CVE-2026-1225
LowAdvisory
Published 22 Jan 2026In the index since 5 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 1.8
- base score, highest
- EPSS
- 0.002
- 5th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 452
- of 17,787 indexed, latest versions
- Container images
- 425
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Logback allows an attacker to instantiate classes already present on the class path
Carried by container images the latest versions of 452 of 17,787 indexed charts deploy, on 425 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| logback-coremaven | 1.0.11, 1.0.13, 1.1.2, 1.1.3+38 more | 1.5.25 | 425 |
- OSV records
- GHSA-qqpg-mvqg-649v
Charts affected
452 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 11,592 |
| language-toolzekker6Verified publisher | 1.12.1 | 1 of 2See more | 1,571 |
Container images carrying it
425 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.