StackRadar

CVE-2026-49844

Medium

Advisory

Published 11 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
603
of 17,781 indexed, latest versions
Container images
570
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Carried by container images the latest versions of 603 of 17,781 indexed charts deploy, on 570 images.

Affected packageAffected versionsFixed inImages
log4j-apimaven2.13.2, 2.13.3, 2.14.0, 2.14.1+24 more2.25.5, 2.26.1570
OSV records
GHSA-qv9r-c865-cp47

Charts affected

603 by stars
ChartLatestAffected imagesRadar Score
airports-apiairports-api0.1.01 of 1See more

airports-api airports-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
log4j-api@2.19.0
2.25.5

Open the chart page →

1,958
airports-consumerairports-consumer0.1.01 of 1See more

airports-consumer airports-consumer 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dina1993/airports-consumer:latest669d146a5e63
log4j-api@2.19.0
2.25.5

Open the chart page →

1,947
airports-producerairports-producer0.1.01 of 1See more

airports-producer airports-producer 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dina1993/airports-producer:latest3d6b0dac1cb4
log4j-api@2.19.0
2.25.5

Open the chart page →

1,947
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
log4j-api@2.23.1
2.25.5

Open the chart page →

1,748
aktoakto0.2.01 of 7See more

akto akto 0.2.0

1 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-dashboard:latestb53a854bd7c1
log4j-api@2.26.0
2.26.1

Open the chart page →

13,613
akto-central-setupakto1.1.103 of 5See more

akto-central-setup akto 1.1.10

3 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2b53a854bd7c1
log4j-api@2.26.0
2.26.1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
log4j-api@2.26.0
2.26.1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
log4j-api@2.25.4
2.25.5

Open the chart page →

4,905
akto-dashboardakto0.1.71 of 1See more

akto-dashboard akto 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
log4j-api@2.26.0
2.26.1

Open the chart page →

1,162
akto-dbabsakto0.1.91 of 1See more

akto-dbabs akto 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
log4j-api@2.26.0
2.26.1

Open the chart page →

1,125
akto-hybrid-redactakto1.44.41 of 5See more

akto-hybrid-redact akto 1.44.4

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
log4j-api@2.24.3
2.25.5

Open the chart page →

4,777
akto-mini-runtimeakto0.7.221 of 3See more

akto-mini-runtime akto 0.7.22

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
log4j-api@2.25.4
2.25.5

Open the chart page →

2,741
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
log4j-api@2.24.3
2.25.5

Open the chart page →

3,217
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
log4j-api@2.25.4
2.25.5

Open the chart page →

6,486
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
log4j-api@2.24.3
2.25.5

Open the chart page →

1,826
akto-regional-setupakto1.3.13 of 9See more

akto-regional-setup akto 1.3.1

3 of the 9 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
log4j-api@2.26.0
2.26.1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
log4j-api@2.24.2
2.25.5
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
log4j-api@2.25.4
2.25.5

Open the chart page →

7,603
akto-runtimeakto0.1.81 of 2See more

akto-runtime akto 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
log4j-api@2.25.4
2.25.5

Open the chart page →

1,411
akto-threat-backendakto0.1.51 of 2See more

akto-threat-backend akto 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
log4j-api@2.25.4
2.25.5

Open the chart page →

1,490
akto-threat-clientakto0.2.02 of 2See more

akto-threat-client akto 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
log4j-api@2.24.2
2.25.5
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
log4j-api@2.25.4
2.25.5

Open the chart page →

1,523
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
log4j-api@2.17.1
2.25.5

Open the chart page →

2,099
zunivers-ninjaalexpressoVerified publisher1.31.21 of 2See more

zunivers-ninja alexpresso 1.31.2

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/neo4j:5.18.18f01f7bb053e
log4j-api@2.20.0
2.25.5

