StackRadar

CVE-2026-49844

Medium

Advisory

Published 11 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
603
of 17,781 indexed, latest versions
Container images
570
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Carried by container images the latest versions of 603 of 17,781 indexed charts deploy, on 570 images.

Affected packageAffected versionsFixed inImages
log4j-apimaven2.13.2, 2.13.3, 2.14.0, 2.14.1+24 more2.25.5, 2.26.1570
OSV records
GHSA-qv9r-c865-cp47

Charts affected

603 by stars
ChartLatestAffected imagesRadar Score
eximeebpmseximeebpms-k8sOfficialVerified publisher0.3.01 of 1See more

eximeebpms eximeebpms-k8s 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.3.0acb8dbce38fd
log4j-api@2.25.3
2.25.5

Open the chart page →

727
fddb-exporterfddb-exporterVerified publisher2.4.31 of 1See more

fddb-exporter fddb-exporter 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
log4j-api@2.25.4
2.25.5

Open the chart page →

467
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
log4j-api@2.23.1
2.25.5
golenski/fibonacci-task-manager:2.0.03a2b36df247b
log4j-api@2.23.1
2.25.5
golenski/fibonacci-worker:2.0.0954caf4aaf6a
log4j-api@2.23.1
2.25.5

Open the chart page →

16,927
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
log4j-api@2.23.1
2.25.5

Open the chart page →

12,454
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
log4j-api@2.14.1
2.25.5

Open the chart page →

7,691
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
log4j-api@2.24.3
2.25.5

Open the chart page →

7,792
scorpio-brokerfiware0.3.39 of 10See more

scorpio-broker fiware 0.3.3

9 of the 10 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
log4j-api@2.14.1
2.25.5

Open the chart page →

55,600
scorpiobrokerfiware0.1.29 of 10See more

scorpiobroker fiware 0.1.2

9 of the 10 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
log4j-api@2.14.1
2.25.5
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
log4j-api@2.14.1
2.25.5

Open the chart page →

55,600
scorpio-broker-aaiofiware0.4.151 of 1See more

scorpio-broker-aaio fiware 0.4.15

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
log4j-api@2.14.1
2.25.5

Open the chart page →

5,286
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
log4j-api@2.19.0
2.25.5

Open the chart page →

24,296
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
log4j-api@2.17.1
2.25.5

Open the chart page →

5,651
base-depflofree-chartVerified publisher1.0.11 of 1See more

base-dep flofree-chart 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
flofree/base-project:2.1.16b6486c5f81e
log4j-api@2.17.2
2.25.5

Open the chart page →

2,797
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-api@2.24.3
2.25.5

Open the chart page →

3,463
edge-caiasoftfolio-org0.1.321 of 1See more

edge-caiasoft folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/edge-caiasoft:latestc3cfa89eee2f
log4j-api@2.25.4
2.25.5

Open the chart page →

525
edge-connexionfolio-org0.1.51 of 1See more

edge-connexion folio-org 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/edge-connexion:latestb4863d135524
log4j-api@2.20.0
2.25.5

Open the chart page →

1,132
edge-dematicfolio-org0.1.331 of 1See more

edge-dematic folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/edge-dematic:latest48c9b1d180d4
log4j-api@2.25.4
2.25.5

Open the chart page →

525
edge-inn-reachfolio-org0.1.41 of 1See more

edge-inn-reach folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/edge-inn-reach:latestc64e4d9dd3fc
log4j-api@2.25.4
2.25.5

Open the chart page →

525
edge-ncipfolio-org0.1.281 of 1See more

edge-ncip folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/edge-ncip:lateste760dbb81d1a
log4j-api@2.20.0
2.25.5

Open the chart page →

820
edge-oai-pmhfolio-org0.1.311 of 1See more

edge-oai-pmh folio-org 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/edge-oai-pmh:latesteedfcbc29792
log4j-api@2.23.1
2.25.5

Open the chart page →

874
edge-ordersfolio-org0.1.301 of 1See more

edge-orders folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/edge-orders:latest1ef654ee9f23
log4j-api@2.25.4
2.25.5

Open the chart page →

735
edge-patronfolio-org0.1.281 of 1See more

edge-patron folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/edge-patron:latest682b852e056d
log4j-api@2.23.0
2.25.5

Open the chart page →

905
edge-rtacfolio-org0.1.281 of 1See more

edge-rtac folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/edge-rtac:latest15ef73b1abd0
log4j-api@2.25.3
2.25.5

Open the chart page →

1,259
mod-aesfolio-org0.1.331 of 1See more

mod-aes folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-aes:latest6d67e9564270
log4j-api@2.14.1
2.25.5

Open the chart page →

2,281
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
log4j-api@2.17.2
2.25.5

Open the chart page →

1,874
mod-auditfolio-org0.1.361 of 1See more

mod-audit folio-org 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-audit:latest88f40730ed45
log4j-api@2.26.0
2.26.1

Open the chart page →

267
mod-authtokenfolio-org0.1.351 of 1See more

mod-authtoken folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-authtoken:latest995a25a33133
log4j-api@2.24.3
2.25.5

Open the chart page →

1,558
mod-calendarfolio-org0.1.341 of 1See more

mod-calendar folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-calendar:latest22f65982efd7
log4j-api@2.25.4
2.25.5

Open the chart page →

415
mod-circulationfolio-org0.1.351 of 1See more

mod-circulation folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-circulation:latest3eecd2ac2d8a
log4j-api@2.24.3
2.25.5

