StackRadar

CVE-2026-1225

Low

Advisory

Published 22 Jan 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
1.8
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
451
of 17,781 indexed, latest versions
Container images
424
deployed by those charts
Fix available
1 of 1
affected package

Logback allows an attacker to instantiate classes already present on the class path

Carried by container images the latest versions of 451 of 17,781 indexed charts deploy, on 424 images.

Affected packageAffected versionsFixed inImages
logback-coremaven1.0.11, 1.0.13, 1.1.2, 1.1.3+38 more1.5.25424
OSV records
GHSA-qqpg-mvqg-649v

Charts affected

451 by stars
ChartLatestAffected imagesRadar Score
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-1225.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
logback-core@1.5.18
1.5.25

Open the chart page →

1,571

Container images carrying it

424 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
stakater/stakater-nordmart-review:1.0.35954d2be66e95
logback-core@1.2.11
1.5.25
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
logback-core@1.5.19
1.5.25
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
logback-core@1.2.11
1.5.25
2
1dev/server:11.9.0cd5b12fe5471
logback-core@1.4.14
1.5.25
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
logback-core@1.5.22
1.5.25
1
adagber/planner:v1.0e5c1ed097752
logback-core@1.2.7
1.5.25
1
adityaprasadpathak/myapp:3.07e3b9777362c
logback-core@1.5.6
1.5.25
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
logback-core@1.4.14
1.5.25
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
logback-core@1.4.14
1.5.25
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
logback-core@1.5.18
1.5.25
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
logback-core@1.2.3
1.5.25
1
amartinm82/planner:v2.01184353ff57b
logback-core@1.2.3
1.5.25
1
andrianrf/backoffice-be:latest6036614803d4
logback-core@1.2.12
1.5.25
1
andrianrf/bpjstk-service:latest46abe878d9d8
logback-core@1.2.3
1.5.25
1
andrianrf/bpjstk-simulator:latestb63fdb51d39d
logback-core@1.2.3
1.5.25
1
andrianrf/iso-client:latestba560086ce15
logback-core@1.2.3
1.5.25
1
andrianrf/iso-server:latest7da47f525c7d
logback-core@1.2.3
1.5.25
1
anguda/ant-media:2.5c435285fc241
logback-core@1.2.9
1.5.25
1
apache/camel-k:1.10.43bb13d14f64a
logback-core@1.2.11
1.5.25
1
apache/drill:1.21.11f96558fd292
logback-core@1.3.5
1.5.25
1
apache/hertzbeat:1.8.075d48a62748f
logback-core@1.5.16
1.5.25
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
logback-core@1.5.16
1.5.25
1
apacheignite/ignite:2.7.0d7deab68b8fa
logback-core@1.2.3
1.5.25
1
apache/iotdb:0.11.28647309f95d1
logback-core@1.1.11
1.5.25
1
apache/iotdb:0.13.3-nodeafa47bf1692a
logback-core@1.2.10
1.5.25
1
apache/nifi-registry:1.14.0090b7f87ec7f
logback-core@1.2.3
1.5.25
1
apache/nifi-registry:1.27.063b8e3e40742
logback-core@1.3.14
1.5.25
1
apache/nifi-registry:0.8.0974efa2f21da
logback-core@1.2.3
1.5.25
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
logback-core@1.2.3
1.5.25
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
logback-core@1.2.3
1.5.25
1
apachepulsar/pulsar:2.6.14db6ff0b4045
logback-core@1.2.3
1.5.25
1
apachepulsar/pulsar:3.0.79c9947de139d
logback-core@1.2.3
1.5.25
1
apachepulsar/pulsar:2.9.0d056c89b7131
logback-core@1.2.3
1.5.25
1
apachepulsar/pulsar:2.8.2d538416d5afe
logback-core@1.2.3
1.5.25
1
apache/ranger:2.7.076c176e8a0e4
logback-core@1.3.14
1.5.25
1
apache/rocketmq:5.3.0434d8398f996
logback-core@1.3.5
1.5.25
1
apache/rocketmq:4.9.35ac2a4e0f627
logback-core@1.2.10
1.5.25
1
apache/rocketmq-exporter:0.0.2c8fb51195444
logback-core@1.2.12
1.5.25
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
logback-core@1.2.3
1.5.25
1
apache/shenyu-admin:2.5.1e2be712fc4f4
logback-core@1.2.11
1.5.25
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
logback-core@1.2.11
1.5.25
1
apache/skywalking-ui:9.2.0295f1dc87d98
logback-core@1.2.11
1.5.25
1
apache/skywalking-ui:8.1.067d50e4deff4
logback-core@1.2.3
1.5.25
1
apache/skywalking-ui:8.9.180530f0308a5
logback-core@1.2.3
1.5.25
1
apimap/api:v1.8.11ae2b3ab00177
logback-core@1.2.11
1.5.25
1
aroralalit/student-producer:1.0.02a094f597b36
logback-core@1.2.12
1.5.25
1
arturisimo/planner:v1.0fff9de644941
logback-core@1.2.7
1.5.25
1
arturisimo/webapp-db-java:v2c95524e90b57
logback-core@1.2.10
1.5.25
1
assistiot/automated_configuration:latest23f195a7a26a
logback-core@1.2.11
1.5.25
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
logback-core@1.2.9
1.5.25
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.