StackRadar

CVE-2026-34477

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
238
of 17,781 indexed, latest versions
Container images
226
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

Carried by container images the latest versions of 238 of 17,781 indexed charts deploy, on 226 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.12.1, 2.12.4, 2.13.0, 2.13.2+26 more2.25.4226
OSV records
GHSA-6hg6-v5c8-fphq

Charts affected

238 by stars
ChartLatestAffected imagesRadar Score
alfiohelmforgeVerified publisher1.2.121 of 3See more

alfio helmforge 1.2.12

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
alfio/alf.io:2.0-M5-26060c836a081446
log4j-core@2.24.3
2.25.4

Open the chart page →

2,091
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
log4j-core@2.21.0
2.25.4

Open the chart page →

9,920
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
log4j-core@2.25.3
2.25.4

Open the chart page →

8,541
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.3.2798cf28e226a
log4j-core@2.21.0
2.25.4

Open the chart page →

25,017
printserverhmediadeVerified publisher1.0.21 of 4See more

printserver hmediade 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
hmediade/printserver:latest481a552c8e1c
log4j-core@2.17.2
2.25.4

Open the chart page →

10,839
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
log4j-core@2.17.1
2.25.4

Open the chart page →

16,401
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
log4j-core@2.15.0
2.25.4

Open the chart page →

20,650
fpga-operatorinaccelVerified publisher2.8.21 of 7See more

fpga-operator inaccel 2.8.2

1 of the 7 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
log4j-core@2.23.1
2.25.4

Open the chart page →

5,759
jenainseefrlab3.1.01 of 1See more

jena inseefrlab 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
stain/jena-fuseki:latestb1d0c96f19ad
log4j-core@2.23.1
2.25.4

Open the chart page →

1,262
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
log4j-core@2.19.0
2.25.4

Open the chart page →

1,754
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
log4j-core@2.17.1
2.25.4

Open the chart page →

10,777
daveit-at-mOfficialVerified publisher0.2.151 of 11See more

dave it-at-m 0.2.15

1 of the 11 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
log4j-core@2.19.0
2.25.4

Open the chart page →

15,089
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
log4j-core@2.23.1
2.25.4

Open the chart page →

45,239
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
log4j-core@2.20.0
2.25.4

Open the chart page →

63,461
kadeck-teamskadeck1.1.211 of 1See more

kadeck-teams kadeck 1.1.21

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
xeotek/kadeck:6.3.439a3b37a17c5
log4j-core@2.20.0
2.25.4

Open the chart page →

3,576
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
log4j-core@2.17.1
2.25.4

Open the chart page →

7,254
sonarqubekubesphereVerified publisher6.7.01 of 3See more

sonarqube kubesphere 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/sonarqube:8.9-communityeb2f0be32efd
log4j-core@2.17.0
2.25.4

Open the chart page →

2,273
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
log4j-core@2.23.1
2.25.4

Open the chart page →

5,759
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
log4j-core@2.23.1
2.25.4

Open the chart page →

16,877
strimzi-kafka-operatorkvalitetsitVerified publisher0.36.11 of 1See more

strimzi-kafka-operator kvalitetsit 0.36.1

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.36.1e9e03b31007c
log4j-core@2.17.2
2.25.4

Open the chart page →

4,098
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
log4j-core@2.24.2
2.25.4

Open the chart page →

2,589
activemqmicroboxlabs3.8.01 of 1See more

activemq microboxlabs 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
log4j-core@2.24.1
2.25.4

Open the chart page →

1,494
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
log4j-core@2.19.0
2.25.4

Open the chart page →

4,257
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
log4j-core@2.17.2
2.25.4

Open the chart page →

11,188
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
log4j-core@2.13.0
2.25.4

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
log4j-core@2.13.0
2.25.4

Open the chart page →

10,603
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
log4j-core@2.20.0
2.25.4

Open the chart page →

30,363
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
log4j-core@2.14.0
2.25.4

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
log4j-core@2.17.1
2.25.4

Open the chart page →

15,675
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
log4j-core@2.17.2
2.25.4

Open the chart page →

5,663
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
log4j-core@2.17.1
2.25.4

Open the chart page →

9,300
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
log4j-core@2.14.0
2.25.4

Open the chart page →

2,640
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
log4j-core@2.20.0
2.25.4

Open the chart page →

2,049
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
log4j-core@2.17.1
2.25.4

Open the chart page →

5,826
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
log4j-core@2.17.2
2.25.4

Open the chart page →

8,540
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
log4j-core@2.18.0
2.25.4

Open the chart page →

9,005
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
log4j-core@2.17.2
2.25.4

Open the chart page →

2,421
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
log4j-core@2.13.0
2.25.4

Open the chart page →

12,927
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
voltha/voltha-onos:5.1.8e038acb950d3
log4j-core@2.17.0
2.25.4

Open the chart page →

41,044
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
log4j-core@2.24.3
2.25.4

Open the chart page →

2,024
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
log4j-core@2.17.2
2.25.4

