StackRadar

CVE-2026-49844

Medium

Advisory

Published 11 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
603
of 17,781 indexed, latest versions
Container images
570
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Carried by container images the latest versions of 603 of 17,781 indexed charts deploy, on 570 images.

Affected packageAffected versionsFixed inImages
log4j-apimaven2.13.2, 2.13.3, 2.14.0, 2.14.1+24 more2.25.5, 2.26.1570
OSV records
GHSA-qv9r-c865-cp47

Charts affected

603 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
log4j-api@2.19.0
2.25.5

Open the chart page →

6,556
metabasepmint932.27.61 of 1See more

metabase pmint93 2.27.6

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
log4j-api@2.25.4
2.25.5

Open the chart page →

1,639
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
log4j-api@2.17.1
2.25.5

Open the chart page →

7,713
kafka-uikafka-uiVerified publisher1.6.51 of 1See more

kafka-ui kafka-ui 1.6.5

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
log4j-api@2.24.3
2.25.5

Open the chart page →

729
jiraatlassian-data-centerVerified publisher2.0.151 of 2See more

jira atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
atlassian/jira-software:11.3.11e5548cd4eea8
log4j-api@2.26.0
2.26.1

Open the chart page →

1,490
trinotrino1.42.21 of 1See more

trino trino 1.42.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
trinodb/trino:4801565e8cac299
log4j-api@2.25.3
2.25.5

Open the chart page →

1,309
graylogkong-zVerified publisher3.0.321 of 5See more

graylog kong-z 3.0.32

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.19.68690b204fe91
log4j-api@2.25.4
2.25.5

Open the chart page →

2,699
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
log4j-api@2.17.0
2.25.5

Open the chart page →

32,259
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
penpotapp/backend:2.17.2770b55f6e51b
log4j-api@2.26.0
2.26.1

Open the chart page →

4,314
nacosygqygq2Verified publisher2.1.101 of 4See more

nacos ygqygq2 2.1.10

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.20e951a1d07bb
log4j-api@2.24.3
2.25.5

Open the chart page →

4,983
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
log4j-api@2.25.4
2.25.5

Open the chart page →

1,548
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.3b149b30da686
log4j-api@2.21.0
2.25.5

Open the chart page →

11,384
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
log4j-api@2.20.0
2.25.5

Open the chart page →

11,933
milvusmilvus-helm5.0.271 of 4See more

milvus milvus-helm 5.0.27

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
log4j-api@2.18.0
2.25.5

Open the chart page →

10,670
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
log4j-api@2.24.3
2.25.5

Open the chart page →

6,328
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
log4j-api@2.25.3
2.25.5

Open the chart page →

1,444
apim3graviteeioVerified publisher4.12.191 of 4See more

apim3 graviteeio 4.12.19

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
graviteeio/apim-management-api:4.12.19-debian27374522cd04
log4j-api@2.25.4
2.25.5

Open the chart page →

4,806
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
log4j-api@2.25.4
2.25.5

Open the chart page →

1,710
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
log4j-api@2.25.3
2.25.5

Open the chart page →

3,812
neo4jneo4j-helm4.3.2-11 of 1See more

neo4j neo4j-helm 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
log4j-api@2.14.0
2.25.5

Open the chart page →

2,640
metabasedeliveryheroVerified publisher0.14.41 of 1See more

metabase deliveryhero 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
log4j-api@2.18.0
2.25.5

Open the chart page →

2,572
grayloggroundhog2k0.13.101 of 1See more

graylog groundhog2k 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
graylog/graylog:7.1.9598bd41fefd5
log4j-api@2.26.0
2.26.1

Open the chart page →

1,074
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
log4j-api@2.13.3
2.25.5
platform9community/api-gateway:latest40a4970de568
log4j-api@2.13.3
2.25.5
platform9community/customers-service:latest2089811e5cc6
log4j-api@2.13.3
2.25.5
platform9community/vets-service:latestd1165c94dfb3
log4j-api@2.13.3
2.25.5
platform9community/visits-service:latest8d11b50368c6
log4j-api@2.13.3
2.25.5

Open the chart page →

41,872
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
log4j-api@2.13.2
2.25.5

Open the chart page →

6,048
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
log4j-api@2.23.1
2.25.5

Open the chart page →

7,268
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
log4j-api@2.25.0
2.25.5

Open the chart page →

2,283
crowdatlassian-data-centerVerified publisher2.0.151 of 2See more

crowd atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
atlassian/crowd:7.2.3c81cc7d6bc9e
log4j-api@2.26.0
2.26.1

Open the chart page →

1,415
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
log4j-api@2.26.0
2.26.1