Open the chart page →

497
mod-circulation-storagefolio-org0.1.351 of 1See more

mod-circulation-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-circulation-storage:latest6bdddcafbc0f
log4j-api@2.20.0
2.25.5

Open the chart page →

658
mod-codex-ekbfolio-org0.1.341 of 1See more

mod-codex-ekb folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-codex-ekb:latest235a3fa4adc9
log4j-api@2.19.0
2.25.5

Open the chart page →

2,113
mod-codex-inventoryfolio-org0.1.341 of 1See more

mod-codex-inventory folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-codex-inventory:latest6d53ed758fd1
log4j-api@2.17.2
2.25.5

Open the chart page →

1,901
mod-codex-muxfolio-org0.1.341 of 1See more

mod-codex-mux folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-codex-mux:latestd4138abfd30d
log4j-api@2.17.2
2.25.5

Open the chart page →

1,755
mod-configurationfolio-org0.1.341 of 1See more

mod-configuration folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-configuration:latestdd0cdc89670a
log4j-api@2.25.4
2.25.5

Open the chart page →

711
mod-copycatfolio-org0.1.31 of 1See more

mod-copycat folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-copycat:latest1513fad2b799
log4j-api@2.25.4
2.25.5

Open the chart page →

1,466
mod-coursesfolio-org0.1.341 of 1See more

mod-courses folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-courses:latest68ca414f5596
log4j-api@2.24.3
2.25.5

Open the chart page →

1,533
mod-data-exportfolio-org0.1.401 of 1See more

mod-data-export folio-org 0.1.40

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-data-export:latest0cc86bf09755
log4j-api@2.25.3
2.25.5

Open the chart page →

1,393
mod-data-export-springfolio-org0.1.41 of 1See more

mod-data-export-spring folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-data-export-spring:latestf1d7caf4544b
log4j-api@2.25.3
2.25.5

Open the chart page →

1,253
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
log4j-api@2.25.3
2.25.5

Open the chart page →

1,214
mod-data-import-converter-storagefolio-org0.1.341 of 1See more

mod-data-import-converter-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-data-import-converter-storage:latest3028f333778f
log4j-api@2.17.2
2.25.5

Open the chart page →

2,488
mod-ebsconetfolio-org0.1.31 of 1See more

mod-ebsconet folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-ebsconet:latest3ae8cb99daa3
log4j-api@2.25.2
2.25.5

Open the chart page →

1,203
mod-emailfolio-org0.1.341 of 1See more

mod-email folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-email:latest79ea8e2e7ebf
log4j-api@2.25.3
2.25.5

Open the chart page →

866
mod-erm-usage-harvesterfolio-org0.1.341 of 1See more

mod-erm-usage-harvester folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-erm-usage-harvester:latest2d6767933c59
log4j-api@2.25.4
2.25.5

Open the chart page →

563
mod-eusage-reportsfolio-org0.1.21 of 1See more

mod-eusage-reports folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-eusage-reports:latest15de67587091
log4j-api@2.25.3
2.25.5

Open the chart page →

1,224
mod-event-configfolio-org0.1.341 of 1See more

mod-event-config folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-event-config:latest0192adad3897
log4j-api@2.26.0
2.26.1

Open the chart page →

420
mod-feesfinesfolio-org0.1.341 of 1See more

mod-feesfines folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-feesfines:latestfe3a7049f2fb
log4j-api@2.24.3
2.25.5

Open the chart page →

663
mod-financefolio-org0.1.341 of 1See more

mod-finance folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-finance:latest14450bc15430
log4j-api@2.26.0
2.26.1

Open the chart page →

534
mod-finance-storagefolio-org0.1.341 of 1See more

mod-finance-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-finance-storage:latest4bc4057abaea
log4j-api@2.26.0
2.26.1

Open the chart page →

413
mod-gobifolio-org0.1.341 of 1See more

mod-gobi folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-gobi:latestc58c989dac44
log4j-api@2.26.0
2.26.1

Open the chart page →

595
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
log4j-api@2.19.0
2.25.5

Open the chart page →

512
mod-inventory-updatefolio-org0.1.21 of 1See more

mod-inventory-update folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
folioci/mod-inventory-update:latestba84812b4d58
log4j-api@2.24.3
2.25.5

Open the chart page →

878

Container images carrying it

570 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
log4j-api@2.24.3
2.25.5
1
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
log4j-api@2.24.3
2.25.5
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
log4j-api@2.24.3
2.25.5
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
log4j-api@2.24.3
2.25.5
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
log4j-api@2.17.1
2.25.5
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
log4j-api@2.24.3
2.25.5
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
log4j-api@2.17.2
2.25.5
1
quay.io/infinispan/server:16.282db6cbba3d9
log4j-api@2.26.0
2.26.1
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
log4j-api@2.14.0
2.25.5
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
log4j-api@2.21.1
2.25.5
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
log4j-api@2.19.0
2.25.5
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
log4j-api@2.20.0
2.25.5
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
log4j-api@2.17.1
2.25.5
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
log4j-api@2.20.0
2.25.5
1
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
log4j-api@2.25.4
2.25.5
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
log4j-api@2.25.4
2.25.5
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
log4j-api@2.17.2
2.25.5
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
log4j-api@2.14.1
2.25.5
1
quay.io/strimzi/operator:0.45.158c727cd2e68
log4j-api@2.17.2
2.25.5
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
log4j-api@2.17.2
2.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.