CVE-2026-34478
MediumAdvisory
Published 10 Apr 2026In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.9
- base score, highest
- EPSS
- 0.010
- 60th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 104
- of 17,781 indexed, latest versions
- Container images
- 99
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
Carried by container images the latest versions of 104 of 17,781 indexed charts deploy, on 99 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| log4j-coremaven | 2.21.0, 2.21.1, 2.22.0, 2.22.1+11 more | 2.25.4 | 99 |
- OSV records
- GHSA-445c-vh5m-36rj
Charts affected
104 by stars
Container images carrying it
99 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.