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

2,221
hadoopmiuler1.2.21 of 1See more

hadoop miuler 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
commons-lang@2.6
commons-lang3@3.4
no fix listed
3.18.0

Open the chart page →

5,772
clowder2ncsaVerified publisher1.9.72 of 12See more

clowder2 ncsa 1.9.7

2 of the 12 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
commons-lang3@3.12.0
3.18.0
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

37,373
glowrootnovum-rgi-charts1.0.101 of 2See more

glowroot novum-rgi-charts 1.0.10

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
commons-lang@2.6
no fix listed

Open the chart page →

2,308
openccuopenccuVerified publisher3.89.81 of 1See more

openccu openccu 3.89.8

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
commons-lang@2.6
no fix listed

Open the chart page →

1,916
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
commons-lang3@3.14.0
3.18.0

Open the chart page →

1,692
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
commons-lang3@3.12.0
3.18.0

Open the chart page →

7,576
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
commons-lang3@3.12.0
3.18.0

Open the chart page →

31,844
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
commons-lang@2.6
no fix listed

Open the chart page →

2,476
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
commons-lang3@3.5
3.18.0

Open the chart page →

4,621
kafka-managerradar-baseVerified publisher2.3.11 of 1See more

kafka-manager radar-base 2.3.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
radarbase/kafka-manager:1.3.3.181d2af7dd5a4e
commons-lang3@3.4
3.18.0

Open the chart page →

4,000
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

3,958
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
commons-lang3@3.12.0
3.18.0

Open the chart page →

6,639
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
commons-lang3@3.17.0
3.18.0

Open the chart page →

7,432
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
commons-lang3@3.12.0
3.18.0

Open the chart page →

9,837
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
commons-lang3@3.12.0
3.18.0

Open the chart page →

10,120

Container images carrying it

684 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
apache/skywalking-ui:8.1.067d50e4deff4
commons-lang@2.6
commons-lang3@3.1
no fix listed
3.18.0
1
apache/tika:2.9.0.092d055a84e9e
commons-lang3@3.13.0
3.18.0
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
commons-lang3@3.9
3.18.0
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
commons-lang3@3.12.0
3.18.0
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
commons-lang@2.6
commons-lang3@3.13.0
no fix listed
3.18.0
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
commons-lang3@3.12.0
3.18.0
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
commons-lang3@3.12.0
3.18.0
1
apimap/api:v1.8.11ae2b3ab00177
commons-lang3@3.12.0
3.18.0
1
arturisimo/planner:v1.0fff9de644941
commons-lang3@3.12.0
3.18.0
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
commons-lang3@3.1
3.18.0
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
commons-lang@2.6
no fix listed
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
assistiot/identity-manager_kc:latest0df4b4fa899a
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
commons-lang@2.4
commons-lang3@3.12.0
no fix listed
3.18.0
1
atlassian/bitbucket:10.2.705933f2b1cfd
commons-lang3@3.17.0
3.18.0
1
atlassian/confluence-server:7.10.03b9222ab32ef
commons-lang@2.6
commons-lang3@3.8
no fix listed
3.18.0
1
atlassian/crowd:5.2.2ebf761c7d437
commons-lang@2.6
commons-lang3@3.8
no fix listed
3.18.0
1
atlassian/jira-software:8.14.037bc46cbec1a
commons-lang@2.4
commons-lang3@3.8
no fix listed
3.18.0
1
atlassian/jira-software:9.7.264a75aa4ec4e
commons-lang@2.5
commons-lang3@3.5
no fix listed
3.18.0
1
atlassian/jira-software:11.3.11e5548cd4eea8
commons-lang@2.4
no fix listed
1
atomix/atomix:3.1.127738ff4f5c63
commons-lang3@3.7
3.18.0
1
audig/clamapi:2.1.62c3fe34ee430
commons-lang3@3.10
3.18.0
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
commons-lang@2.6
commons-lang3@3.7
no fix listed
3.18.0
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
commons-lang3@3.11
3.18.0
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
commons-lang3@3.12.0
3.18.0
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
commons-lang3@3.12.0
3.18.0
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
commons-lang3@3.9
3.18.0
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
commons-lang3@3.8.1
3.18.0
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
commons-lang3@3.8.1
3.18.0
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
commons-lang3@3.8.1
3.18.0
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
commons-lang3@3.14.0
3.18.0
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
commons-lang3@3.17.0
3.18.0
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
bivas/presto:0.19605545994f806
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
commons-lang3@3.14.0
3.18.0
1
bluerange/bluerange:26.1.307c8f73b55df
commons-lang3@3.17.0
3.18.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
commons-lang3@3.8
libcommons-lang3-java@3.8-2
3.18.0
3.8-2ubuntu0.1~esm1
1
budibase/database:2.1.0d90f656261c9
commons-lang@2.6
no fix listed
1
camunda/zeebe:8.4.5ab5abc09e407
commons-lang3@3.14.0
3.18.0
1
castlemock/castlemock:latestb7f3f1527ba9
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
commons-lang3@3.17.0
3.18.0
1
choerodon/event-store-service:0.8.03c94c97f6f69
commons-lang@2.6
no fix listed
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
commons-lang3@3.15.0
3.18.0
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
codetogether/codetogether:latest4348c8a38752
commons-lang3@3.4
3.18.0
1
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
commons-lang3@3.9
3.18.0
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
commons-lang3@3.9
3.18.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.