StackRadar

CVE-2026-34478

Medium

Advisory

Published 10 Apr 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.010
60th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
104
of 17,781 indexed, latest versions
Container images
99
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility

Carried by container images the latest versions of 104 of 17,781 indexed charts deploy, on 99 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.21.0, 2.21.1, 2.22.0, 2.22.1+11 more2.25.499
OSV records
GHSA-445c-vh5m-36rj

Charts affected

104 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.3b149b30da686
log4j-core@2.21.0
2.25.4

Open the chart page →

11,384
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
log4j-core@2.25.3
2.25.4

Open the chart page →

3,812
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
log4j-core@2.25.0
2.25.4

Open the chart page →

2,283
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.11.1a7a2076b167e
log4j-core@2.21.0
2.25.4

Open the chart page →

6,168
zipkinygqygq2Verified publisher2.1.41 of 4See more

zipkin ygqygq2 2.1.4

1 of the 4 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.24197a9692f6a9
log4j-core@2.22.0
2.25.4

Open the chart page →

2,764
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
log4j-core@2.25.3
2.25.4

Open the chart page →

13,953
hertzbeathertzbeatOfficialVerified publisher1.8.11 of 4See more

hertzbeat hertzbeat 1.8.1

1 of the 4 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
log4j-core@2.24.3
2.25.4

Open the chart page →

14,000
opensearchcaptnbpVerified publisher3.1.11 of 2See more

opensearch captnbp 3.1.1

1 of the 2 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.19.269588c664014
log4j-core@2.21.0
2.25.4

Open the chart page →

998
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-core@2.24.3
2.25.4

Open the chart page →

4,641
hazelcasthazelcastVerified publisher5.10.22 of 2See more

hazelcast hazelcast 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
log4j-core@2.23.1
2.25.4
hazelcast/management-center:5.5.2991ddb27c251
log4j-core@2.23.1
2.25.4

Open the chart page →

2,634
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
log4j-core@3.0.0-beta3
no fix listed

Open the chart page →

107,811
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
log4j-core@2.25.3
2.25.4

Open the chart page →

5,852
kafka-chartsoldevelo-kafka-chart32.4.41 of 1See more

kafka-chart soldevelo-kafka-chart 32.4.4

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
log4j-core@2.24.3
2.25.4

Open the chart page →

2,355
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
log4j-core@2.24.3
2.25.4

Open the chart page →

4,378
tikaapache-tika3.2.21 of 1See more

tika apache-tika 3.2.2

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
apache/tika:3.2.2.0-fullffab324253ed
log4j-core@2.25.1
2.25.4

Open the chart page →

437
cp-schema-registrycp-schema-registryVerified publisher1.0.01 of 1See more

cp-schema-registry cp-schema-registry 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
log4j-core@2.24.3
2.25.4

Open the chart page →

1,864
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
log4j-core@2.21.0
2.25.4

Open the chart page →

52,635
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
log4j-core@2.23.1
2.25.4

Open the chart page →

11,553
openccuopenccuVerified publisher3.89.81 of 1See more

openccu openccu 3.89.8

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
log4j-core@2.25.2
2.25.4

Open the chart page →

1,916
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
log4j-core@2.23.1
2.25.4

Open the chart page →

1,692
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
log4j-core@2.23.1
2.25.4

Open the chart page →

31,844
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
log4j-core@2.25.3
2.25.4

Open the chart page →

8,158
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
log4j-core@2.24.3
2.25.4

Open the chart page →

7,432
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
log4j-core@2.24.3
2.25.4

Open the chart page →

1,482
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
log4j-core@2.25.2
2.25.4

Open the chart page →

3,188
migrationadeptia-automate-migration5.2.91 of 1See more

migration adeptia-automate-migration 5.2.9

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
log4j-core@2.25.3
2.25.4

Open the chart page →

395
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
log4j-core@2.23.1
2.25.4

Open the chart page →

854
akto-hybrid-redactakto1.44.41 of 5See more

akto-hybrid-redact akto 1.44.4

1 of the 5 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
log4j-core@2.24.3
2.25.4

