StackRadar

CVE-2025-68161

Medium

Advisory

Published 18 Dec 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
254
of 17,781 indexed, latest versions
Container images
241
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j does not verify the TLS hostname in its Socket Appender

Carried by container images the latest versions of 254 of 17,781 indexed charts deploy, on 241 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.6.2, 2.8.2, 2.9.0, 2.9.1+32 more2.25.3241
OSV records
GHSA-vc5p-v9hr-52mj

Charts affected

254 by stars
ChartLatestAffected imagesRadar Score
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
2.25.3

Open the chart page →

6,213
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
log4j-core@2.21.0
2.25.3

Open the chart page →

9,381
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
log4j-core@2.20.0
2.25.3

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-68161.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
log4j-core@2.17.2
2.25.3

Open the chart page →

5,846

Container images carrying it

241 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j-core@2.6.2
2.25.3
4
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-core@2.17.2
2.25.3
4
library/solr:8.11.18c5f7881cebb
log4j-core@2.16.0
2.25.3
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.25.3
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
log4j-core@2.10.0
2.25.3
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
log4j-core@2.23.1
2.25.3
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
log4j-core@2.19.0
2.25.3
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
log4j-core@2.11.1
2.25.3
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
log4j-core@2.6.2
2.25.3
2
hazelcast/hazelcast:5.5.05dd5d31c7a06
log4j-core@2.23.1
2.25.3
2
hazelcast/management-center:5.5.2991ddb27c251
log4j-core@2.23.1
2.25.3
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
log4j-core@2.17.2
2.25.3
2
inaccel/coral:2.18c53744ed70b
log4j-core@2.23.1
2.25.3
2
library/elasticsearch:7.17.35e6ac15bf6a5
log4j-core@2.17.1
2.25.3
2
library/elasticsearch:8.19.1289729a95066a
log4j-core@2.25.0
2.25.3
2
library/neo4j:5.20.052d3dec8d455
log4j-core@2.20.0
2.25.3
2
library/neo4j:4.3.2-enterprise56a9453c4064
log4j-core@2.14.0
2.25.3
2
mbentley/omada-controller:4.3f4e682274bed
log4j-core@2.23.1
2.25.3
2
metabase/metabase:v0.45.21fb334ce4820
log4j-core@2.17.1
2.25.3
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
log4j-core@2.17.2
2.25.3
2
opensearchproject/opensearch:2.1.04254021a8c71
log4j-core@2.17.1
2.25.3
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
log4j-core@2.21.0
2.25.3
2
opensearchproject/opensearch:1.1.0967d7f57f72f
log4j-core@2.13.0
2.25.3
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
log4j-core@2.11.2
2.25.3
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-core@2.24.3
2.25.3
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
log4j-core@2.24.3
2.25.3
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
log4j-core@2.17.2
2.25.3
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
log4j-core@2.17.2
2.25.3
2
2martens/configserver:latestbf1cdb80239d
log4j-core@2.23.1
2.25.3
1
2martens/timetable:latestbd1ba6ab84c9
log4j-core@2.25.1
2.25.3
1
2martens/wahlrecht:latestba2c3040dab0
log4j-core@2.25.1
2.25.3
1
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
log4j-core@2.17.1
2.25.3
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
log4j-core@2.20.0
2.25.3
1
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
log4j-core@2.23.1
2.25.3
1
airbyte/cron:0.40.17caf4f551c546
log4j-core@2.17.2
2.25.3
1
aktosecurity/data-ingestion-service213aded7adc5
log4j-core@2.24.2
2.25.3
1
alfio/alf.io:2.0-M5-26060c836a081446
log4j-core@2.24.3
2.25.3
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
log4j-core@2.24.1
2.25.3
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
log4j-core@2.11.1
2.25.3
1
apache/activemq-artemis:2.44.00305c26f19ed
log4j-core@2.25.2
2.25.3
1
apache/activemq-artemis:2.37.0bae523439ee3
log4j-core@2.23.1
2.25.3
1
apache/druid:29.0.10cef139b6bf1
log4j-core@2.18.0
2.25.3
1
apache/hertzbeat:1.8.075d48a62748f
log4j-core@2.24.3
2.25.3
1
apacheignite/ignite:2.7.0d7deab68b8fa
log4j-core@2.11.0
2.25.3
1
apache/kafka:4.1.0bff074a5d005
log4j-core@2.24.3
2.25.3
1
apachepinot/pinot:latest-jdk110018bb04ced7
log4j-core@2.17.1
2.25.3
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
log4j-core@2.18.0
2.25.3
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
log4j-core@2.17.1
2.25.3
1
apachepulsar/pulsar:2.6.14db6ff0b4045
log4j-core@2.10.0
2.25.3
1
apachepulsar/pulsar:3.0.79c9947de139d
log4j-core@2.18.0
2.25.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.