StackRadar

CVE-2026-34477

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
238
of 17,781 indexed, latest versions
Container images
226
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

Carried by container images the latest versions of 238 of 17,781 indexed charts deploy, on 226 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.12.1, 2.12.4, 2.13.0, 2.13.2+26 more2.25.4226
OSV records
GHSA-6hg6-v5c8-fphq

Charts affected

238 by stars
ChartLatestAffected imagesRadar Score
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
log4j-core@2.23.1
2.25.4

Open the chart page →

12,454
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
log4j-core@2.19.0
2.25.4

Open the chart page →

24,296
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
log4j-core@2.17.1
2.25.4

Open the chart page →

5,651
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-core@2.24.3
2.25.4

Open the chart page →

3,463
edge-connexionfolio-org0.1.51 of 1See more

edge-connexion folio-org 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/edge-connexion:latestb4863d135524
log4j-core@2.20.0
2.25.4

Open the chart page →

1,132
edge-ncipfolio-org0.1.281 of 1See more

edge-ncip folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/edge-ncip:lateste760dbb81d1a
log4j-core@2.20.0
2.25.4

Open the chart page →

820
edge-oai-pmhfolio-org0.1.311 of 1See more

edge-oai-pmh folio-org 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/edge-oai-pmh:latesteedfcbc29792
log4j-core@2.23.1
2.25.4

Open the chart page →

874
edge-patronfolio-org0.1.281 of 1See more

edge-patron folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/edge-patron:latest682b852e056d
log4j-core@2.23.0
2.25.4

Open the chart page →

905
edge-rtacfolio-org0.1.281 of 1See more

edge-rtac folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/edge-rtac:latest15ef73b1abd0
log4j-core@2.25.3
2.25.4

Open the chart page →

1,259
mod-aesfolio-org0.1.331 of 1See more

mod-aes folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-aes:latest6d67e9564270
log4j-core@2.14.1
2.25.4

Open the chart page →

2,281
mod-authtokenfolio-org0.1.351 of 1See more

mod-authtoken folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-authtoken:latest995a25a33133
log4j-core@2.24.3
2.25.4

Open the chart page →

1,558
mod-circulationfolio-org0.1.351 of 1See more

mod-circulation folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-circulation:latest3eecd2ac2d8a
log4j-core@2.24.3
2.25.4

Open the chart page →

497
mod-circulation-storagefolio-org0.1.351 of 1See more

mod-circulation-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-circulation-storage:latest6bdddcafbc0f
log4j-core@2.20.0
2.25.4

Open the chart page →

658
mod-codex-ekbfolio-org0.1.341 of 1See more

mod-codex-ekb folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-codex-ekb:latest235a3fa4adc9
log4j-core@2.19.0
2.25.4

Open the chart page →

2,113
mod-codex-inventoryfolio-org0.1.341 of 1See more

mod-codex-inventory folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-codex-inventory:latest6d53ed758fd1
log4j-core@2.17.2
2.25.4

Open the chart page →

1,901
mod-codex-muxfolio-org0.1.341 of 1See more

mod-codex-mux folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-codex-mux:latestd4138abfd30d
log4j-core@2.17.2
2.25.4

Open the chart page →

1,755
mod-coursesfolio-org0.1.341 of 1See more

mod-courses folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-courses:latest68ca414f5596
log4j-core@2.24.3
2.25.4

Open the chart page →

1,533
mod-data-exportfolio-org0.1.401 of 1See more

mod-data-export folio-org 0.1.40

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-data-export:latest0cc86bf09755
log4j-core@2.25.3
2.25.4

Open the chart page →

1,393
mod-data-export-springfolio-org0.1.41 of 1See more

mod-data-export-spring folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-data-export-spring:latestf1d7caf4544b
log4j-core@2.25.3
2.25.4

Open the chart page →

1,253
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
log4j-core@2.25.3
2.25.4

Open the chart page →

1,214
mod-data-import-converter-storagefolio-org0.1.341 of 1See more

mod-data-import-converter-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-data-import-converter-storage:latest3028f333778f
log4j-core@2.17.2
2.25.4

Open the chart page →

2,488
mod-ebsconetfolio-org0.1.31 of 1See more

mod-ebsconet folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-ebsconet:latest3ae8cb99daa3
log4j-core@2.25.2
2.25.4

Open the chart page →

1,203
mod-emailfolio-org0.1.341 of 1See more

mod-email folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-email:latest79ea8e2e7ebf
log4j-core@2.25.3
2.25.4

Open the chart page →

866
mod-eusage-reportsfolio-org0.1.21 of 1See more

mod-eusage-reports folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-eusage-reports:latest15de67587091
log4j-core@2.25.3
2.25.4

