StackRadar

CVE-2025-48924

Medium

Advisory

Published 11 Jul 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
631
of 17,781 indexed, latest versions
Container images
684
deployed by those charts
Fix available
2 of 3
affected packages

Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs

Carried by container images the latest versions of 631 of 17,781 indexed charts deploy, on 684 images.

Affected packageAffected versionsFixed inImages
commons-lang3maven3.0, 3.1, 3.2, 3.2.1+17 more3.18.0599
commons-langmaven2.1, 2.2, 2.4, 2.5+1 moreno fix listed307
libcommons-lang3-javadeb3.8-23.8-2ubuntu0.1~esm11
OSV records
GHSA-j288-q9x7-2f5vUBUNTU-CVE-2025-48924
Also known as
USN-8364-1

Charts affected

631 by stars
ChartLatestAffected imagesRadar Score
routrroutr0.0.101 of 2See more

routr routr 0.0.10

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
fonoster/routr:1.0.0-rc52ca65af17cbc
commons-lang@2.6
commons-lang3@3.10
no fix listed
3.18.0

Open the chart page →

4,983
seldon-coreseldon0.2.72 of 3See more

seldon-core seldon 0.2.7

2 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
commons-lang@2.6
commons-lang3@3.5
no fix listed
3.18.0
seldonio/cluster-manager:0.2.729e362bb1ba2
commons-lang@2.4
commons-lang3@3.5
no fix listed
3.18.0

Open the chart page →

13,798
sentinel-dashboardsentinel-dashboardVerified publisher0.1.01 of 1See more

sentinel-dashboard sentinel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
royalwang/sentinel-dashboard:1.8.4df99e2499f91
commons-lang@2.6
no fix listed

Open the chart page →

4,287
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.6.683dbca3efd2a
commons-lang3@3.8.1
3.18.0

Open the chart page →

16,449
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

2,406
nexus-iq-server-hasonatypeVerified publisher207.1.01 of 2See more

nexus-iq-server-ha sonatype 207.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
sonatype/nexus-iq-server:1.207.1a70014ed10b1
commons-lang@2.6
no fix listed

Open the chart page →

38
stardogstardog3.1.01 of 3See more

stardog stardog 3.1.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
stardog/stardog:latest2714e5c4b3c1
commons-lang@2.4
no fix listed

Open the chart page →

293
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

13,486
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-lang@2.6
commons-lang3@3.10
no fix listed
3.18.0

Open the chart page →

24,930
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
commons-lang3@3.17.0
3.18.0

Open the chart page →

2,826
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
commons-lang@2.6
commons-lang3@3.1
no fix listed
3.18.0

Open the chart page →

8,063
snowplowt3n0.0.11 of 1See more

snowplow t3n 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
commons-lang3@3.5
3.18.0

Open the chart page →

2,269
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

9,102
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

9,102
tocktock0.6.32 of 9See more

tock tock 0.6.3

2 of the 9 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
tock/build_worker:25.10.7080cb6b08d5b
commons-lang3@3.3.1
3.18.0
tock/nlp_api:25.10.7c04ffe67b977
commons-lang3@3.3.1
3.18.0

Open the chart page →

12,907
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
commons-lang@2.6
commons-lang3@3.1
no fix listed
3.18.0

Open the chart page →

15,970
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
commons-lang@2.6
no fix listed

Open the chart page →

41,427
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

7,835
workflows-aggregatorworkflows-aggregatorVerified publisher0.16.91 of 1See more

workflows-aggregator workflows-aggregator 0.16.9

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
commons-lang3@3.16.0
3.18.0

Open the chart page →

1,290
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
commons-lang@2.6
no fix listed

Open the chart page →

2,168
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
commons-lang@2.6
no fix listed

Open the chart page →

2,326
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
commons-lang@2.6
no fix listed

Open the chart page →

2,853
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

7,713
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
commons-lang@2.6
no fix listed

Open the chart page →

2,221
quotes-provideraccount-serviceVerified publisher0.4.21 of 1See more

quotes-provider account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
commons-lang@2.6
commons-lang3@3.12.0
no fix listed
3.18.0

Open the chart page →

2,205
migrationadeptia-automate-migration5.2.91 of 1See more

migration adeptia-automate-migration 5.2.9

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
commons-lang@2.6
no fix listed

Open the chart page →

395
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
commons-lang@2.6
no fix listed

Open the chart page →

2,476
gotenbergadnoctemVerified publisher0.5.01 of 1See more

gotenberg adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.37.0f29984bd1e22
commons-lang3@3.12.0
3.18.0