Open the chart page →

1,500
janssenjanssen-auth-serverOfficialVerified publisher0.0.0-nightly7 of 8See more

janssen janssen-auth-server 0.0.0-nightly

7 of the 8 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/janssenproject/jans/auth-server:0.0.0-nightly7752874e71d8
log4j-api@2.25.4
2.25.5
ghcr.io/janssenproject/jans/casa:0.0.0-nightly3f2d14563495
log4j-api@2.25.4
2.25.5
ghcr.io/janssenproject/jans/cloudtools:0.0.0-nightly1fd3779f208e
log4j-api@2.25.4
2.25.5
ghcr.io/janssenproject/jans/config-api:0.0.0-nightly900e2b88bd08
log4j-api@2.25.4
2.25.5
ghcr.io/janssenproject/jans/configurator:0.0.0-nightly5128775117aa
log4j-api@2.25.4
2.25.5
ghcr.io/janssenproject/jans/fido2:0.0.0-nightly2a797804f08c
log4j-api@2.25.4
2.25.5
ghcr.io/janssenproject/jans/scim:0.0.0-nightly096b8bcbbe45
log4j-api@2.25.4
2.25.5

Open the chart page →

1,068
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
log4j-api@2.17.2
2.25.5

Open the chart page →

8,636
thehivestrangebee-helmOfficialVerified publisher1.0.61 of 7See more

thehive strangebee-helm 1.0.6

1 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
log4j-api@2.19.0
2.25.5

Open the chart page →

16,210
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.11.1a7a2076b167e
log4j-api@2.21.0
2.25.5

Open the chart page →

6,168
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
log4j-api@2.18.0
2.25.5

Open the chart page →

7,930
zipkinygqygq2Verified publisher2.1.41 of 4See more

zipkin ygqygq2 2.1.4

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.24197a9692f6a9
log4j-api@2.22.0
2.25.5

Open the chart page →

2,764
bambooatlassian-data-centerVerified publisher2.0.151 of 2See more

bamboo atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
atlassian/bamboo:12.1.114af4bb6c8d46
log4j-api@2.26.0
2.26.1

Open the chart page →

2,031
seafiledatamateVerified publisher0.6.02 of 6See more

seafile datamate 0.6.0

2 of the 6 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
log4j-api@2.19.0
2.25.5
datamate/seafile-professional:11.0.202dd66b722464
log4j-api@2.18.0
2.25.5

Open the chart page →

27,267
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
log4j-api@2.25.3
2.25.5

Open the chart page →

13,953
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
log4j-api@2.24.3
2.25.5
apache/hertzbeat-collector:1.8.0a2bab1be574c
log4j-api@2.24.3
2.25.5

Open the chart page →

14,000
infrahubinfrahubVerified publisher4.33.21 of 5See more

infrahub infrahub 4.33.2

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/neo4j:2026.05.06c162e2432f8
log4j-api@2.25.4
2.25.5

Open the chart page →

10,428
kubernetes-loggingkubernetes-logging4.8.02 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

2 of the 6 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
log4j-api@2.17.1
2.25.5
opensearchproject/opensearch:2.10.0c8f3ebd2a934
log4j-api@2.20.0
2.25.5

Open the chart page →

10,530
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
log4j-api@2.17.2
2.25.5

Open the chart page →

10,469
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
log4j-api@2.17.1
2.25.5

Open the chart page →

7,166
geoservercloudcamptocamp23.0.17 of 7See more

geoservercloud camptocamp2 3.0.1

7 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
log4j-api@2.26.0
2.26.1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
log4j-api@2.26.0
2.26.1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
log4j-api@2.26.0
2.26.1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
log4j-api@2.26.0
2.26.1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
log4j-api@2.26.0
2.26.1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
log4j-api@2.26.0
2.26.1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
log4j-api@2.26.0
2.26.1

Open the chart page →

10,546
opensearchcaptnbpVerified publisher3.1.11 of 2See more

opensearch captnbp 3.1.1

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.19.269588c664014
log4j-api@2.21.0
2.25.5

Open the chart page →

998
thingsboardcetic0.1.21 of 2See more

thingsboard cetic 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
thingsboard/tb-postgres:latest2d17e4e36edc
log4j-api@2.24.3
2.25.5

Open the chart page →

5,235
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/convertigo:8.4.3ae605bfcda05
log4j-api@2.25.4
2.25.5

Open the chart page →

17,404
cosmotech-apicosmotech-apiVerified publisher5.2.01 of 1See more

cosmotech-api cosmotech-api 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-api:5.2.0269ee25c359b
log4j-api@2.25.4
2.25.5

Open the chart page →

206
flowableflowable-oss7.1.01 of 2See more

flowable flowable-oss 7.1.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
flowable/flowable-rest:7.1.0b7ae287502cd
log4j-api@2.23.1
2.25.5

