StackRadar

CVE-2026-34477

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
238
of 17,781 indexed, latest versions
Container images
226
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

Carried by container images the latest versions of 238 of 17,781 indexed charts deploy, on 226 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.12.1, 2.12.4, 2.13.0, 2.13.2+26 more2.25.4226
OSV records
GHSA-6hg6-v5c8-fphq

Charts affected

238 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
log4j-core@2.19.0
2.25.4

Open the chart page →

6,556
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
log4j-core@2.17.0
2.25.4

Open the chart page →

32,259
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.3b149b30da686
log4j-core@2.21.0
2.25.4

Open the chart page →

11,384
milvusmilvus-helm5.0.271 of 4See more

milvus milvus-helm 5.0.27

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
log4j-core@2.18.0
2.25.4

Open the chart page →

10,670
zipkincarlosjgp0.2.01 of 2See more

zipkin carlosjgp 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.21.060c3970df479
log4j-core@2.12.1
2.25.4

Open the chart page →

3,229
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
log4j-core@2.25.3
2.25.4

Open the chart page →

3,812
neo4jneo4j-helm4.3.2-11 of 1See more

neo4j neo4j-helm 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
log4j-core@2.14.0
2.25.4

Open the chart page →

2,640
metabasedeliveryheroVerified publisher0.14.41 of 1See more

metabase deliveryhero 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
log4j-core@2.17.1
2.25.4

Open the chart page →

2,572
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
log4j-core@2.13.2
2.25.4

Open the chart page →

6,048
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
log4j-core@2.25.0
2.25.4

Open the chart page →

2,283
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
log4j-core@2.17.2
2.25.4

Open the chart page →

8,636
thehivestrangebee-helmOfficialVerified publisher1.0.61 of 7See more

thehive strangebee-helm 1.0.6

1 of the 7 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
log4j-core@2.19.0
2.25.4

Open the chart page →

16,210
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.11.1a7a2076b167e
log4j-core@2.21.0
2.25.4

Open the chart page →

6,168
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
log4j-core@2.18.0
2.25.4

Open the chart page →

7,930
zipkinygqygq2Verified publisher2.1.41 of 4See more

zipkin ygqygq2 2.1.4

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.24197a9692f6a9
log4j-core@2.22.0
2.25.4

Open the chart page →

2,764
seafiledatamateVerified publisher0.6.02 of 6See more

seafile datamate 0.6.0

2 of the 6 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
log4j-core@2.12.4
2.25.4
datamate/seafile-professional:11.0.202dd66b722464
log4j-core@2.18.0
2.25.4

Open the chart page →

27,267
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
log4j-core@2.25.3
2.25.4

Open the chart page →

13,953
hertzbeathertzbeatOfficialVerified publisher1.8.11 of 4See more

hertzbeat hertzbeat 1.8.1

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
log4j-core@2.24.3
2.25.4

Open the chart page →

14,000
kubernetes-loggingkubernetes-logging4.8.02 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

2 of the 6 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
log4j-core@2.17.1
2.25.4
opensearchproject/opensearch:2.10.0c8f3ebd2a934
log4j-core@2.20.0
2.25.4

Open the chart page →

10,530
flinkriskfocus0.2.01 of 1See more

flink riskfocus 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/flink:1.11.2-scala_2.121fe4fb22a2a5
log4j-core@2.12.1
2.25.4

Open the chart page →

3,235
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
log4j-core@2.17.1
2.25.4

Open the chart page →

7,166
opensearchcaptnbpVerified publisher3.1.11 of 2See more

opensearch captnbp 3.1.1

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.19.269588c664014
log4j-core@2.21.0
2.25.4

Open the chart page →

998
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-core@2.24.3
2.25.4

Open the chart page →

4,641
hazelcasthazelcastVerified publisher5.10.22 of 2See more

hazelcast hazelcast 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
log4j-core@2.23.1
2.25.4
hazelcast/management-center:5.5.2991ddb27c251
log4j-core@2.23.1
2.25.4

