StackRadar

CVE-2026-49844

Medium

Advisory

Published 11 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
603
of 17,781 indexed, latest versions
Container images
570
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Carried by container images the latest versions of 603 of 17,781 indexed charts deploy, on 570 images.

Affected packageAffected versionsFixed inImages
log4j-apimaven2.13.2, 2.13.3, 2.14.0, 2.14.1+24 more2.25.5, 2.26.1570
OSV records
GHSA-qv9r-c865-cp47

Charts affected

603 by stars
ChartLatestAffected imagesRadar Score
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
log4j-api@2.17.1
2.25.5

Open the chart page →

17,284
traccarjeffrescVerified publisher0.2.01 of 2See more

traccar jeffresc 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
traccar/traccar:6.7-alpine621c8d6d46fd
log4j-api@2.17.2
2.25.5

Open the chart page →

1,341
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
salehmir/jesse:1.10.101afa95f979e9
log4j-api@2.17.1
2.25.5

Open the chart page →

3,421
ipfix-generatorjfwenischVerified publisher0.3.16-feature-helm-package.01 of 1See more

ipfix-generator jfwenisch 0.3.16-feature-helm-package.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
log4j-api@2.24.3
2.25.5

Open the chart page →

697
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
log4j-api@2.17.2
2.25.5

Open the chart page →

2,067
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.01 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
log4j-api@2.20.0
2.25.5

Open the chart page →

14,130
kokukokuVerified publisher1.0.02 of 7See more

koku koku 1.0.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
log4j-api@2.17.1
2.25.5
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
log4j-api@2.24.3
2.25.5

Open the chart page →

12,019
auditflowlabs64io-helm-chartsVerified publisher0.12.11 of 3See more

auditflow labs64io-helm-charts 0.12.1

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
log4j-api@2.25.4
2.25.5

Open the chart page →

1,446
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.01 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
log4j-api@2.25.4
2.25.5

Open the chart page →

2,657
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
log4j-api@2.17.1
2.25.5

Open the chart page →

13,479
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
glarad/mc-service-registry:latest7b02b9e7f1ef
log4j-api@2.25.4
2.25.5

Open the chart page →

6,929
metabasemetabase-helmVerified publisher2.7.11 of 1See more

metabase metabase-helm 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
metabase/metabase:v0.46.09ebdc664a6b2
log4j-api@2.17.1
2.25.5

Open the chart page →

2,221
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
log4j-api@2.19.0
2.25.5

Open the chart page →

37,373
openccuopenccuVerified publisher3.89.81 of 1See more

openccu openccu 3.89.8

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
log4j-api@2.17.2
2.25.5

Open the chart page →

1,916
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
log4j-api@2.23.1
2.25.5

Open the chart page →

1,692
infinispanopenshift0.9.01 of 1See more

infinispan openshift 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/infinispan/server:16.282db6cbba3d9
log4j-api@2.26.0
2.26.1

Open the chart page →

41
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
log4j-api@2.25.4
2.25.5

Open the chart page →

22,420
todo-apipavanelthepu0.1.01 of 2See more

todo-api pavanelthepu 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
pavanelthepu/todo-api:1.0.2f47658e3b24c
log4j-api@2.14.1
2.25.5

Open the chart page →

2,544
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
log4j-api@2.17.2
2.25.5

Open the chart page →

7,576
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
log4j-api@2.17.1
2.25.5
treskon/portrait:DEV-latest88e813f22347
log4j-api@2.23.1
2.25.5

Open the chart page →

31,844
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
log4j-api@2.14.1
2.25.5

Open the chart page →

4,621
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
log4j-api@2.25.3
2.25.5

Open the chart page →

8,158
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
log4j-api@2.17.2
2.25.5

Open the chart page →

3,958
reportportalreportportal-ioOfficialVerified publisher26.8.123 of 15See more

reportportal reportportal-io 26.8.12

3 of the 15 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
reportportal/service-api:5.15.4bf193091525a
log4j-api@2.24.3
2.25.5
reportportal/service-authorization:5.15.16a954407b417
log4j-api@2.24.3
2.25.5
reportportal/service-jobs:5.15.299d27d58d6b4
log4j-api@2.21.1
2.25.5

Open the chart page →

11,869
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
log4j-api@2.17.2
2.25.5

Open the chart page →

6,639
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
log4j-api@2.24.3
2.25.5

Open the chart page →

7,432
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
log4j-api@2.17.2
2.25.5

Open the chart page →

9,837
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
log4j-api@2.14.1
2.25.5

Open the chart page →

10,120
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
log4j-api@2.17.1
2.25.5

Open the chart page →

6,045
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
log4j-api@2.17.1
2.25.5

Open the chart page →

7,529
sentinel-dashboardsentinel-dashboardVerified publisher0.1.01 of 1See more

sentinel-dashboard sentinel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
royalwang/sentinel-dashboard:1.8.4df99e2499f91
log4j-api@2.17.2
2.25.5

Open the chart page →

4,287
querysiakhooiVerified publisher1.0.01 of 1See more

query siakhooi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
siakhooi/query:1.0.0f1f4b5b1b870
log4j-api@2.25.3
2.25.5

Open the chart page →

1,792
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
log4j-api@2.23.1
2.25.5

Open the chart page →

2,406
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
log4j-api@2.24.3
2.25.5

Open the chart page →

1,482
stardogstardog3.1.01 of 3See more

stardog stardog 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
stardog/stardog:latest2714e5c4b3c1
log4j-api@2.25.4
2.25.5

Open the chart page →

293
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
log4j-api@2.17.2
2.25.5

Open the chart page →

13,486
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-api@2.16.0
2.25.5

Open the chart page →

24,930
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
log4j-api@2.24.3
2.25.5

