Package
kayenta-fips-2026.2
Component
commons-lang3
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable code is bundled and relocated inside a third-party client library's shaded jar rather than resolved as a standalone dependency, so it cannot be reached by the normal dependency-pin mechanism. A fix requires that bundled library to release an update with a patched embedded copy of the affected component; no such release exists yet.
Status