CVE-2025-68161
MediumAdvisory
Published 18 Dec 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.3
- base score, highest
- EPSS
- 0.008
- 53rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 254
- of 17,781 indexed, latest versions
- Container images
- 241
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Apache Log4j does not verify the TLS hostname in its Socket Appender
Carried by container images the latest versions of 254 of 17,781 indexed charts deploy, on 241 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| log4j-coremaven | 2.6.2, 2.8.2, 2.9.0, 2.9.1+32 more | 2.25.3 | 241 |
- OSV records
- GHSA-vc5p-v9hr-52mj
Charts affected
254 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| is-pattern-1wso2is-pattern1 | 5.11.0 | 1 of 2See more | 6,213 |
| ygdrassil-monitoringygdrassilVerified publisher | 0.4.0 | 1 of 10See more | 9,381 |
| zahori-processzahoriVerified publisher | 1.0.1 | 1 of 1See more | 3,480 |
| zahori-serverzahoriVerified publisher | 1.0.1 | 1 of 2See more | 5,846 |
Container images carrying it
241 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.