StackRadar

CVE-2025-68161

Medium

Advisory

Published 18 Dec 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
254
of 17,781 indexed, latest versions
Container images
241
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j does not verify the TLS hostname in its Socket Appender

Carried by container images the latest versions of 254 of 17,781 indexed charts deploy, on 241 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.6.2, 2.8.2, 2.9.0, 2.9.1+32 more2.25.3241
OSV records
GHSA-vc5p-v9hr-52mj

Charts affected

254 by stars
ChartLatestAffected imagesRadar Score
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
log4j-core@2.17.2
2.25.3

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
log4j-core@2.17.2
2.25.3

Open the chart page →

7,963
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
log4j-core@2.11.1
2.25.3

Open the chart page →

8,245
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
log4j-core@2.17.0
2.25.3

Open the chart page →

2,237
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-core@2.17.2
2.25.3

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-core@2.17.2
2.25.3

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-core@2.17.2
2.25.3

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-core@2.17.2
2.25.3

Open the chart page →

4,033
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
log4j-core@2.17.2
2.25.3

Open the chart page →

2,942
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
log4j-core@2.17.1
2.25.3

Open the chart page →

10,564
dshackleethereum-helm-chartsVerified publisher0.1.91 of 2See more

dshackle ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.14.0126f0ae0b388
log4j-core@2.17.0
2.25.3

Open the chart page →

2,021
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
log4j-core@2.23.1
2.25.3

Open the chart page →

12,454
scorpio-brokerfiware0.3.31 of 10See more

scorpio-broker fiware 0.3.3

1 of the 10 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
log4j-core@2.11.2
2.25.3

Open the chart page →

55,600
scorpiobrokerfiware0.1.21 of 10See more

scorpiobroker fiware 0.1.2

1 of the 10 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
log4j-core@2.11.2
2.25.3

Open the chart page →

55,600
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
log4j-core@2.19.0
2.25.3

Open the chart page →

24,296
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
log4j-core@2.17.1
2.25.3

Open the chart page →

5,651
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-core@2.24.3
2.25.3

Open the chart page →

3,463
edge-connexionfolio-org0.1.51 of 1See more

edge-connexion folio-org 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/edge-connexion:latestb4863d135524
log4j-core@2.20.0
2.25.3

Open the chart page →

1,132
edge-ncipfolio-org0.1.281 of 1See more

edge-ncip folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/edge-ncip:lateste760dbb81d1a
log4j-core@2.20.0
2.25.3

Open the chart page →

820
edge-oai-pmhfolio-org0.1.311 of 1See more

edge-oai-pmh folio-org 0.1.31

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/edge-oai-pmh:latesteedfcbc29792
log4j-core@2.23.1
2.25.3

Open the chart page →

874
edge-patronfolio-org0.1.281 of 1See more

edge-patron folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/edge-patron:latest682b852e056d
log4j-core@2.23.0
2.25.3

Open the chart page →

905
mod-aesfolio-org0.1.331 of 1See more

mod-aes folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-aes:latest6d67e9564270
log4j-core@2.14.1
2.25.3

Open the chart page →

2,281
mod-authtokenfolio-org0.1.351 of 1See more

mod-authtoken folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-authtoken:latest995a25a33133
log4j-core@2.24.3
2.25.3

Open the chart page →

1,558
mod-circulationfolio-org0.1.351 of 1See more

mod-circulation folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-circulation:latest3eecd2ac2d8a
log4j-core@2.24.3
2.25.3

Open the chart page →

497
mod-circulation-storagefolio-org0.1.351 of 1See more

mod-circulation-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-circulation-storage:latest6bdddcafbc0f
log4j-core@2.20.0
2.25.3

Open the chart page →

658
mod-codex-ekbfolio-org0.1.341 of 1See more

mod-codex-ekb folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-codex-ekb:latest235a3fa4adc9
log4j-core@2.19.0
2.25.3

Open the chart page →

2,113
mod-codex-inventoryfolio-org0.1.341 of 1See more

mod-codex-inventory folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-codex-inventory:latest6d53ed758fd1
log4j-core@2.17.2
2.25.3

Open the chart page →

1,901
mod-codex-muxfolio-org0.1.341 of 1See more

mod-codex-mux folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-codex-mux:latestd4138abfd30d
log4j-core@2.17.2
2.25.3

Open the chart page →

1,755
mod-coursesfolio-org0.1.341 of 1See more

mod-courses folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-courses:latest68ca414f5596
log4j-core@2.24.3
2.25.3

Open the chart page →

1,533
mod-data-import-converter-storagefolio-org0.1.341 of 1See more

mod-data-import-converter-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-data-import-converter-storage:latest3028f333778f
log4j-core@2.17.2
2.25.3

Open the chart page →

2,488
mod-ebsconetfolio-org0.1.31 of 1See more

mod-ebsconet folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-ebsconet:latest3ae8cb99daa3
log4j-core@2.25.2
2.25.3

Open the chart page →

1,203
mod-feesfinesfolio-org0.1.341 of 1See more

mod-feesfines folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-feesfines:latestfe3a7049f2fb
log4j-core@2.24.3
2.25.3

Open the chart page →

663
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
log4j-core@2.19.0
2.25.3

Open the chart page →

512
mod-inventory-updatefolio-org0.1.21 of 1See more

mod-inventory-update folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-inventory-update:latestba84812b4d58
log4j-core@2.24.3
2.25.3