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
log4j-core@2.17.2
2.25.4

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
log4j-core@2.17.2
2.25.4

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
log4j-core@2.17.2
2.25.4

Open the chart page →

13,551
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
log4j-core@2.21.0
2.25.4

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
log4j-core@2.21.0
2.25.4

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
log4j-core@2.21.0
2.25.4

Open the chart page →

1,753
flink-kubernetes-operatorpresto-loadbalancer1.10.01 of 1See more

flink-kubernetes-operator presto-loadbalancer 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
log4j-core@2.23.1
2.25.4

Open the chart page →

3,277
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
log4j-core@2.17.1
2.25.4

Open the chart page →

1,995
app-configradar-baseVerified publisher1.7.21 of 1See more

app-config radar-base 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-34477.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
log4j-core@2.23.1
2.25.4

Open the chart page →

2,036

Container images carrying it

226 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
log4j-core@2.17.1
2.25.4
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
2.25.4
1
metabase/metabase:v0.53.4.17807bc5cad17
log4j-core@2.24.2
2.25.4
1
metabase/metabase:v0.46.09ebdc664a6b2
log4j-core@2.17.1
2.25.4
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
log4j-core@2.17.1
2.25.4
1
olvid/bot-daemon:2.0.1e0e6b165d879
log4j-core@2.20.0
2.25.4
1
onosproject/onos:2.2.144914a8d4b3f
log4j-core@2.13.0
2.25.4
1
openhab/openhab:3.2.0d0aa4af452c1
log4j-core@2.17.0
2.25.4
1
opennms/sentinel:36.0.288869082a14f
log4j-core@2.24.3
2.25.4
1
opensearchproject/data-prepper:2.8.057c25fa01d3c
log4j-core@2.23.1
2.25.4
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
log4j-core@2.17.1
2.25.4
1
opensearchproject/opensearch:2.15.01963b3ece46d
log4j-core@2.21.0
2.25.4
1
opensearchproject/opensearch:2.14.0466a49f379bb
log4j-core@2.21.0
2.25.4
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
log4j-core@2.21.0
2.25.4
1
opensearchproject/opensearch:2.12.0645d3d9390ad
log4j-core@2.21.0
2.25.4
1
opensearchproject/opensearch:2.19.269588c664014
log4j-core@2.21.0
2.25.4
1
opensearchproject/opensearch:3.3.2798cf28e226a
log4j-core@2.21.0
2.25.4
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
log4j-core@2.20.0
2.25.4
1
opentext/kafka-scheduler:24.1.0cf89a88180fb
log4j-core@2.17.1
2.25.4
1
openzipkin/zipkin:2.24197a9692f6a9
log4j-core@2.22.0
2.25.4
1
openzipkin/zipkin:2.21.060c3970df479
log4j-core@2.12.1
2.25.4
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
log4j-core@2.12.1
2.25.4
1
penpotapp/backend:2.2.147853d9bb9dd
log4j-core@2.23.1
2.25.4
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
log4j-core@2.23.0
2.25.4
1
resurfaceio/resurface:3.7.84d5cda2f64109
log4j-core@2.24.3
2.25.4
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
log4j-core@2.19.0
2.25.4
1
salehmir/jesse:1.10.101afa95f979e9
log4j-core@2.17.1
2.25.4
1
signald/signald:0.18.20ffad7ccc2eb
log4j-core@2.17.1
2.25.4
1
signald/signald:0.23.2edbff058278c
log4j-core@2.19.0
2.25.4
1
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
log4j-core@2.24.3
2.25.4
1
sslhep/hive-metastore:3.1.39e80af083079
log4j-core@2.17.1
2.25.4
1
stain/jena-fuseki:latestb1d0c96f19ad
log4j-core@2.23.1
2.25.4
1
structurizr/onpremises:2025.11.094b5ffb5119c8
log4j-core@2.24.3
2.25.4
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
log4j-core@2.17.1
2.25.4
1
treskon/portrait:DEV-latest88e813f22347
log4j-core@2.23.1
2.25.4
1
voltha/voltha-onos:5.1.8e038acb950d3
log4j-core@2.17.0
2.25.4
1
wavefronthq/proxy:9.2d1064d28f6eb
log4j-core@2.12.1
2.25.4
1
wazuh/wazuh-indexer:4.14.49c344d2b1757
log4j-core@2.21.0
2.25.4
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
log4j-core@2.21.0
2.25.4
1
wazuh/wazuh-indexer:4.14.3b149b30da686
log4j-core@2.21.0
2.25.4
1
xeotek/kadeck:6.3.439a3b37a17c5
log4j-core@2.20.0
2.25.4
1
xeotek/kadeck:4.2.94c6b04d9ce55
log4j-core@2.17.1
2.25.4
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
log4j-core@2.20.0
2.25.4
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
log4j-core@2.17.2
2.25.4
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
log4j-core@2.24.3
2.25.4
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
log4j-core@2.23.1
2.25.4
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
log4j-core@2.20.0
2.25.4
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
log4j-core@2.17.1
2.25.4
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
log4j-core@2.24.3
2.25.4
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
log4j-core@2.17.2
2.25.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.