StackRadar

CVE-2026-34480

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.010
60th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
269
of 17,781 indexed, latest versions
Container images
255
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

Carried by container images the latest versions of 269 of 17,781 indexed charts deploy, on 255 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.6.2, 2.8.2, 2.9.0, 2.9.1+34 more2.25.4255
OSV records
GHSA-3pxv-7cmr-fjr4

Charts affected

269 by stars
ChartLatestAffected imagesRadar Score
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
log4j-core@2.17.1
2.25.4

Open the chart page →

8,554
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
log4j-core@2.23.1
2.25.4

Open the chart page →

4,674
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
log4j-core@2.17.1
2.25.4

Open the chart page →

18,756
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
log4j-core@2.12.1
2.25.4

Open the chart page →

4,538
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
log4j-core@2.25.3
2.25.4

Open the chart page →

1,825
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
log4j-core@2.23.1
2.25.4

Open the chart page →

2,144
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
log4j-core@2.25.1
2.25.4

Open the chart page →

1,527
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
log4j-core@2.25.1
2.25.4

Open the chart page →

1,689
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
log4j-core@2.23.1
2.25.4

Open the chart page →

45,239
vertica-kafka-schedulervertica-chartsVerified publisher0.1.81 of 1See more

vertica-kafka-scheduler vertica-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
opentext/kafka-scheduler:24.1.0cf89a88180fb
log4j-core@2.17.1
2.25.4

Open the chart page →

50
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
log4j-core@2.21.0
2.25.4

Open the chart page →

5,484
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
log4j-core@2.11.1
2.25.4

Open the chart page →

5,460
hazelcastwenerme5.10.22 of 2See more

hazelcast wenerme 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
log4j-core@2.23.1
2.25.4
hazelcast/management-center:5.5.2991ddb27c251
log4j-core@2.23.1
2.25.4

Open the chart page →

2,634
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
log4j-core@2.25.0
2.25.4

Open the chart page →

2,191
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.25.4

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
2.25.4

Open the chart page →

6,213
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
log4j-core@2.21.0
2.25.4

Open the chart page →

9,381
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
log4j-core@2.20.0
2.25.4

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34480.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
log4j-core@2.17.2
2.25.4

Open the chart page →

5,846

Container images carrying it

255 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
resurfaceio/resurface:3.7.84d5cda2f64109
log4j-core@2.24.3
2.25.4
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
log4j-core@2.19.0
2.25.4
1
salehmir/jesse:1.10.101afa95f979e9
log4j-core@2.17.1
2.25.4
1
signald/signald:0.18.20ffad7ccc2eb
log4j-core@2.17.1
2.25.4
1
signald/signald:0.23.2edbff058278c
log4j-core@2.19.0
2.25.4
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
log4j-core@2.6.2
2.25.4
1
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
log4j-core@2.24.3
2.25.4
1
sslhep/hive-metastore:3.1.39e80af083079
log4j-core@2.17.1
2.25.4
1
stain/jena-fuseki:latestb1d0c96f19ad
log4j-core@2.23.1
2.25.4
1
structurizr/onpremises:2025.11.094b5ffb5119c8
log4j-core@2.24.3
2.25.4
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
log4j-core@2.17.1
2.25.4
1
treskon/portrait:DEV-latest88e813f22347
log4j-core@2.23.1
2.25.4
1
voltha/voltha-onos:5.1.8e038acb950d3
log4j-core@2.17.0
2.25.4
1
wavefronthq/proxy:9.2d1064d28f6eb
log4j-core@2.12.1
2.25.4
1
wazuh/wazuh-indexer:4.14.49c344d2b1757
log4j-core@2.21.0
2.25.4
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
log4j-core@2.21.0
2.25.4
1
wazuh/wazuh-indexer:4.14.3b149b30da686
log4j-core@2.21.0
2.25.4
1
xeotek/kadeck:6.3.439a3b37a17c5
log4j-core@2.20.0
2.25.4
1
xeotek/kadeck:4.2.94c6b04d9ce55
log4j-core@2.17.1
2.25.4
1
xetusoss/archiva:v2.2.588f25242b9ee
log4j-core@2.8.2
2.25.4
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
log4j-core@2.20.0
2.25.4
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
log4j-core@2.17.2
2.25.4
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
log4j-core@2.11.1
2.25.4
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
log4j-core@2.24.3
2.25.4
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
log4j-core@2.23.1
2.25.4
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
log4j-core@2.20.0
2.25.4
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
log4j-core@2.17.1
2.25.4
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
log4j-core@2.24.3
2.25.4
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
log4j-core@2.17.2
2.25.4
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
log4j-core@2.17.2
2.25.4
1
ghcr.io/joffreybvn/k8s-geyser:0.0.247f36880072e
log4j-core@2.20.0
2.25.4
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
log4j-core@2.25.3
2.25.4
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
log4j-core@2.20.0
2.25.4
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
log4j-core@2.17.2
2.25.4
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
log4j-core@2.25.2
2.25.4
1
ghcr.io/open-telemetry/demo:1.12.0-frauddetectionservice77cefdab4d5c
log4j-core@2.21.1
2.25.4
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
log4j-core@2.23.1
2.25.4
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
log4j-core@2.17.1
2.25.4
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
log4j-core@2.23.1
2.25.4
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
log4j-core@2.21.0
2.25.4
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
log4j-core@2.23.1
2.25.4
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
log4j-core@2.21.0
2.25.4
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
log4j-core@2.20.0
2.25.4
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
log4j-core@2.21.1
2.25.4
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
log4j-core@2.24.2
2.25.4
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
log4j-core@2.24.2
2.25.4
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
log4j-core@2.24.3
2.25.4
1
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
log4j-core@2.24.3
2.25.4
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
log4j-core@2.24.3
2.25.4
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
log4j-core@2.24.3
2.25.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.