Open the chart page →

2,826
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
log4j-api@2.20.0
2.25.5

Open the chart page →

7,835
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
log4j-api@2.20.0
2.25.5

Open the chart page →

2,168
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
log4j-api@2.20.0
2.25.5

Open the chart page →

2,326
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
log4j-api@2.20.0
2.25.5

Open the chart page →

2,853
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
log4j-api@2.17.1
2.25.5

Open the chart page →

7,713
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
log4j-api@2.20.0
2.25.5

Open the chart page →

2,221
quotes-provideraccount-serviceVerified publisher0.4.21 of 1See more

quotes-provider account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
log4j-api@2.20.0
2.25.5

Open the chart page →

2,205
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
log4j-api@2.25.2
2.25.5

Open the chart page →

3,188
migrationadeptia-automate-migration5.2.91 of 1See more

migration adeptia-automate-migration 5.2.9

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
log4j-api@2.25.3
2.25.5

Open the chart page →

395
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
log4j-api@2.23.1
2.25.5

Open the chart page →

854
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
log4j-api@2.17.2
2.25.5

Open the chart page →

1,413
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
airbyte/server:2.2.070e125498a1c
log4j-api@2.25.2
2.25.5

Open the chart page →

12,473

Container images carrying it

570 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/drill:1.21.11f96558fd292
log4j-api@2.19.0
2.25.5
1
apache/druid:29.0.10cef139b6bf1
log4j-api@2.18.0
2.25.5
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
log4j-api@2.25.4
2.25.5
1
apache/hertzbeat:1.8.075d48a62748f
log4j-api@2.24.3
2.25.5
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
log4j-api@2.24.3
2.25.5
1
apache/kafka:4.1.0bff074a5d005
log4j-api@2.24.3
2.25.5
1
apache/nifi-registry:1.14.0090b7f87ec7f
log4j-api@2.14.1
2.25.5
1
apachepinot/pinot:latest-jdk110018bb04ced7
log4j-api@2.17.1
2.25.5
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
log4j-api@2.18.0
2.25.5
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
log4j-api@2.17.1
2.25.5
1
apachepulsar/pulsar:3.0.79c9947de139d
log4j-api@2.18.0
2.25.5
1
apachepulsar/pulsar:2.9.0d056c89b7131
log4j-api@2.14.0
2.25.5
1
apachepulsar/pulsar:2.8.2d538416d5afe
log4j-api@2.17.0
2.25.5
1
apache/ranger:2.7.076c176e8a0e4
log4j-api@2.17.2
2.25.5
1
apache/rocketmq-exporter:0.0.2c8fb51195444
log4j-api@2.17.2
2.25.5
1
apache/shenyu-admin:2.5.1e2be712fc4f4
log4j-api@2.17.2
2.25.5
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
log4j-api@2.17.2
2.25.5
1
apache/skywalking-oap-server:9.2.0133d35d2c263
log4j-api@2.17.1
2.25.5
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
log4j-api@2.15.0
2.25.5
1
apache/skywalking-ui:8.9.180530f0308a5
log4j-api@2.13.3
2.25.5
1
apache/tika:3.3.1.090b7fa1dc018
log4j-api@2.26.0
2.26.1
1
apache/tika:2.9.0.092d055a84e9e
log4j-api@2.20.0
2.25.5
1
apache/tika:3.2.2.0-fullffab324253ed
log4j-api@2.25.1
2.25.5
1
apimap/api:v1.8.11ae2b3ab00177
log4j-api@2.17.2
2.25.5
1
aroralalit/student-producer:1.0.02a094f597b36
log4j-api@2.17.2
2.25.5
1
arturisimo/planner:v1.0fff9de644941
log4j-api@2.14.1
2.25.5
1
arturisimo/webapp-db-java:v2c95524e90b57
log4j-api@2.17.1
2.25.5
1
assistiot/automated_configuration:latest23f195a7a26a
log4j-api@2.17.1
2.25.5
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
log4j-api@2.17.0
2.25.5
1
assistiot/identity-manager_kc:latest0df4b4fa899a
log4j-api@2.17.2
2.25.5
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
log4j-api@2.17.2
2.25.5
1
atlassian/bamboo:12.1.114af4bb6c8d46
log4j-api@2.26.0
2.26.1
1
atlassian/bitbucket:10.2.705933f2b1cfd
log4j-api@2.25.3
2.25.5
1
atlassian/crowd:7.2.3c81cc7d6bc9e
log4j-api@2.26.0
2.26.1
1
atlassian/crowd:5.2.2ebf761c7d437
log4j-api@2.19.0
2.25.5
1
atlassian/jira-software:9.7.264a75aa4ec4e
log4j-api@2.17.2
2.25.5
1
atlassian/jira-software:11.3.11e5548cd4eea8
log4j-api@2.26.0
2.26.1
1
audig/clamapi:2.1.62c3fe34ee430
log4j-api@2.13.3
2.25.5
1
beastob/url-shortener:1.0.299a49885ab33
log4j-api@2.13.3
2.25.5
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
log4j-api@2.25.3
2.25.5
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
log4j-api@2.17.1
2.25.5
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
log4j-api@2.13.3
2.25.5
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
log4j-api@2.19.0
2.25.5
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
log4j-api@2.19.0
2.25.5
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
log4j-api@2.19.0
2.25.5
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
log4j-api@2.21.0
2.25.5
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
log4j-api@2.23.1
2.25.5
1
bluerange/bluerange:26.1.307c8f73b55df
log4j-api@2.24.3
2.25.5
1
camunda/zeebe:8.4.5ab5abc09e407
log4j-api@2.22.1
2.25.5
1
castlemock/castlemock:latestb7f3f1527ba9
log4j-api@2.24.3
2.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.