StackRadar

CVE-2026-34479

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
86
of 17,781 indexed, latest versions
Container images
83
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters

Carried by container images the latest versions of 86 of 17,781 indexed charts deploy, on 83 images.

Affected packageAffected versionsFixed inImages
log4j-1.2-apimaven2.8.2, 2.9.1, 2.11.0, 2.11.1+17 more2.25.483
OSV records
GHSA-h383-gmxw-35v2

Charts affected

86 by stars
ChartLatestAffected imagesRadar Score
edge-patronfolio-org0.1.281 of 1See more

edge-patron folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
folioci/edge-patron:latest682b852e056d
log4j-1.2-api@2.23.0
2.25.4

Open the chart page →

905
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.83 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

3 of the 5 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
log4j-1.2-api@2.13.3
2.25.4
jingking/geonetwork-hnap:4.2.843e74ab234e1
log4j-1.2-api@2.17.2
2.25.4
library/elasticsearch:7.17.1588c2ec10c7f2
log4j-1.2-api@2.17.1
2.25.4

Open the chart page →

34,754
metabasehelm-charts-nr0.14.41 of 1See more

metabase helm-charts-nr 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
log4j-1.2-api@2.18.0
2.25.4

Open the chart page →

2,572
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
log4j-1.2-api@2.21.0
2.25.4

Open the chart page →

9,920
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
log4j-1.2-api@2.25.3
2.25.4

Open the chart page →

8,541
printserverhmediadeVerified publisher1.0.21 of 4See more

printserver hmediade 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
hmediade/printserver:latest481a552c8e1c
log4j-1.2-api@2.17.2
2.25.4

Open the chart page →

10,839
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
log4j-1.2-api@2.11.1
2.25.4
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
log4j-1.2-api@2.11.1
2.25.4

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
log4j-1.2-api@2.8.2
2.25.4

Open the chart page →

57,669
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
log4j-1.2-api@2.19.0
2.25.4

Open the chart page →

1,754
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
log4j-1.2-api@2.17.1
2.25.4

Open the chart page →

10,777
daveit-at-mOfficialVerified publisher0.2.151 of 11See more

dave it-at-m 0.2.15

1 of the 11 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
log4j-1.2-api@2.19.0
2.25.4

Open the chart page →

15,089
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
log4j-1.2-api@2.24.2
2.25.4

Open the chart page →

2,589
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
log4j-1.2-api@2.19.0
2.25.4

Open the chart page →

4,257
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
log4j-1.2-api@2.14.0
2.25.4

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
log4j-1.2-api@2.17.1
2.25.4

Open the chart page →

15,675
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
log4j-1.2-api@2.19.0
2.25.4

Open the chart page →

5,663
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
log4j-1.2-api@2.17.1
2.25.4

Open the chart page →

9,300
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
log4j-1.2-api@2.17.2
2.25.4

Open the chart page →

8,540
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
log4j-1.2-api@2.17.2
2.25.4

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
log4j-1.2-api@2.17.2
2.25.4

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
log4j-1.2-api@2.17.2
2.25.4

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
log4j-1.2-api@2.17.2
2.25.4

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
log4j-1.2-api@2.17.2
2.25.4

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
log4j-1.2-api@2.17.2
2.25.4

Open the chart page →

13,100
flink-kubernetes-operatorpresto-loadbalancer1.10.01 of 1See more

flink-kubernetes-operator presto-loadbalancer 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
log4j-1.2-api@2.23.1
2.25.4

Open the chart page →

3,277
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
log4j-1.2-api@2.8.2
2.25.4

Open the chart page →

9,606
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
log4j-1.2-api@2.20.0
2.25.4

Open the chart page →

21,211
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
log4j-1.2-api@2.19.0
2.25.4

Open the chart page →

4,203
routr-connectroutr0.4.32 of 10See more

routr-connect routr 0.4.3

2 of the 10 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
fonoster/routr-edgeport:2.13.6d08a8a574a50
log4j-1.2-api@2.17.1
2.25.4
fonoster/routr-requester:2.13.6e0c823506eb2
log4j-1.2-api@2.17.1
2.25.4