Open the chart page →

1,224
mod-feesfinesfolio-org0.1.341 of 1See more

mod-feesfines folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-feesfines:latestfe3a7049f2fb
log4j-core@2.24.3
2.25.4

Open the chart page →

663
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
log4j-core@2.19.0
2.25.4

Open the chart page →

512
mod-inventory-updatefolio-org0.1.21 of 1See more

mod-inventory-update folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-inventory-update:latestba84812b4d58
log4j-core@2.24.3
2.25.4

Open the chart page →

878
mod-loginfolio-org0.1.341 of 1See more

mod-login folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-login:latest88de493f86db
log4j-core@2.24.3
2.25.4

Open the chart page →

1,151
mod-ncipfolio-org0.1.341 of 1See more

mod-ncip folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-ncip:latest8ed83674352b
log4j-core@2.20.0
2.25.4

Open the chart page →

1,103
mod-oai-pmhfolio-org0.1.341 of 1See more

mod-oai-pmh folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-oai-pmh:latest5cd5ef063f2a
log4j-core@2.24.3
2.25.4

Open the chart page →

962
mod-patronfolio-org0.1.341 of 1See more

mod-patron folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-patron:latest5f213acfe2f8
log4j-core@2.24.3
2.25.4

Open the chart page →

827
mod-patron-blocksfolio-org0.1.341 of 1See more

mod-patron-blocks folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-patron-blocks:latestde7318069a67
log4j-core@2.24.3
2.25.4

Open the chart page →

359
mod-pubsubfolio-org0.1.341 of 1See more

mod-pubsub folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-pubsub:latest0a4fa4ad5d72
log4j-core@2.24.0
2.25.4

Open the chart page →

1,009
mod-rtacfolio-org0.1.341 of 1See more

mod-rtac folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-rtac:latestc959b2d6142f
log4j-core@2.24.3
2.25.4

Open the chart page →

665
mod-senderfolio-org0.1.341 of 1See more

mod-sender folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-sender:latestd88a675dddf0
log4j-core@2.25.2
2.25.4

Open the chart page →

818
mod-template-enginefolio-org0.1.341 of 1See more

mod-template-engine folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-template-engine:latestd105c585da30
log4j-core@2.24.3
2.25.4

Open the chart page →

818
mod-users-blfolio-org0.1.351 of 1See more

mod-users-bl folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
folioci/mod-users-bl:latest4e2d96c9340d
log4j-core@2.25.2
2.25.4

Open the chart page →

1,321
galoy-depsgaloymoney0.10.201 of 9See more

galoy-deps galoymoney 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
log4j-core@2.17.2
2.25.4

Open the chart page →

11,961
galoy-depsgaloymoney20.10.201 of 9See more

galoy-deps galoymoney2 0.10.20

1 of the 9 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.39.002f6f143fc6d
log4j-core@2.17.2
2.25.4

Open the chart page →

11,961
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
log4j-core@2.17.0
2.25.4

Open the chart page →

2,887
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
log4j-core@2.17.1
2.25.4

Open the chart page →

8,923
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.83 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

3 of the 5 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
log4j-core@2.13.3
2.25.4
jingking/geonetwork-hnap:4.2.843e74ab234e1
log4j-core@2.17.2
2.25.4
library/elasticsearch:7.17.1588c2ec10c7f2
log4j-core@2.17.1
2.25.4

Open the chart page →

34,754
geysergeyserVerified publisher0.1.31 of 1See more

geyser geyser 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/joffreybvn/k8s-geyser:0.0.247f36880072e
log4j-core@2.20.0
2.25.4

Open the chart page →

350
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
log4j-core@2.21.0
2.25.4
ghcr.io/open-telemetry/demo:1.12.0-frauddetectionservice77cefdab4d5c
log4j-core@2.21.1
2.25.4
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
log4j-core@2.23.1
2.25.4

Open the chart page →

49,025
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
log4j-core@2.24.1
2.25.4

Open the chart page →

5,261
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
log4j-core@2.25.3
2.25.4

Open the chart page →

1,691
mautrix-signalhalkeye0.3.01 of 2See more

mautrix-signal halkeye 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
signald/signald:0.23.2edbff058278c
log4j-core@2.19.0
2.25.4

Open the chart page →

1,499
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
log4j-core@2.17.0
2.25.4

Open the chart page →

6,102
metabasehelm-charts-nr0.14.41 of 1See more

metabase helm-charts-nr 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
log4j-core@2.17.1
2.25.4

