StackRadar

CVE-2026-49844

Medium

Advisory

Published 11 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
604
of 17,787 indexed, latest versions
Container images
571
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Carried by container images the latest versions of 604 of 17,787 indexed charts deploy, on 571 images.

Affected packageAffected versionsFixed inImages
log4j-apimaven2.13.2, 2.13.3, 2.14.0, 2.14.1+24 more2.25.5, 2.26.1571
OSV records
GHSA-qv9r-c865-cp47

Charts affected

604 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
log4j-api@2.21.1
2.25.5

Open the chart page →

11,592
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
log4j-api@2.21.0
2.25.5

Open the chart page →

9,381
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
log4j-api@2.20.0
2.25.5

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
log4j-api@2.17.2
2.25.5

Open the chart page →

5,847

Container images carrying it

571 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
log4j-api@2.25.3
2.25.5
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
log4j-api@2.25.3
2.25.5
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
log4j-api@2.25.3
2.25.5
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
log4j-api@2.25.3
2.25.5
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
log4j-api@2.24.3
2.25.5
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
log4j-api@2.24.3
2.25.5
1
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
log4j-api@2.24.3
2.25.5
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
log4j-api@2.24.3
2.25.5
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
log4j-api@2.24.3
2.25.5
1
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
log4j-api@2.25.4
2.25.5
1
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
log4j-api@2.24.3
2.25.5
1
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
log4j-api@2.24.3
2.25.5
1
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
log4j-api@2.24.3
2.25.5
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
log4j-api@2.24.3
2.25.5
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
log4j-api@2.24.3
2.25.5
1
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
log4j-api@2.25.4
2.25.5
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
log4j-api@2.17.2
2.25.5
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
log4j-api@2.17.2
2.25.5
1
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
log4j-api@2.24.3
2.25.5
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
log4j-api@2.24.1
2.25.5
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
log4j-api@2.24.1
2.25.5
1
ghcr.io/joffreybvn/k8s-geyser:0.0.247f36880072e
log4j-api@2.20.0
2.25.5
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
log4j-api@2.13.3
2.25.5
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
log4j-api@2.24.3
2.25.5
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
log4j-api@2.25.3
2.25.5
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
log4j-api@2.20.0
2.25.5
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
log4j-api@2.13.2
2.25.5
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
log4j-api@2.17.2
2.25.5
1
ghcr.io/openccu/openccu:3.89.9.20260914eaeefd355dca
log4j-api@2.17.2
2.25.5
1
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
log4j-api@2.25.4
2.25.5
1
ghcr.io/open-telemetry/demo:1.12.0-frauddetectionservice77cefdab4d5c
log4j-api@2.21.1
2.25.5
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
log4j-api@2.23.1
2.25.5
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
log4j-api@2.17.2
2.25.5
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
log4j-api@2.21.1
2.25.5
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
log4j-api@2.17.1
2.25.5
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
log4j-api@2.17.2
2.25.5
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
log4j-api@2.23.1
2.25.5
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
log4j-api@2.21.0
2.25.5
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
log4j-api@2.23.1
2.25.5
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
log4j-api@2.21.0
2.25.5
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
log4j-api@2.20.0
2.25.5
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
log4j-api@2.21.1
2.25.5
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
log4j-api@2.17.2
2.25.5
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
log4j-api@2.25.4
2.25.5
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
log4j-api@2.24.3
2.25.5
1
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
log4j-api@2.25.4
2.25.5
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
log4j-api@2.26.0
2.26.1
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
log4j-api@2.26.0
2.26.1
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
log4j-api@2.26.0
2.26.1
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
log4j-api@2.24.2
2.25.5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.