Open the chart page →

11,021
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
log4j-1.2-api@2.17.2
2.25.4

Open the chart page →

8,804
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
log4j-1.2-api@2.8.2
2.25.4

Open the chart page →

6,907
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
log4j-1.2-api@2.9.1
2.25.4

Open the chart page →

11,841
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-1.2-api@2.16.0
2.25.4

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-1.2-api@2.16.0
2.25.4

Open the chart page →

8,806
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
log4j-1.2-api@2.11.1
2.25.4

Open the chart page →

5,460
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-34479.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
log4j-1.2-api@2.19.0
2.25.4

Open the chart page →

2,191

Container images carrying it

83 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/elasticsearch:8.15.0310b9fc03b06
log4j-1.2-api@2.19.0
2.25.4
1
library/elasticsearch:7.17.0332c6d416808
log4j-1.2-api@2.17.1
2.25.4
1
library/elasticsearch:7.17.1588c2ec10c7f2
log4j-1.2-api@2.17.1
2.25.4
1
library/elasticsearch:7.17.8fdc73b3249c1
log4j-1.2-api@2.17.1
2.25.4
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
log4j-1.2-api@2.12.1
2.25.4
1
library/flink:1.14.6-scala_2.122461f02672b3
log4j-1.2-api@2.17.1
2.25.4
1
library/logstash:7.17.817a4f64e9cf5
log4j-1.2-api@2.17.1
2.25.4
1
library/logstash:9.1.233eae14f0867
log4j-1.2-api@2.19.0
2.25.4
1
library/solr:8.7.0d124efd81fbb
log4j-1.2-api@2.13.2
2.25.4
1
library/sonarqube:10.7.0-community0842dcd4c8f8
log4j-1.2-api@2.19.0
2.25.4
1
library/sonarqube:6.7.6-community0ae5169e3d0f
log4j-1.2-api@2.9.1
2.25.4
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
log4j-1.2-api@2.11.1
2.25.4
1
library/sonarqube:8.2-communitya246bc64207e
log4j-1.2-api@2.11.1
2.25.4
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
log4j-1.2-api@2.11.1
2.25.4
1
library/sonarqube:10.0.0-communityef9723cf4fe4
log4j-1.2-api@2.19.0
2.25.4
1
library/storm:2.4.0bd5d420506d6
log4j-1.2-api@2.17.1
2.25.4
1
liukunup/jmeter:5.59c079617a81b
log4j-1.2-api@2.17.2
2.25.4
1
metabase/metabase:v0.53.4.17807bc5cad17
log4j-1.2-api@2.24.2
2.25.4
1
metabase/metabase:v0.46.09ebdc664a6b2
log4j-1.2-api@2.19.0
2.25.4
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
log4j-1.2-api@2.17.1
2.25.4
1
pedrocesarti/jmeter-docker:3.314851f144f57
log4j-1.2-api@2.8.2
2.25.4
1
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
log4j-1.2-api@2.24.3
2.25.4
1
sslhep/hive-metastore:3.1.39e80af083079
log4j-1.2-api@2.17.1
2.25.4
1
trinodb/trino:45038c6f24ab1a4
log4j-1.2-api@2.20.0
2.25.4
1
wavefronthq/proxy:9.2d1064d28f6eb
log4j-1.2-api@2.12.1
2.25.4
1
xetusoss/archiva:v2.2.588f25242b9ee
log4j-1.2-api@2.8.2
2.25.4
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
log4j-1.2-api@2.23.1
2.25.4
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
log4j-1.2-api@2.17.1
2.25.4
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
log4j-1.2-api@2.24.3
2.25.4
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
log4j-1.2-api@2.20.0
2.25.4
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
log4j-1.2-api@2.17.2
2.25.4
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
log4j-1.2-api@2.24.3
2.25.4
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
log4j-1.2-api@2.17.1
2.25.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.