StackRadar

CVE-2026-1225

Low

Advisory

Published 22 Jan 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
1.8
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
452
of 17,787 indexed, latest versions
Container images
425
deployed by those charts
Fix available
1 of 1
affected package

Logback allows an attacker to instantiate classes already present on the class path

Carried by container images the latest versions of 452 of 17,787 indexed charts deploy, on 425 images.

Affected packageAffected versionsFixed inImages
logback-coremaven1.0.11, 1.0.13, 1.1.2, 1.1.3+38 more1.5.25425
OSV records
GHSA-qqpg-mvqg-649v

Charts affected

452 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-1225.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
logback-core@1.4.11
1.5.25

Open the chart page →

11,592
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-1225.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
logback-core@1.5.18
1.5.25

Open the chart page →

1,571

Container images carrying it

425 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
logback-core@1.2.11
1.5.25
1
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
logback-core@1.2.11
1.5.25
1
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
logback-core@1.5.19
1.5.25
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
logback-core@1.2.11
1.5.25
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
logback-core@1.4.11
1.5.25
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
logback-core@1.2.3
1.5.25
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
logback-core@1.4.14
1.5.25
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
logback-core@1.4.14
1.5.25
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
logback-core@1.4.14
1.5.25
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
logback-core@1.4.14
1.5.25
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
logback-core@1.5.9
1.5.25
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
logback-core@1.2.12
1.5.25
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
logback-core@1.2.3
1.5.25
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
logback-core@1.5.9
1.5.25
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.