Open the chart page →

878
mod-loginfolio-org0.1.341 of 1See more

mod-login folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-login:latest88de493f86db
log4j-core@2.24.3
2.25.3

Open the chart page →

1,151
mod-marccatfolio-org0.1.301 of 1See more

mod-marccat folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-marccat:latest1b57d690d568
log4j-core@2.10.0
2.25.3

Open the chart page →

6,988
mod-ncipfolio-org0.1.341 of 1See more

mod-ncip folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-ncip:latest8ed83674352b
log4j-core@2.20.0
2.25.3

Open the chart page →

1,103
mod-oai-pmhfolio-org0.1.341 of 1See more

mod-oai-pmh folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-oai-pmh:latest5cd5ef063f2a
log4j-core@2.24.3
2.25.3

Open the chart page →

962
mod-patronfolio-org0.1.341 of 1See more

mod-patron folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-patron:latest5f213acfe2f8
log4j-core@2.24.3
2.25.3

Open the chart page →

827
mod-patron-blocksfolio-org0.1.341 of 1See more

mod-patron-blocks folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-patron-blocks:latestde7318069a67
log4j-core@2.24.3
2.25.3

Open the chart page →

359
mod-pubsubfolio-org0.1.341 of 1See more

mod-pubsub folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-pubsub:latest0a4fa4ad5d72
log4j-core@2.24.0
2.25.3

Open the chart page →

1,009
mod-rtacfolio-org0.1.341 of 1See more

mod-rtac folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-rtac:latestc959b2d6142f
log4j-core@2.24.3
2.25.3

Open the chart page →

665
mod-senderfolio-org0.1.341 of 1See more

mod-sender folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-sender:latestd88a675dddf0
log4j-core@2.25.2
2.25.3

Open the chart page →

818
mod-template-enginefolio-org0.1.341 of 1See more

mod-template-engine folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-template-engine:latestd105c585da30
log4j-core@2.24.3
2.25.3

Open the chart page →

818
mod-users-blfolio-org0.1.351 of 1See more

mod-users-bl folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
folioci/mod-users-bl:latest4e2d96c9340d
log4j-core@2.25.2
2.25.3

Open the chart page →

1,321
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
log4j-core@2.17.2
2.25.3

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
log4j-core@2.17.2
2.25.3

Open the chart page →

11,961
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
log4j-core@2.17.0
2.25.3

Open the chart page →

2,887
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
log4j-core@2.17.1
2.25.3

Open the chart page →

8,923
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.83 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

3 of the 5 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
log4j-core@2.13.3
2.25.3
jingking/geonetwork-hnap:4.2.843e74ab234e1
log4j-core@2.17.2
2.25.3
library/elasticsearch:7.17.1588c2ec10c7f2
log4j-core@2.17.1
2.25.3

Open the chart page →

34,754

Container images carrying it

241 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
voltha/voltha-onos:5.1.8e038acb950d3
log4j-core@2.17.0
2.25.3
1
wavefronthq/proxy:9.2d1064d28f6eb
log4j-core@2.12.1
2.25.3
1
wazuh/wazuh-indexer:4.14.49c344d2b1757
log4j-core@2.21.0
2.25.3
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
log4j-core@2.21.0
2.25.3
1
wazuh/wazuh-indexer:4.14.3b149b30da686
log4j-core@2.21.0
2.25.3
1
xeotek/kadeck:6.3.439a3b37a17c5
log4j-core@2.20.0
2.25.3
1
xeotek/kadeck:4.2.94c6b04d9ce55
log4j-core@2.17.1
2.25.3
1
xetusoss/archiva:v2.2.588f25242b9ee
log4j-core@2.8.2
2.25.3
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
log4j-core@2.20.0
2.25.3
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
log4j-core@2.17.2
2.25.3
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
log4j-core@2.11.1
2.25.3
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
log4j-core@2.24.3
2.25.3
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
log4j-core@2.23.1
2.25.3
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
log4j-core@2.20.0
2.25.3
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
log4j-core@2.17.1
2.25.3
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
log4j-core@2.24.3
2.25.3
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
log4j-core@2.17.2
2.25.3
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
log4j-core@2.17.2
2.25.3
1
ghcr.io/joffreybvn/k8s-geyser:0.0.247f36880072e
log4j-core@2.20.0
2.25.3
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
log4j-core@2.20.0
2.25.3
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
log4j-core@2.17.2
2.25.3
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
log4j-core@2.25.2
2.25.3
1
ghcr.io/open-telemetry/demo:1.12.0-frauddetectionservice77cefdab4d5c
log4j-core@2.21.1
2.25.3
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
log4j-core@2.23.1
2.25.3
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
log4j-core@2.17.1
2.25.3
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
log4j-core@2.23.1
2.25.3
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
log4j-core@2.21.0
2.25.3
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
log4j-core@2.23.1
2.25.3
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
log4j-core@2.21.0
2.25.3
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
log4j-core@2.20.0
2.25.3
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
log4j-core@2.21.1
2.25.3
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
log4j-core@2.24.2
2.25.3
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
log4j-core@2.24.2
2.25.3
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
log4j-core@2.24.3
2.25.3
1
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
log4j-core@2.24.3
2.25.3
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
log4j-core@2.24.3
2.25.3
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
log4j-core@2.24.3
2.25.3
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
log4j-core@2.17.1
2.25.3
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
log4j-core@2.12.1
2.25.3
1
quay.io/strimzi/operator:0.45.158c727cd2e68
log4j-core@2.17.2
2.25.3
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
log4j-core@2.17.2
2.25.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.