Open the chart page →

4,777
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
log4j-core@2.24.3
2.25.4

Open the chart page →

3,217
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
log4j-core@2.24.3
2.25.4

Open the chart page →

1,826
akto-regional-setupakto1.3.11 of 9See more

akto-regional-setup akto 1.3.1

1 of the 9 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
log4j-core@2.24.2
2.25.4

Open the chart page →

7,603
akto-threat-clientakto0.2.01 of 2See more

akto-threat-client akto 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
log4j-core@2.24.2
2.25.4

Open the chart page →

1,523
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
log4j-core@2.24.2
2.25.4

Open the chart page →

3,442
amorphieamorphie0.1.21 of 18See more

amorphie amorphie 0.1.2

1 of the 18 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
log4j-core@2.22.1
2.25.4

Open the chart page →

28,131
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
log4j-core@2.23.1
2.25.4

Open the chart page →

11,553
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
apache/kafka:4.1.0bff074a5d005
log4j-core@2.24.3
2.25.4

Open the chart page →

2,398
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
log4j-core@2.21.0
2.25.4

Open the chart page →

1,073
metabasecasemark2.16.111 of 1See more

metabase casemark 2.16.11

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
log4j-core@2.23.1
2.25.4

Open the chart page →

1,215
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
log4j-core@2.24.3
2.25.4

Open the chart page →

4,578
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
log4j-core@2.23.1
2.25.4

Open the chart page →

12,454
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-core@2.24.3
2.25.4

Open the chart page →

3,463
edge-oai-pmhfolio-org0.1.311 of 1See more

edge-oai-pmh folio-org 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
folioci/edge-oai-pmh:latesteedfcbc29792
log4j-core@2.23.1
2.25.4

Open the chart page →

874
edge-patronfolio-org0.1.281 of 1See more

edge-patron folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
folioci/edge-patron:latest682b852e056d
log4j-core@2.23.0
2.25.4

Open the chart page →

905
edge-rtacfolio-org0.1.281 of 1See more

edge-rtac folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
folioci/edge-rtac:latest15ef73b1abd0
log4j-core@2.25.3
2.25.4

Open the chart page →

1,259
mod-authtokenfolio-org0.1.351 of 1See more

mod-authtoken folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
folioci/mod-authtoken:latest995a25a33133
log4j-core@2.24.3
2.25.4

Open the chart page →

1,558
mod-circulationfolio-org0.1.351 of 1See more

mod-circulation folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
folioci/mod-circulation:latest3eecd2ac2d8a
log4j-core@2.24.3
2.25.4

Open the chart page →

497
mod-coursesfolio-org0.1.341 of 1See more

mod-courses folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
folioci/mod-courses:latest68ca414f5596
log4j-core@2.24.3
2.25.4

Open the chart page →

1,533
mod-data-exportfolio-org0.1.401 of 1See more

mod-data-export folio-org 0.1.40

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
folioci/mod-data-export:latest0cc86bf09755
log4j-core@2.25.3
2.25.4

Open the chart page →

1,393
mod-data-export-springfolio-org0.1.41 of 1See more

mod-data-export-spring folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
folioci/mod-data-export-spring:latestf1d7caf4544b
log4j-core@2.25.3
2.25.4

Open the chart page →

1,253
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-34478.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
log4j-core@2.25.3
2.25.4

