StackRadar

CVE-2026-49844

Medium

Advisory

Published 11 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
603
of 17,781 indexed, latest versions
Container images
570
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Carried by container images the latest versions of 603 of 17,781 indexed charts deploy, on 570 images.

Affected packageAffected versionsFixed inImages
log4j-apimaven2.13.2, 2.13.3, 2.14.0, 2.14.1+24 more2.25.5, 2.26.1570
OSV records
GHSA-qv9r-c865-cp47

Charts affected

603 by stars
ChartLatestAffected imagesRadar Score
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
metabasecasemark2.16.111 of 1See more

metabase casemark 2.16.11

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
log4j-api@2.17.1
2.25.5

Open the chart page →

1,215
Chart-Oracle-Host-Appchart-oracle-host-appVerified publisher0.1.21 of 1See more

Chart-Oracle-Host-App chart-oracle-host-app 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
stanislovesid/oracle-host-app:14fe1ed26e194
log4j-api@2.14.1
2.25.5

Open the chart page →

2,434
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
log4j-api@2.17.2
2.25.5

Open the chart page →

6,447
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
robotshop/rs-shipping:latest89753ab48919
log4j-api@2.13.3
2.25.5

Open the chart page →

29,555
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
log4j-api@2.24.3
2.25.5

Open the chart page →

4,578
clamapicnieg2.0.51 of 2See more

clamapi cnieg 2.0.5

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
audig/clamapi:2.1.62c3fe34ee430
log4j-api@2.13.3
2.25.5

Open the chart page →

4,671
ganttcnieg2.1.01 of 1See more

gantt cnieg 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
cnieg/gantt:1.1.2d4b478d76f2a
log4j-api@2.17.2
2.25.5

Open the chart page →

2,390
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
log4j-api@2.17.2
2.25.5

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
log4j-api@2.17.2
2.25.5

Open the chart page →

7,963
consumer-helmconsumer-app-helm-chart0.1.01 of 1See more

consumer-helm consumer-app-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
j4ckhunter/consumer:1.00bb7a429e3e75
log4j-api@2.17.2
2.25.5

Open the chart page →

2,564
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
dadosfake-helmdadosfake-app0.1.01 of 1See more

dadosfake-helm dadosfake-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
log4j-api@2.21.1
2.25.5

Open the chart page →

2,064
pagesdalston-pages1.0.01 of 3See more

pages dalston-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
pagesdaman-dell-kuber1.0.01 of 3See more

pages daman-dell-kuber 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
damap-chartdamapVerified publisher0.3.01 of 5See more

damap-chart damap 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
log4j-api@2.23.1
2.25.5

Open the chart page →

13,936
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
log4j-api@2.24.3
2.25.5

Open the chart page →

3,547
kafka-connectdasmeta1.0.21 of 3See more

kafka-connect dasmeta 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
confluentinc/cp-schema-registry:latestf0cfd047a839
log4j-api@2.25.4
2.25.5

Open the chart page →

532
pagesdavid-pages1.0.01 of 3See more

pages david-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
pagesdebasish-pages1.0.01 of 3See more

pages debasish-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
amartinm82/planner:v2.01184353ff57b
log4j-api@2.13.3
2.25.5
oscarsotosanchez/toposervice:v1.0d4d020e9f272
log4j-api@2.13.3
2.25.5

Open the chart page →

27,550
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
epam/ai-dial-admin-backend:0.20.00ac5be78d7c2
log4j-api@2.25.4
2.25.5

Open the chart page →

4,046
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
log4j-api@2.24.3
2.25.5

Open the chart page →

1,269
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
oscarsotosanchez/toposervice:v1.0d4d020e9f272
log4j-api@2.13.3
2.25.5

Open the chart page →

24,656
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
log4j-api@2.17.0
2.25.5

Open the chart page →

2,237
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
log4j-api@2.21.1
2.25.5

Open the chart page →

2,512
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
log4j-api@2.21.1
2.25.5

Open the chart page →

3,888
pagesedgwarepages1.0.01 of 3See more

pages edgwarepages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
log4j-api@2.23.1
2.25.5

Open the chart page →

7,268
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-api@2.17.2
2.25.5

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-api@2.17.2
2.25.5

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-api@2.17.2
2.25.5

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-api@2.17.2
2.25.5

Open the chart page →

4,033
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
log4j-api@2.17.2
2.25.5

