StackRadar

CVE-2026-49844

Medium

Advisory

Published 11 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
597
of 17,787 indexed, latest versions
Container images
564
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Carried by container images the latest versions of 597 of 17,787 indexed charts deploy, on 564 images.

Affected packageAffected versionsFixed inImages
log4j-apimaven2.13.2, 2.13.3, 2.14.0, 2.14.1+24 more2.25.5, 2.26.1564
OSV records
GHSA-qv9r-c865-cp47

Charts affected

597 by stars
ChartLatestAffected imagesRadar Score
Chart-Oracle-Host-Appchart-oracle-host-appVerified publisher0.1.21 of 1See more

Chart-Oracle-Host-App chart-oracle-host-app 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
stanislovesid/oracle-host-app:14fe1ed26e194
log4j-api@2.14.1
2.25.5

Open the chart page →

2,434
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
log4j-api@2.17.2
2.25.5

Open the chart page →

6,447
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
robotshop/rs-shipping:latest89753ab48919
log4j-api@2.13.3
2.25.5

Open the chart page →

29,555
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
log4j-api@2.24.3
2.25.5

Open the chart page →

4,578
clamapicnieg2.0.51 of 2See more

clamapi cnieg 2.0.5

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
audig/clamapi:2.1.62c3fe34ee430
log4j-api@2.13.3
2.25.5

Open the chart page →

4,671
ganttcnieg2.1.01 of 1See more

gantt cnieg 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
cnieg/gantt:1.1.2d4b478d76f2a
log4j-api@2.17.2
2.25.5

Open the chart page →

2,390
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
log4j-api@2.17.2
2.25.5

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
log4j-api@2.17.2
2.25.5

Open the chart page →

7,963
consumer-helmconsumer-app-helm-chart0.1.01 of 1See more

consumer-helm consumer-app-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
j4ckhunter/consumer:1.00bb7a429e3e75
log4j-api@2.17.2
2.25.5

Open the chart page →

2,564
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
dadosfake-helmdadosfake-app0.1.01 of 1See more

dadosfake-helm dadosfake-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
log4j-api@2.21.1
2.25.5

Open the chart page →

2,064
pagesdalston-pages1.0.01 of 3See more

pages dalston-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
pagesdaman-dell-kuber1.0.01 of 3See more

pages daman-dell-kuber 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
damap-chartdamapVerified publisher0.3.01 of 5See more

damap-chart damap 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
log4j-api@2.23.1
2.25.5

Open the chart page →

13,936
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
log4j-api@2.24.3
2.25.5

Open the chart page →

3,547
kafka-connectdasmeta1.0.21 of 3See more

kafka-connect dasmeta 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
confluentinc/cp-schema-registry:latestf0cfd047a839
log4j-api@2.25.4
2.25.5

Open the chart page →

532
pagesdavid-pages1.0.01 of 3See more

pages david-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
pagesdebasish-pages1.0.01 of 3See more

pages debasish-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
amartinm82/planner:v2.01184353ff57b
log4j-api@2.13.3
2.25.5
oscarsotosanchez/toposervice:v1.0d4d020e9f272
log4j-api@2.13.3
2.25.5

Open the chart page →

27,550
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
epam/ai-dial-admin-backend:0.20.00ac5be78d7c2
log4j-api@2.25.4
2.25.5

Open the chart page →

4,046
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
log4j-api@2.24.3
2.25.5

Open the chart page →

1,269
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
oscarsotosanchez/toposervice:v1.0d4d020e9f272
log4j-api@2.13.3
2.25.5

Open the chart page →

24,656
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
log4j-api@2.17.0
2.25.5

Open the chart page →

2,237
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
log4j-api@2.21.1
2.25.5

Open the chart page →

2,512
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
log4j-api@2.21.1
2.25.5

Open the chart page →

3,888
pagesedgwarepages1.0.01 of 3See more

pages edgwarepages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
log4j-api@2.23.1
2.25.5

Open the chart page →

7,268
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-api@2.17.2
2.25.5

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-api@2.17.2
2.25.5

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-api@2.17.2
2.25.5

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
log4j-api@2.17.2
2.25.5

Open the chart page →

4,033
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
log4j-api@2.17.2
2.25.5

Open the chart page →

2,942
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
log4j-api@2.17.1
2.25.5

Open the chart page →

10,564
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
oscarsotosanchez/planner:v1.0730c00a099b8
log4j-api@2.13.3
2.25.5
oscarsotosanchez/toposervice:v1.0d4d020e9f272
log4j-api@2.13.3
2.25.5