Open the chart page →

5,582
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
commons-lang3@3.14.0
3.18.0

Open the chart page →

854
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0

Open the chart page →

1,413
connector-rollout-workerairbyteVerified publisher1.9.21 of 1See more

connector-rollout-worker airbyte 1.9.2

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
commons-lang3@3.14.0
3.18.0

Open the chart page →

829
airbyteairbyte-v2Verified publisher2.2.04 of 10See more

airbyte airbyte-v2 2.2.0

4 of the 10 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
airbyte/bootloader:2.2.0f71cf4e185d5
commons-lang3@3.14.0
3.18.0
airbyte/cron:2.2.0d97b67a1346d
commons-lang3@3.14.0
3.18.0
airbyte/worker:2.2.08060b88b29c8
commons-lang3@3.14.0
3.18.0
airbyte/workload-launcher:2.2.0119be7bfb719
commons-lang3@3.14.0
3.18.0

Open the chart page →

12,473
airbyte-data-planeairbyte-v2Verified publisher2.2.01 of 1See more

airbyte-data-plane airbyte-v2 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
airbyte/workload-launcher:2.2.0119be7bfb719
commons-lang3@3.14.0
3.18.0

Open the chart page →

790
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
commons-lang3@3.8.1
3.18.0

Open the chart page →

4,547
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
commons-lang@2.6
commons-lang3@3.16.0
no fix listed
3.18.0

Open the chart page →

1,748
aktoakto0.2.04 of 7See more

akto akto 0.2.0

4 of the 7 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
commons-lang3@3.8.1
3.18.0
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
commons-lang3@3.8.1
3.18.0
public.ecr.aws/aktosecurity/akto-api-security-runtime:latestfacdfba6d4e4
commons-lang3@3.12.0
3.18.0
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
commons-lang3@3.12.0
3.18.0

Open the chart page →

13,613
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-lang3@3.8.1
3.18.0

Open the chart page →

9,321
akto-hybrid-redactakto1.44.42 of 5See more

akto-hybrid-redact akto 1.44.4

2 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.1_localf2e2d816ef82
commons-lang3@3.13.0
3.18.0
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.1_local75f00caa6f3f
commons-lang3@3.12.0
3.18.0

Open the chart page →

4,777
akto-mini-runtimeakto0.7.221 of 3See more

akto-mini-runtime akto 0.7.22

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
commons-lang3@3.13.0
3.18.0

Open the chart page →

2,741
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtimedigest-pinned4d3a8042c761
commons-lang3@3.13.0
3.18.0

Open the chart page →

3,217
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
commons-lang3@3.12.0
3.18.0

Open the chart page →

6,486
akto-mini-testing-kafkaakto1.42.13 of 5See more

akto-mini-testing-kafka akto 1.42.1

3 of the 5 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
commons-lang3@3.12.0
3.18.0
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
commons-lang3@3.12.0
3.18.0
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:improve-testing-performance8e9d15ed71c7
commons-lang3@3.12.0
3.18.0

Open the chart page →

6,397
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.54.4_localb2b97137aef5
commons-lang3@3.13.0
3.18.0

Open the chart page →

1,826
akto-protectionakto0.1.03 of 4See more

akto-protection akto 0.1.0

3 of the 4 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
aktosecurity/akto-api-protection:localbcd7382c9c1b
commons-lang3@3.12.0
3.18.0
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
commons-lang3@3.8.1
3.18.0
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
commons-lang3@3.8.1
3.18.0

Open the chart page →

11,285
akto-regional-setupakto1.3.11 of 9See more

akto-regional-setup akto 1.3.1

1 of the 9 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
commons-lang3@3.13.0
3.18.0

Open the chart page →

7,603
akto-runtimeakto0.1.81 of 2See more

akto-runtime akto 0.1.8

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
commons-lang3@3.13.0
3.18.0

Open the chart page →

1,411
akto-source-code-analyserakto0.1.52 of 3See more

akto-source-code-analyser akto 0.1.5

2 of the 3 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
commons-lang3@3.12.0
3.18.0
hotavneesh/eclipse-jdtls:latesta4579b163414
commons-lang3@3.14.0
3.18.0

Open the chart page →

4,880
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
commons-lang3@3.12.0
3.18.0

Open the chart page →

5,489
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
commons-lang3@3.8.1
3.18.0

Open the chart page →

3,442
zunivers-ninjaalexpressoVerified publisher1.31.21 of 2See more

zunivers-ninja alexpresso 1.31.2

1 of the 2 container images this version deploys carry CVE-2025-48924.