Open the chart page →

2,942
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
log4j-api@2.17.1
2.25.5

Open the chart page →

10,564
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
oscarsotosanchez/planner:v1.0730c00a099b8
log4j-api@2.13.3
2.25.5
oscarsotosanchez/toposervice:v1.0d4d020e9f272
log4j-api@2.13.3
2.25.5

Open the chart page →

27,291
eoloPlanteolo-plannerVerified publisher0.1.02 of 7See more

eoloPlant eolo-planner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
log4j-api@2.19.0
2.25.5
mastercloudapps/planner:v1.2340a950b311b2
log4j-api@2.14.1
2.25.5

Open the chart page →

27,537
eoloplannereoloplannerVerified publisher0.1.02 of 7See more

eoloplanner eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
log4j-api@2.14.1
2.25.5
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5

Open the chart page →

32,205
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.02 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
log4j-api@2.19.0
2.25.5
mastercloudapps/planner:v1.2340a950b311b2
log4j-api@2.14.1
2.25.5

Open the chart page →

27,537
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
franrobles8/planner:v3.099985392d63c
log4j-api@2.13.3
2.25.5
oscarsotosanchez/toposervice:v1.0d4d020e9f272
log4j-api@2.13.3
2.25.5

Open the chart page →

27,256
eoloplannereoloplanner-molynx-gat0.1.02 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5
molynx/planner:v1441c9f52f092
log4j-api@2.14.1
2.25.5

Open the chart page →

28,482
eolo-plannereolo-planner-repo0.1.02 of 7See more

eolo-planner eolo-planner-repo 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
arturisimo/planner:v1.0fff9de644941
log4j-api@2.14.1
2.25.5
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5

Open the chart page →

27,096
eoloplanteoloplant1.0.02 of 7See more

eoloplant eoloplant 1.0.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
log4j-api@2.19.0
2.25.5
mastercloudapps/planner:v1.2340a950b311b2
log4j-api@2.14.1
2.25.5

Open the chart page →

27,537
eoloplantseoloplants-urjcVerified publisher0.1.02 of 7See more

eoloplants eoloplants-urjc 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5
lourdesmorente/new-planner:1.0.0608745878cdb
log4j-api@2.14.1
2.25.5

Open the chart page →

27,721
servereoloserverVerified publisher0.1.02 of 7See more

server eoloserver 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
log4j-api@2.14.1
2.25.5
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5

Open the chart page →

32,205
dshackleethereum-helm-chartsVerified publisher0.1.91 of 2See more

dshackle ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.14.0126f0ae0b388
log4j-api@2.17.0
2.25.5

Open the chart page →

2,021
web3signerethereum-helm-chartsVerified publisher1.0.61 of 4See more

web3signer ethereum-helm-charts 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
consensys/web3signer:latestf146a51a1ba3
log4j-api@2.25.4
2.25.5

Open the chart page →

1,997
spring-boot-adminevryfs-ossVerified publisher0.1.101 of 1See more

spring-boot-admin evryfs-oss 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
log4j-api@2.17.2
2.25.5