Open the chart page →

1,165
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
amorphieamorphie0.1.24 of 18See more

amorphie amorphie 0.1.2

4 of the 18 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
log4j-api@2.22.1
2.25.5
hazelcast/hazelcast:5.3.18fe26efde8e1
log4j-api@2.20.0
2.25.5
hazelcast/management-center:5.3.2f9d34300d330
log4j-api@2.17.2
2.25.5
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
log4j-api@2.21.1
2.25.5

Open the chart page →

28,131
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
log4j-api@2.23.1
2.25.5

Open the chart page →

11,553
apimap-apiapimapOfficialVerified publisher1.8.111 of 1See more

apimap-api apimap 1.8.11

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apimap/api:v1.8.11ae2b3ab00177
log4j-api@2.17.2
2.25.5

Open the chart page →

2,231
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
log4j-api@2.21.1
2.25.5

Open the chart page →

6,187
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
log4j-api@2.24.3
2.25.5

Open the chart page →

3,963
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
log4j-api@2.17.1
2.25.5
ghcr.io/appscode/inbox-server:latest536358d7b17e
log4j-api@2.24.3
2.25.5

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
log4j-api@2.17.1
2.25.5
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
log4j-api@2.20.0
2.25.5

Open the chart page →

16,975
kafka-uiappscodeVerified publisher2026.3.301 of 1See more

kafka-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
log4j-api@2.24.3
2.25.5

Open the chart page →

729
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
log4j-api@2.13.3
2.25.5

Open the chart page →

8,866
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
log4j-api@2.19.0
2.25.5

Open the chart page →

40,238
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
assistiot/automated_configuration:latest23f195a7a26a
log4j-api@2.17.1
2.25.5
provectuslabs/kafka-ui:latest8f2ff02d64b0
log4j-api@2.20.0
2.25.5

Open the chart page →

14,728
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
log4j-api@2.17.2
2.25.5

Open the chart page →

13,352
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
log4j-api@2.17.2
2.25.5

Open the chart page →

4,145
url-shortenerbeastob1.0.21 of 3See more

url-shortener beastob 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
beastob/url-shortener:1.0.299a49885ab33
log4j-api@2.13.3
2.25.5

Open the chart page →

3,607
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
log4j-api@2.23.1
2.25.5

Open the chart page →

4,292
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
log4j-api@2.17.2
2.25.5

Open the chart page →

13,459
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
log4j-api@2.24.3
2.25.5

Open the chart page →

1,816
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
log4j-api@2.24.3
2.25.5

Open the chart page →

26,996
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
log4j-api@2.13.3
2.25.5

Open the chart page →

11,869
casepack-apibysamioVerified publisher0.31.01 of 1See more

casepack-api bysamio 0.31.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/bysamio/casepack-api:0.31.00eb3ad229c2c
log4j-api@2.24.3
2.25.5

Open the chart page →

339
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/kafka:4.1.0bff074a5d005
log4j-api@2.24.3
2.25.5

Open the chart page →

2,398
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
log4j-api@2.13.3
2.25.5

Open the chart page →

20,190
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
log4j-api@2.24.3
2.25.5

Open the chart page →

8,001
geoservercamptocamp20.0.36 of 12See more

geoserver camptocamp2 0.0.3

6 of the 12 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
log4j-api@2.13.3
2.25.5
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
log4j-api@2.13.3
2.25.5
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
log4j-api@2.13.3
2.25.5
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
log4j-api@2.13.3
2.25.5
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
log4j-api@2.13.3
2.25.5
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
log4j-api@2.13.3
2.25.5

Open the chart page →

88,335
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
log4j-api@2.21.0
2.25.5