Open the chart page →

2,784
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
log4j-api@2.24.3
2.25.5

Open the chart page →

4,641
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
log4j-api@2.17.2
2.25.5

Open the chart page →

11,839

Container images carrying it

570 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/drill:1.21.11f96558fd292
log4j-api@2.19.0
2.25.5
1
apache/druid:29.0.10cef139b6bf1
log4j-api@2.18.0
2.25.5
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
log4j-api@2.25.4
2.25.5
1
apache/hertzbeat:1.8.075d48a62748f
log4j-api@2.24.3
2.25.5
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
log4j-api@2.24.3
2.25.5
1
apache/kafka:4.1.0bff074a5d005
log4j-api@2.24.3
2.25.5
1
apache/nifi-registry:1.14.0090b7f87ec7f
log4j-api@2.14.1
2.25.5
1
apachepinot/pinot:latest-jdk110018bb04ced7
log4j-api@2.17.1
2.25.5
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
log4j-api@2.18.0
2.25.5
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
log4j-api@2.17.1
2.25.5
1
apachepulsar/pulsar:3.0.79c9947de139d
log4j-api@2.18.0
2.25.5
1
apachepulsar/pulsar:2.9.0d056c89b7131
log4j-api@2.14.0
2.25.5
1
apachepulsar/pulsar:2.8.2d538416d5afe
log4j-api@2.17.0
2.25.5
1
apache/ranger:2.7.076c176e8a0e4
log4j-api@2.17.2
2.25.5
1
apache/rocketmq-exporter:0.0.2c8fb51195444
log4j-api@2.17.2
2.25.5
1
apache/shenyu-admin:2.5.1e2be712fc4f4
log4j-api@2.17.2
2.25.5
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
log4j-api@2.17.2
2.25.5
1
apache/skywalking-oap-server:9.2.0133d35d2c263
log4j-api@2.17.1
2.25.5
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
log4j-api@2.15.0
2.25.5
1
apache/skywalking-ui:8.9.180530f0308a5
log4j-api@2.13.3
2.25.5
1
apache/tika:3.3.1.090b7fa1dc018
log4j-api@2.26.0
2.26.1
1
apache/tika:2.9.0.092d055a84e9e
log4j-api@2.20.0
2.25.5
1
apache/tika:3.2.2.0-fullffab324253ed
log4j-api@2.25.1
2.25.5
1
apimap/api:v1.8.11ae2b3ab00177
log4j-api@2.17.2
2.25.5
1
aroralalit/student-producer:1.0.02a094f597b36
log4j-api@2.17.2
2.25.5
1
arturisimo/planner:v1.0fff9de644941
log4j-api@2.14.1
2.25.5
1
arturisimo/webapp-db-java:v2c95524e90b57
log4j-api@2.17.1
2.25.5
1
assistiot/automated_configuration:latest23f195a7a26a
log4j-api@2.17.1
2.25.5
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
log4j-api@2.17.0
2.25.5
1
assistiot/identity-manager_kc:latest0df4b4fa899a
log4j-api@2.17.2
2.25.5
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
log4j-api@2.17.2
2.25.5
1
atlassian/bamboo:12.1.114af4bb6c8d46
log4j-api@2.26.0
2.26.1
1
atlassian/bitbucket:10.2.705933f2b1cfd
log4j-api@2.25.3
2.25.5
1
atlassian/crowd:7.2.3c81cc7d6bc9e
log4j-api@2.26.0
2.26.1
1
atlassian/crowd:5.2.2ebf761c7d437
log4j-api@2.19.0
2.25.5
1
atlassian/jira-software:9.7.264a75aa4ec4e
log4j-api@2.17.2
2.25.5
1
atlassian/jira-software:11.3.11e5548cd4eea8
log4j-api@2.26.0
2.26.1
1
audig/clamapi:2.1.62c3fe34ee430
log4j-api@2.13.3
2.25.5
1
beastob/url-shortener:1.0.299a49885ab33
log4j-api@2.13.3
2.25.5
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
log4j-api@2.25.3
2.25.5
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
log4j-api@2.17.1
2.25.5
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
log4j-api@2.13.3
2.25.5
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
log4j-api@2.19.0
2.25.5
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
log4j-api@2.19.0
2.25.5
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
log4j-api@2.19.0
2.25.5
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
log4j-api@2.21.0
2.25.5
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
log4j-api@2.23.1
2.25.5
1
bluerange/bluerange:26.1.307c8f73b55df
log4j-api@2.24.3
2.25.5
1
camunda/zeebe:8.4.5ab5abc09e407
log4j-api@2.22.1
2.25.5
1
castlemock/castlemock:latestb7f3f1527ba9
log4j-api@2.24.3
2.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.