Open the chart page →

2,572
cruise-controlhelm-cruise-controlVerified publisher2.1.11 of 2See more

cruise-control helm-cruise-control 2.1.1

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
log4j-core@2.17.2
2.25.4

Open the chart page →

1,453

Container images carrying it

226 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
folioci/mod-ncip:latest8ed83674352b
log4j-core@2.20.0
2.25.4
1
folioci/mod-oai-pmh:latest5cd5ef063f2a
log4j-core@2.24.3
2.25.4
1
folioci/mod-patron:latest5f213acfe2f8
log4j-core@2.24.3
2.25.4
1
folioci/mod-patron-blocks:latestde7318069a67
log4j-core@2.24.3
2.25.4
1
folioci/mod-pubsub:latest0a4fa4ad5d72
log4j-core@2.24.0
2.25.4
1
folioci/mod-rtac:latestc959b2d6142f
log4j-core@2.24.3
2.25.4
1
folioci/mod-sender:latestd88a675dddf0
log4j-core@2.25.2
2.25.4
1
folioci/mod-template-engine:latestd105c585da30
log4j-core@2.24.3
2.25.4
1
folioci/mod-users-bl:latest4e2d96c9340d
log4j-core@2.25.2
2.25.4
1
fonoster/routr-edgeport:2.13.6d08a8a574a50
log4j-core@2.22.0
2.25.4
1
fonoster/routr-requester:2.13.6e0c823506eb2
log4j-core@2.22.0
2.25.4
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
log4j-core@2.13.3
2.25.4
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
log4j-core@2.25.3
2.25.4
1
graylog/graylog:6.1.1019de1aff48c2
log4j-core@2.24.1
2.25.4
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
log4j-core@2.25.3
2.25.4
1
gridgain/community:8.9.11d32d182a0e6a
log4j-core@2.20.0
2.25.4
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
log4j-core@2.17.2
2.25.4
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
log4j-core@2.17.2
2.25.4
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
log4j-core@2.17.2
2.25.4
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
log4j-core@2.17.2
2.25.4
1
hazelcast/hazelcast:5.3.18fe26efde8e1
log4j-core@2.20.0
2.25.4
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
log4j-core@2.17.0
2.25.4
1
hazelcast/management-center:5.3.2f9d34300d330
log4j-core@2.17.2
2.25.4
1
hmediade/printserver:latest481a552c8e1c
log4j-core@2.17.2
2.25.4
1
iamdorsah/bastillion:v0.1db83a0254d81
log4j-core@2.17.1
2.25.4
1
jacobalberty/unifi:v7.1.664a3616625dda
log4j-core@2.17.2
2.25.4
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
log4j-core@2.17.2
2.25.4
1
just1not2/streama:1.10.48a2305192dec
log4j-core@2.17.1
2.25.4
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
log4j-core@2.20.0
2.25.4
1
keyfactor/signserver-ce:7.3.2798fbbe00283
log4j-core@2.20.0
2.25.4
1
library/crate:4.7.0c7984a05e15b
log4j-core@2.17.1
2.25.4
1
library/elasticsearch:8.17.32cc40b15dff8
log4j-core@2.19.0
2.25.4
1
library/elasticsearch:8.15.0310b9fc03b06
log4j-core@2.12.4
2.25.4
1
library/elasticsearch:7.17.0332c6d416808
log4j-core@2.17.1
2.25.4
1
library/elasticsearch:7.17.1588c2ec10c7f2
log4j-core@2.17.1
2.25.4
1
library/elasticsearch:7.17.8fdc73b3249c1
log4j-core@2.17.1
2.25.4
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
log4j-core@2.12.1
2.25.4
1
library/flink:1.14.6-scala_2.122461f02672b3
log4j-core@2.17.1
2.25.4
1
library/logstash:7.17.817a4f64e9cf5
log4j-core@2.17.1
2.25.4
1
library/logstash:9.1.233eae14f0867
log4j-core@2.17.2
2.25.4
1
library/neo4j:4.2.4348e3f56faa2
log4j-core@2.14.0
2.25.4
1
library/neo4j:2026.02.25ab4ab0358cf
log4j-core@2.25.3
2.25.4
1
library/neo4j:5.18.18f01f7bb053e
log4j-core@2.20.0
2.25.4
1
library/solr:8.7.0d124efd81fbb
log4j-core@2.13.2
2.25.4
1
library/sonarqube:10.7.0-community0842dcd4c8f8
log4j-core@2.19.0
2.25.4
1
library/sonarqube:8.9-communityeb2f0be32efd
log4j-core@2.17.0
2.25.4
1
library/sonarqube:10.0.0-communityef9723cf4fe4
log4j-core@2.19.0
2.25.4
1
library/storm:2.4.0bd5d420506d6
log4j-core@2.17.1
2.25.4
1
linuxserver/unifi-controller:7.3.83ab105cc50322
log4j-core@2.17.2
2.25.4
1
liukunup/jmeter:5.59c079617a81b
log4j-core@2.17.2
2.25.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.