Open the chart page →

2,634
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
log4j-core@2.17.1
2.25.4

Open the chart page →

7,335
cratedbhmdmph2.0.31 of 2See more

cratedb hmdmph 2.0.3

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/crate:4.7.0c7984a05e15b
log4j-core@2.17.1
2.25.4

Open the chart page →

1,335
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
log4j-core@2.17.2
2.25.4

Open the chart page →

7,901
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
log4j-core@3.0.0-beta3
no fix listed

Open the chart page →

107,811
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/elasticsearch:8.15.0310b9fc03b06
log4j-core@2.12.4
2.25.4

Open the chart page →

13,521
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
log4j-core@2.25.3
2.25.4

Open the chart page →

5,852
kafka-chartsoldevelo-kafka-chart32.4.41 of 1See more

kafka-chart soldevelo-kafka-chart 32.4.4

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
log4j-core@2.24.3
2.25.4

Open the chart page →

2,355
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
log4j-core@2.24.3
2.25.4

Open the chart page →

4,378
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/tika:2.9.0.092d055a84e9e
log4j-core@2.20.0
2.25.4

Open the chart page →

19,691
tikaapache-tika3.2.21 of 1See more

tika apache-tika 3.2.2

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/tika:3.2.2.0-fullffab324253ed
log4j-core@2.25.1
2.25.4

Open the chart page →

437
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
log4j-core@2.13.0
2.25.4

Open the chart page →

10,730
cp-schema-registrycp-schema-registryVerified publisher1.0.01 of 1See more

cp-schema-registry cp-schema-registry 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
log4j-core@2.24.3
2.25.4

Open the chart page →

1,864
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
log4j-core@2.17.1
2.25.4

Open the chart page →

38,346
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
log4j-core@2.21.0
2.25.4

Open the chart page →

52,635
neo4j-communityequinor-charts1.2.51 of 1See more

neo4j-community equinor-charts 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/neo4j:4.2.4348e3f56faa2
log4j-core@2.14.0
2.25.4

Open the chart page →

2,751
featurehubfeaturehub4.1.63 of 7See more

featurehub featurehub 4.1.6

3 of the 7 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
featurehub/dacha2:1.9.1c8d5551b5e40
log4j-core@2.20.0
2.25.4
featurehub/edge:1.9.198ad426737f6
log4j-core@2.20.0
2.25.4
featurehub/mr:1.9.1477d8bf771a9
log4j-core@2.20.0
2.25.4

Open the chart page →

8,240
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
log4j-core@2.23.1
2.25.4

Open the chart page →

11,553
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
log4j-core@2.17.1
2.25.4

Open the chart page →

6,165
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
log4j-core@2.20.0
2.25.4

Open the chart page →

4,679
iceberg-resticeberg-rest-fixture0.0.11 of 2See more

iceberg-rest iceberg-rest-fixture 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
log4j-core@2.20.0
2.25.4

Open the chart page →

3,470
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
log4j-core@2.17.1
2.25.4

Open the chart page →

17,284
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
salehmir/jesse:1.10.101afa95f979e9
log4j-core@2.17.1
2.25.4

Open the chart page →

3,421
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
log4j-core@2.17.2
2.25.4

Open the chart page →

2,067
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.01 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
log4j-core@2.20.0
2.25.4

Open the chart page →

14,130
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
log4j-core@2.17.1
2.25.4

Open the chart page →

12,019
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
log4j-core@2.17.1
2.25.4