Container imageDigestPackageFixed in
library/neo4j:5.18.18f01f7bb053e
commons-lang3@3.14.0
3.18.0

Open the chart page →

1,165

Container images carrying it

684 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
apache/skywalking-ui:8.1.067d50e4deff4
commons-lang@2.6
commons-lang3@3.1
no fix listed
3.18.0
1
apache/tika:2.9.0.092d055a84e9e
commons-lang3@3.13.0
3.18.0
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
commons-lang3@3.9
3.18.0
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
commons-lang3@3.12.0
3.18.0
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
commons-lang@2.6
commons-lang3@3.13.0
no fix listed
3.18.0
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
commons-lang3@3.12.0
3.18.0
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
commons-lang3@3.12.0
3.18.0
1
apimap/api:v1.8.11ae2b3ab00177
commons-lang3@3.12.0
3.18.0
1
arturisimo/planner:v1.0fff9de644941
commons-lang3@3.12.0
3.18.0
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
commons-lang@2.6
commons-lang3@3.9
no fix listed
3.18.0
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
commons-lang3@3.1
3.18.0
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
commons-lang@2.6
no fix listed
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
assistiot/identity-manager_kc:latest0df4b4fa899a
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
commons-lang@2.6
commons-lang3@3.8.1
no fix listed
3.18.0
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
commons-lang@2.4
commons-lang3@3.12.0
no fix listed
3.18.0
1
atlassian/bitbucket:10.2.705933f2b1cfd
commons-lang3@3.17.0
3.18.0
1
atlassian/confluence-server:7.10.03b9222ab32ef
commons-lang@2.6
commons-lang3@3.8
no fix listed
3.18.0
1
atlassian/crowd:5.2.2ebf761c7d437
commons-lang@2.6
commons-lang3@3.8
no fix listed
3.18.0
1
atlassian/jira-software:8.14.037bc46cbec1a
commons-lang@2.4
commons-lang3@3.8
no fix listed
3.18.0
1
atlassian/jira-software:9.7.264a75aa4ec4e
commons-lang@2.5
commons-lang3@3.5
no fix listed
3.18.0
1
atlassian/jira-software:11.3.11e5548cd4eea8
commons-lang@2.4
no fix listed
1
atomix/atomix:3.1.127738ff4f5c63
commons-lang3@3.7
3.18.0
1
audig/clamapi:2.1.62c3fe34ee430
commons-lang3@3.10
3.18.0
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
commons-lang@2.6
commons-lang3@3.7
no fix listed
3.18.0
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
commons-lang3@3.11
3.18.0
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
commons-lang3@3.12.0
3.18.0
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
commons-lang3@3.12.0
3.18.0
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
commons-lang3@3.9
3.18.0
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
commons-lang3@3.8.1
3.18.0
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
commons-lang3@3.8.1
3.18.0
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
commons-lang3@3.8.1
3.18.0
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
commons-lang@2.6
commons-lang3@3.11
no fix listed
3.18.0
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
commons-lang3@3.14.0
3.18.0
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
commons-lang3@3.17.0
3.18.0
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
commons-lang@2.6
commons-lang3@3.17.0
no fix listed
3.18.0
1
bivas/presto:0.19605545994f806
commons-lang@2.4
commons-lang3@3.4
no fix listed
3.18.0
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
commons-lang3@3.14.0
3.18.0
1
bluerange/bluerange:26.1.307c8f73b55df
commons-lang3@3.17.0
3.18.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
commons-lang3@3.8
libcommons-lang3-java@3.8-2
3.18.0
3.8-2ubuntu0.1~esm1
1
budibase/database:2.1.0d90f656261c9
commons-lang@2.6
no fix listed
1
camunda/zeebe:8.4.5ab5abc09e407
commons-lang3@3.14.0
3.18.0
1
castlemock/castlemock:latestb7f3f1527ba9
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
commons-lang3@3.17.0
3.18.0
1
choerodon/event-store-service:0.8.03c94c97f6f69
commons-lang@2.6
no fix listed
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
commons-lang3@3.15.0
3.18.0
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
commons-lang@2.6
commons-lang3@3.14.0
no fix listed
3.18.0
1
codetogether/codetogether:latest4348c8a38752
commons-lang3@3.4
3.18.0
1
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
commons-lang3@3.9
3.18.0
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
commons-lang3@3.9
3.18.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.