Open the chart page →

1,214

Container images carrying it

99 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/druid:37.0.00116fb802786
log4j-core@2.25.3
2.25.4
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
log4j-core@2.23.1
2.25.4
2
hazelcast/hazelcast:5.5.05dd5d31c7a06
log4j-core@2.23.1
2.25.4
2
hazelcast/management-center:5.5.2991ddb27c251
log4j-core@2.23.1
2.25.4
2
inaccel/coral:2.18c53744ed70b
log4j-core@2.23.1
2.25.4
2
library/elasticsearch:8.19.1289729a95066a
log4j-core@2.25.0
2.25.4
2
mbentley/omada-controller:4.3f4e682274bed
log4j-core@2.23.1
2.25.4
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
log4j-core@2.21.0
2.25.4
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-core@2.24.3
2.25.4
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
log4j-core@2.24.3
2.25.4
2
2martens/configserver:latestbf1cdb80239d
log4j-core@2.23.1
2.25.4
1
2martens/timetable:latestbd1ba6ab84c9
log4j-core@2.25.1
2.25.4
1
2martens/wahlrecht:latestba2c3040dab0
log4j-core@2.25.1
2.25.4
1
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
log4j-core@2.25.3
2.25.4
1
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
log4j-core@2.23.1
2.25.4
1
aktosecurity/data-ingestion-service213aded7adc5
log4j-core@2.24.2
2.25.4
1
alfio/alf.io:2.0-M5-26060c836a081446
log4j-core@2.24.3
2.25.4
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
log4j-core@2.24.1
2.25.4
1
apache/activemq-artemis:2.44.00305c26f19ed
log4j-core@2.25.2
2.25.4
1
apache/activemq-artemis:2.37.0bae523439ee3
log4j-core@2.23.1
2.25.4
1
apache/hertzbeat:1.8.075d48a62748f
log4j-core@2.24.3
2.25.4
1
apache/kafka:4.1.0bff074a5d005
log4j-core@2.24.3
2.25.4
1
apache/tika:3.2.2.0-fullffab324253ed
log4j-core@2.25.1
2.25.4
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
log4j-core@2.25.3
2.25.4
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
log4j-core@2.21.0
2.25.4
1
camunda/zeebe:8.4.5ab5abc09e407
log4j-core@2.22.1
2.25.4
1
castlemock/castlemock:latestb7f3f1527ba9
log4j-core@2.24.3
2.25.4
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
log4j-core@2.21.0
2.25.4
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
log4j-core@2.23.1
2.25.4
1
conductoross/conductor:3.31.09fba127693e6
log4j-core@2.23.1
2.25.4
1
consensys/teku:25.4.1bf6ecd2ea716
log4j-core@2.24.3
2.25.4
1
folioci/edge-oai-pmh:latesteedfcbc29792
log4j-core@2.23.1
2.25.4
1
folioci/edge-patron:latest682b852e056d
log4j-core@2.23.0
2.25.4
1
folioci/edge-rtac:latest15ef73b1abd0
log4j-core@2.25.3
2.25.4
1
folioci/mod-authtoken:latest995a25a33133
log4j-core@2.24.3
2.25.4
1
folioci/mod-circulation:latest3eecd2ac2d8a
log4j-core@2.24.3
2.25.4
1
folioci/mod-courses:latest68ca414f5596
log4j-core@2.24.3
2.25.4
1
folioci/mod-data-export:latest0cc86bf09755
log4j-core@2.25.3
2.25.4
1
folioci/mod-data-export-spring:latestf1d7caf4544b
log4j-core@2.25.3
2.25.4
1
folioci/mod-data-export-worker:latest1ad1811c9b37
log4j-core@2.25.3
2.25.4
1
folioci/mod-ebsconet:latest3ae8cb99daa3
log4j-core@2.25.2
2.25.4
1
folioci/mod-email:latest79ea8e2e7ebf
log4j-core@2.25.3
2.25.4
1
folioci/mod-eusage-reports:latest15de67587091
log4j-core@2.25.3
2.25.4
1
folioci/mod-feesfines:latestfe3a7049f2fb
log4j-core@2.24.3
2.25.4
1
folioci/mod-inventory-update:latestba84812b4d58
log4j-core@2.24.3
2.25.4
1
folioci/mod-login:latest88de493f86db
log4j-core@2.24.3
2.25.4
1
folioci/mod-oai-pmh:latest5cd5ef063f2a
log4j-core@2.24.3
2.25.4
1
folioci/mod-patron:latest5f213acfe2f8
log4j-core@2.24.3
2.25.4
1
folioci/mod-patron-blocks:latestde7318069a67
log4j-core@2.24.3
2.25.4
1
folioci/mod-pubsub:latest0a4fa4ad5d72
log4j-core@2.24.0
2.25.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.