StackRadar

CVE-2026-34481

Medium

Advisory

Published 10 Apr 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
log4j-layout-template-jsonmaven2.16.0, 2.20.0, 2.21.0, 2.23.1+3 more2.25.414
OSV records
GHSA-w35j-pv5h-q9q9

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-layout-template-json@2.24.3
2.25.4

Open the chart page →

4,641
hazelcasthazelcastVerified publisher5.10.22 of 2See more

hazelcast hazelcast 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
log4j-layout-template-json@2.23.1
2.25.4
hazelcast/management-center:5.5.2991ddb27c251
log4j-layout-template-json@2.23.1
2.25.4

Open the chart page →

2,634
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
log4j-layout-template-json@2.25.3
2.25.4

Open the chart page →

8,158
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-layout-template-json@2.16.0
2.25.4

Open the chart page →

24,930
migrationadeptia-automate-migration5.2.91 of 1See more

migration adeptia-automate-migration 5.2.9

1 of the 1 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
log4j-layout-template-json@2.25.3
2.25.4

Open the chart page →

395
zunivers-ninjaalexpressoVerified publisher1.31.21 of 2See more

zunivers-ninja alexpresso 1.31.2

1 of the 2 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
library/neo4j:5.18.18f01f7bb053e
log4j-layout-template-json@2.20.0
2.25.4

Open the chart page →

1,165
amorphieamorphie0.1.21 of 18See more

amorphie amorphie 0.1.2

1 of the 18 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.3.18fe26efde8e1
log4j-layout-template-json@2.20.0
2.25.4

Open the chart page →

28,131
metabasecasemark2.16.111 of 1See more

metabase casemark 2.16.11

1 of the 1 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
log4j-layout-template-json@2.23.1
2.25.4

Open the chart page →

1,215
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-layout-template-json@2.24.3
2.25.4

Open the chart page →

3,463
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
log4j-layout-template-json@2.21.0
2.25.4

Open the chart page →

9,920
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
log4j-layout-template-json@2.20.0
2.25.4

Open the chart page →

63,461
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
log4j-layout-template-json@2.24.2
2.25.4

Open the chart page →

2,589
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
log4j-layout-template-json@2.20.0
2.25.4

Open the chart page →

30,363
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
log4j-layout-template-json@2.24.3
2.25.4

Open the chart page →

2,024
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-layout-template-json@2.16.0
2.25.4

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-layout-template-json@2.16.0
2.25.4

Open the chart page →

8,806
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
log4j-layout-template-json@2.24.3
2.25.4

Open the chart page →

1,827
hazelcastwenerme5.10.22 of 2See more

hazelcast wenerme 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-34481.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
log4j-layout-template-json@2.23.1
2.25.4
hazelcast/management-center:5.5.2991ddb27c251
log4j-layout-template-json@2.23.1
2.25.4

Open the chart page →

2,634

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/solr:8.11.18c5f7881cebb
log4j-layout-template-json@2.16.0
2.25.4
3
hazelcast/hazelcast:5.5.05dd5d31c7a06
log4j-layout-template-json@2.23.1
2.25.4
2
hazelcast/management-center:5.5.2991ddb27c251
log4j-layout-template-json@2.23.1
2.25.4
2
library/neo4j:5.20.052d3dec8d455
log4j-layout-template-json@2.20.0
2.25.4
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-layout-template-json@2.24.3
2.25.4
2
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
log4j-layout-template-json@2.25.3
2.25.4
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
log4j-layout-template-json@2.21.0
2.25.4
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
log4j-layout-template-json@2.23.1
2.25.4
1
hazelcast/hazelcast:5.3.18fe26efde8e1
log4j-layout-template-json@2.20.0
2.25.4
1
library/neo4j:2026.02.25ab4ab0358cf
log4j-layout-template-json@2.25.3
2.25.4
1
library/neo4j:5.18.18f01f7bb053e
log4j-layout-template-json@2.20.0
2.25.4
1
metabase/metabase:v0.53.4.17807bc5cad17
log4j-layout-template-json@2.24.2
2.25.4
1
opennms/sentinel:36.0.288869082a14f
log4j-layout-template-json@2.24.3
2.25.4
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
log4j-layout-template-json@2.24.3
2.25.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.