Open the chart page →

5,998

Container images carrying it

570 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
folioci/edge-oai-pmh:latesteedfcbc29792
log4j-api@2.23.1
2.25.5
1
folioci/edge-orders:latest1ef654ee9f23
log4j-api@2.25.4
2.25.5
1
folioci/edge-patron:latest682b852e056d
log4j-api@2.23.0
2.25.5
1
folioci/edge-rtac:latest15ef73b1abd0
log4j-api@2.25.3
2.25.5
1
folioci/mod-aes:latest6d67e9564270
log4j-api@2.14.1
2.25.5
1
folioci/mod-agreements:latest29c3f233a498
log4j-api@2.17.2
2.25.5
1
folioci/mod-audit:latest88f40730ed45
log4j-api@2.26.0
2.26.1
1
folioci/mod-authtoken:latest995a25a33133
log4j-api@2.24.3
2.25.5
1
folioci/mod-calendar:latest22f65982efd7
log4j-api@2.25.4
2.25.5
1
folioci/mod-circulation:latest3eecd2ac2d8a
log4j-api@2.24.3
2.25.5
1
folioci/mod-circulation-storage:latest6bdddcafbc0f
log4j-api@2.20.0
2.25.5
1
folioci/mod-codex-ekb:latest235a3fa4adc9
log4j-api@2.19.0
2.25.5
1
folioci/mod-codex-inventory:latest6d53ed758fd1
log4j-api@2.17.2
2.25.5
1
folioci/mod-codex-mux:latestd4138abfd30d
log4j-api@2.17.2
2.25.5
1
folioci/mod-configuration:latestdd0cdc89670a
log4j-api@2.25.4
2.25.5
1
folioci/mod-copycat:latest1513fad2b799
log4j-api@2.25.4
2.25.5
1
folioci/mod-courses:latest68ca414f5596
log4j-api@2.24.3
2.25.5
1
folioci/mod-data-export:latest0cc86bf09755
log4j-api@2.25.3
2.25.5
1
folioci/mod-data-export-spring:latestf1d7caf4544b
log4j-api@2.25.3
2.25.5
1
folioci/mod-data-export-worker:latest1ad1811c9b37
log4j-api@2.25.3
2.25.5
1
folioci/mod-data-import-converter-storage:latest3028f333778f
log4j-api@2.17.2
2.25.5
1
folioci/mod-ebsconet:latest3ae8cb99daa3
log4j-api@2.25.2
2.25.5
1
folioci/mod-email:latest79ea8e2e7ebf
log4j-api@2.25.3
2.25.5
1
folioci/mod-erm-usage-harvester:latest2d6767933c59
log4j-api@2.25.4
2.25.5
1
folioci/mod-eusage-reports:latest15de67587091
log4j-api@2.25.3
2.25.5
1
folioci/mod-event-config:latest0192adad3897
log4j-api@2.26.0
2.26.1
1
folioci/mod-feesfines:latestfe3a7049f2fb
log4j-api@2.24.3
2.25.5
1
folioci/mod-finance:latest14450bc15430
log4j-api@2.26.0
2.26.1
1
folioci/mod-finance-storage:latest4bc4057abaea
log4j-api@2.26.0
2.26.1
1
folioci/mod-gobi:latestc58c989dac44
log4j-api@2.26.0
2.26.1
1
folioci/mod-inn-reach:latestcc8584e43382
log4j-api@2.19.0
2.25.5
1
folioci/mod-inventory-update:latestba84812b4d58
log4j-api@2.24.3
2.25.5
1
folioci/mod-invoice:latest45b7b13e81e1
log4j-api@2.26.0
2.26.1
1
folioci/mod-ldp:latestb55696fd9065
log4j-api@2.21.1
2.25.5
1
folioci/mod-licenses:latestcfd6109bf477
log4j-api@2.17.2
2.25.5
1
folioci/mod-login:latest88de493f86db
log4j-api@2.24.3
2.25.5
1
folioci/mod-login-saml:latest5f3358ccaa0f
log4j-api@2.25.4
2.25.5
1
folioci/mod-ncip:latest8ed83674352b
log4j-api@2.20.0
2.25.5
1
folioci/mod-notify:latesta8c1a90005fc
log4j-api@2.26.0
2.26.1
1
folioci/mod-oa:latestae3b069d4ba5
log4j-api@2.17.2
2.25.5
1
folioci/mod-oai-pmh:latest5cd5ef063f2a
log4j-api@2.24.3
2.25.5
1
folioci/mod-orders:latestfc4528220fb8
log4j-api@2.26.0
2.26.1
1
folioci/mod-orders-storage:latestceeaacc3bf16
log4j-api@2.26.0
2.26.1
1
folioci/mod-organizations:latest7dc9ccf3d937
log4j-api@2.25.4
2.25.5
1
folioci/mod-organizations-storage:lateste46892405fde
log4j-api@2.26.0
2.26.1
1
folioci/mod-password-validator:latestb31d75f2bf7b
log4j-api@2.25.4
2.25.5
1
folioci/mod-patron:latest5f213acfe2f8
log4j-api@2.24.3
2.25.5
1
folioci/mod-patron-blocks:latestde7318069a67
log4j-api@2.24.3
2.25.5
1
folioci/mod-permissions:latest5363e98c6299
log4j-api@2.25.4
2.25.5
1
folioci/mod-pubsub:latest0a4fa4ad5d72
log4j-api@2.24.0
2.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.