Open the chart page →

13,479

Container images carrying it

226 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-core@2.17.2
2.25.4
4
library/solr:8.11.18c5f7881cebb
log4j-core@2.16.0
2.25.4
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.25.4
2
apache/druid:37.0.00116fb802786
log4j-core@2.25.3
2.25.4
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
log4j-core@2.23.1
2.25.4
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
log4j-core@2.19.0
2.25.4
2
hazelcast/hazelcast:5.5.05dd5d31c7a06
log4j-core@2.23.1
2.25.4
2
hazelcast/management-center:5.5.2991ddb27c251
log4j-core@2.23.1
2.25.4
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
log4j-core@2.17.2
2.25.4
2
inaccel/coral:2.18c53744ed70b
log4j-core@2.23.1
2.25.4
2
library/elasticsearch:7.17.35e6ac15bf6a5
log4j-core@2.17.1
2.25.4
2
library/elasticsearch:8.19.1289729a95066a
log4j-core@2.25.0
2.25.4
2
library/neo4j:5.20.052d3dec8d455
log4j-core@2.20.0
2.25.4
2
library/neo4j:4.3.2-enterprise56a9453c4064
log4j-core@2.14.0
2.25.4
2
mbentley/omada-controller:4.3f4e682274bed
log4j-core@2.23.1
2.25.4
2
metabase/metabase:v0.45.21fb334ce4820
log4j-core@2.17.1
2.25.4
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
log4j-core@2.17.2
2.25.4
2
opensearchproject/opensearch:2.1.04254021a8c71
log4j-core@2.17.1
2.25.4
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
log4j-core@2.21.0
2.25.4
2
opensearchproject/opensearch:1.1.0967d7f57f72f
log4j-core@2.13.0
2.25.4
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-core@2.24.3
2.25.4
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
log4j-core@2.24.3
2.25.4
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
log4j-core@2.17.2
2.25.4
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
log4j-core@2.17.2
2.25.4
2
2martens/configserver:latestbf1cdb80239d
log4j-core@2.23.1
2.25.4
1
2martens/timetable:latestbd1ba6ab84c9
log4j-core@2.25.1
2.25.4
1
2martens/wahlrecht:latestba2c3040dab0
log4j-core@2.25.1
2.25.4
1
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
log4j-core@2.17.1
2.25.4
1
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
log4j-core@2.25.3
2.25.4
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
log4j-core@2.20.0
2.25.4
1
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
log4j-core@2.23.1
2.25.4
1
airbyte/cron:0.40.17caf4f551c546
log4j-core@2.17.2
2.25.4
1
aktosecurity/data-ingestion-service213aded7adc5
log4j-core@2.24.2
2.25.4
1
alfio/alf.io:2.0-M5-26060c836a081446
log4j-core@2.24.3
2.25.4
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
log4j-core@2.24.1
2.25.4
1
apache/activemq-artemis:2.44.00305c26f19ed
log4j-core@2.25.2
2.25.4
1
apache/activemq-artemis:2.37.0bae523439ee3
log4j-core@2.23.1
2.25.4
1
apache/druid:29.0.10cef139b6bf1
log4j-core@2.18.0
2.25.4
1
apache/hertzbeat:1.8.075d48a62748f
log4j-core@2.24.3
2.25.4
1
apache/kafka:4.1.0bff074a5d005
log4j-core@2.24.3
2.25.4
1
apachepinot/pinot:latest-jdk110018bb04ced7
log4j-core@2.17.1
2.25.4
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
log4j-core@2.18.0
2.25.4
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
log4j-core@2.17.1
2.25.4
1
apachepulsar/pulsar:3.0.79c9947de139d
log4j-core@2.18.0
2.25.4
1
apachepulsar/pulsar:2.9.0d056c89b7131
log4j-core@2.14.0
2.25.4
1
apachepulsar/pulsar:2.8.2d538416d5afe
log4j-core@2.17.0
2.25.4
1
apache/skywalking-oap-server:9.2.0133d35d2c263
log4j-core@2.17.1
2.25.4
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
log4j-core@2.15.0
2.25.4
1
apache/tika:2.9.0.092d055a84e9e
log4j-core@2.20.0
2.25.4
1
apache/tika:3.2.2.0-fullffab324253ed
log4j-core@2.25.1
2.25.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.