Open the chart page →

1,073

Container images carrying it

570 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
log4j-api@2.14.1
2.25.5
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
log4j-api@2.14.1
2.25.5
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
log4j-api@2.14.1
2.25.5
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
log4j-api@2.14.1
2.25.5
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
log4j-api@2.14.1
2.25.5
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
log4j-api@2.17.1
2.25.5
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
log4j-api@2.24.3
2.25.5
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-api@2.24.3
2.25.5
2
ghcr.io/janssenproject/jans/auth-server:0.0.0-nightly7752874e71d8
log4j-api@2.25.4
2.25.5
2
ghcr.io/janssenproject/jans/casa:0.0.0-nightly3f2d14563495
log4j-api@2.25.4
2.25.5
2
ghcr.io/janssenproject/jans/cloudtools:0.0.0-nightly1fd3779f208e
log4j-api@2.25.4
2.25.5
2
ghcr.io/janssenproject/jans/config-api:0.0.0-nightly900e2b88bd08
log4j-api@2.25.4
2.25.5
2
ghcr.io/janssenproject/jans/configurator:0.0.0-nightly5128775117aa
log4j-api@2.25.4
2.25.5
2
ghcr.io/janssenproject/jans/fido2:0.0.0-nightly2a797804f08c
log4j-api@2.25.4
2.25.5
2
ghcr.io/janssenproject/jans/scim:0.0.0-nightly096b8bcbbe45
log4j-api@2.25.4
2.25.5
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
log4j-api@2.24.3
2.25.5
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
log4j-api@2.17.2
2.25.5
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
log4j-api@2.26.0
2.26.1
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
log4j-api@2.24.3
2.25.5
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
log4j-api@2.17.1
2.25.5
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
log4j-api@2.17.2
2.25.5
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
log4j-api@2.17.2
2.25.5
2
2martens/configserver:latestbf1cdb80239d
log4j-api@2.23.1
2.25.5
1
2martens/timetable:latestbd1ba6ab84c9
log4j-api@2.25.1
2.25.5
1
2martens/wahlrecht:latestba2c3040dab0
log4j-api@2.25.1
2.25.5
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
log4j-api@2.24.3
2.25.5
1
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
log4j-api@2.17.1
2.25.5
1
adagber/planner:v1.0e5c1ed097752
log4j-api@2.14.1
2.25.5
1
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
log4j-api@2.25.3
2.25.5
1
adeptiainc/adeptia-connect-migration:4.8.1f1087da3da0b
log4j-api@2.25.4
2.25.5
1
adityaprasadpathak/myapp:3.07e3b9777362c
log4j-api@2.23.1
2.25.5
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
log4j-api@2.23.1
2.25.5
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
log4j-api@2.22.1
2.25.5
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
log4j-api@2.20.0
2.25.5
1
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
log4j-api@2.23.1
2.25.5
1
airbyte/cron:0.40.17caf4f551c546
log4j-api@2.17.2
2.25.5
1
airbyte/server:2.2.070e125498a1c
log4j-api@2.25.2
2.25.5
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
log4j-api@2.14.1
2.25.5
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
log4j-api@2.26.0
2.26.1
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
log4j-api@2.26.0
2.26.1
1
alfio/alf.io:2.0-M5-26060c836a081446
log4j-api@2.24.3
2.25.5
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
log4j-api@2.24.1
2.25.5
1
amartinm82/planner:v2.01184353ff57b
log4j-api@2.13.3
2.25.5
1
andrianrf/backoffice-be:latest6036614803d4
log4j-api@2.17.2
2.25.5
1
andrianrf/bpjstk-service:latest46abe878d9d8
log4j-api@2.13.3
2.25.5
1
andrianrf/bpjstk-simulator:latestb63fdb51d39d
log4j-api@2.13.3
2.25.5
1
andrianrf/iso-client:latestba560086ce15
log4j-api@2.13.3
2.25.5
1
andrianrf/iso-server:latest7da47f525c7d
log4j-api@2.13.3
2.25.5
1
apache/activemq-artemis:2.44.00305c26f19ed
log4j-api@2.25.2
2.25.5
1
apache/activemq-artemis:2.37.0bae523439ee3
log4j-api@2.23.1
2.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.