Open the chart page →

27,291
eoloPlanteolo-plannerVerified publisher0.1.02 of 7See more

eoloPlant eolo-planner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
log4j-api@2.19.0
2.25.5
mastercloudapps/planner:v1.2340a950b311b2
log4j-api@2.14.1
2.25.5

Open the chart page →

27,537
eoloplannereoloplannerVerified publisher0.1.02 of 7See more

eoloplanner eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
log4j-api@2.14.1
2.25.5
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5

Open the chart page →

32,205
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.02 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
log4j-api@2.19.0
2.25.5
mastercloudapps/planner:v1.2340a950b311b2
log4j-api@2.14.1
2.25.5

Open the chart page →

27,537
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
franrobles8/planner:v3.099985392d63c
log4j-api@2.13.3
2.25.5
oscarsotosanchez/toposervice:v1.0d4d020e9f272
log4j-api@2.13.3
2.25.5

Open the chart page →

27,256
eoloplannereoloplanner-molynx-gat0.1.02 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5
molynx/planner:v1441c9f52f092
log4j-api@2.14.1
2.25.5

Open the chart page →

28,482
eolo-plannereolo-planner-repo0.1.02 of 7See more

eolo-planner eolo-planner-repo 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
arturisimo/planner:v1.0fff9de644941
log4j-api@2.14.1
2.25.5
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5

Open the chart page →

27,096
eoloplanteoloplant1.0.02 of 7See more

eoloplant eoloplant 1.0.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
log4j-api@2.19.0
2.25.5
mastercloudapps/planner:v1.2340a950b311b2
log4j-api@2.14.1
2.25.5

Open the chart page →

27,537
eoloplantseoloplants-urjcVerified publisher0.1.02 of 7See more

eoloplants eoloplants-urjc 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5
lourdesmorente/new-planner:1.0.0608745878cdb
log4j-api@2.14.1
2.25.5

Open the chart page →

27,721
servereoloserverVerified publisher0.1.02 of 7See more

server eoloserver 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
log4j-api@2.14.1
2.25.5
codeurjc/toposervice:v1.09fb4c11e6a49
log4j-api@2.19.0
2.25.5

Open the chart page →

32,205
dshackleethereum-helm-chartsVerified publisher0.1.91 of 2See more

dshackle ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.14.0126f0ae0b388
log4j-api@2.17.0
2.25.5

Open the chart page →

2,021
web3signerethereum-helm-chartsVerified publisher1.0.61 of 4See more

web3signer ethereum-helm-charts 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
consensys/web3signer:latestf146a51a1ba3
log4j-api@2.25.4
2.25.5

Open the chart page →

1,997
spring-boot-adminevryfs-ossVerified publisher0.1.101 of 1See more

spring-boot-admin evryfs-oss 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
log4j-api@2.17.2
2.25.5

Open the chart page →

5,998
eximeebpmseximeebpms-k8sOfficialVerified publisher0.3.01 of 1See more

eximeebpms eximeebpms-k8s 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.3.0acb8dbce38fd
log4j-api@2.25.3
2.25.5

Open the chart page →

727
fddb-exporterfddb-exporterVerified publisher2.4.31 of 1See more

fddb-exporter fddb-exporter 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
log4j-api@2.25.4
2.25.5

Open the chart page →

467
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
log4j-api@2.23.1
2.25.5
golenski/fibonacci-task-manager:2.0.03a2b36df247b
log4j-api@2.23.1
2.25.5
golenski/fibonacci-worker:2.0.0954caf4aaf6a
log4j-api@2.23.1
2.25.5

Open the chart page →

16,927

Container images carrying it

564 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
log4j-api@2.17.2
2.25.5
1
quay.io/infinispan/server:16.282db6cbba3d9
log4j-api@2.26.0
2.26.1
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
log4j-api@2.14.0
2.25.5
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
log4j-api@2.21.1
2.25.5
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
log4j-api@2.19.0
2.25.5
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
log4j-api@2.20.0
2.25.5
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
log4j-api@2.17.1
2.25.5
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
log4j-api@2.20.0
2.25.5
1
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
log4j-api@2.25.4
2.25.5
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
log4j-api@2.25.4
2.25.5
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
log4j-api@2.17.2
2.25.5
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
log4j-api@2.14.1
2.25.5
1
quay.io/strimzi/operator:0.45.158c727cd2e68
log4j-api@2.17.2
2.25.5
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
log4j-api@2.17.2
2.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.