StackRadar

CVE-2026-49844

Medium

Advisory

Published 11 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
600
of 17,787 indexed, latest versions
Container images
566
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Carried by container images the latest versions of 600 of 17,787 indexed charts deploy, on 566 images.

Affected packageAffected versionsFixed inImages
log4j-apimaven2.13.2, 2.13.3, 2.14.0, 2.14.1+24 more2.25.5, 2.26.1566
OSV records
GHSA-qv9r-c865-cp47

Charts affected

600 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

566 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hazelcast/hazelcast:latestf086bf0ecb23
log4j-api@2.25.4
2.25.5
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
log4j-api@2.17.0
2.25.5
1
hazelcast/management-center:5.3.2f9d34300d330
log4j-api@2.17.2
2.25.5
1
hmediade/printserver:latest481a552c8e1c
log4j-api@2.17.2
2.25.5
1
housewrecker/gaps:latestf417dd0a7547
log4j-api@2.17.0
2.25.5
1
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
log4j-api@2.20.0
2.25.5
1
huertaslopez/i.huertas.2021-v.martinp.2021-planner:2.0.0e2c18bd65472
log4j-api@2.14.1
2.25.5
1
hugohg34/planner:0.0.2171f61e8d7e2
log4j-api@2.14.1
2.25.5
1
hugohg34/toposervice:0.0.2812a03b3f274
log4j-api@2.14.1
2.25.5
1
iamdorsah/bastillion:v0.1db83a0254d81
log4j-api@2.17.1
2.25.5
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
log4j-api@2.21.1
2.25.5
1
j4ckhunter/consumer:1.00bb7a429e3e75
log4j-api@2.17.2
2.25.5
1
j4ckhunter/producer:1.006ba447609b12
log4j-api@2.17.2
2.25.5
1
jacobalberty/unifi:v7.1.664a3616625dda
log4j-api@2.17.2
2.25.5
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
log4j-api@2.17.2
2.25.5
1
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
log4j-api@2.21.1
2.25.5
1
jhidalgo3/spring-echo-example:lateste08733191ea0
log4j-api@2.13.3
2.25.5
1
jhipster/jhipster-registry:latest7184525acd4d
log4j-api@2.17.2
2.25.5
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
log4j-api@2.17.2
2.25.5
1
just1not2/streama:1.10.48a2305192dec
log4j-api@2.17.1
2.25.5
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
log4j-api@2.20.0
2.25.5
1
keyfactor/signserver-ce:7.3.2798fbbe00283
log4j-api@2.23.1
2.25.5
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
log4j-api@2.25.4
2.25.5
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
log4j-api@2.13.3
2.25.5
1
krontechnology/aapm-service:1.1.39dd602db8baa
log4j-api@2.24.3
2.25.5
1
kubebb/gateway-api:v5.6.04d062f20309c
log4j-api@2.17.2
2.25.5
1
kubebb/mesh-api:v5.7.0a3879931dfa1
log4j-api@2.17.1
2.25.5
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
log4j-api@2.23.1
2.25.5
1
labs64/auditflowc7b26d3ca11c
log4j-api@2.25.4
2.25.5
1
labs64/payment-gateway:0.0.10c66feefca17
log4j-api@2.25.4
2.25.5
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
log4j-api@2.13.3
2.25.5
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
log4j-api@2.13.3
2.25.5
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
log4j-api@2.13.3
2.25.5
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
log4j-api@2.17.0
2.25.5
1
lavandadelpatio/tmdb:latestded9377636e9
log4j-api@2.20.0
2.25.5
1
lavandadelpatio/tmdb:0.0.2f36af885e915
log4j-api@2.13.3
2.25.5
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
log4j-api@2.19.0
2.25.5
1
library/convertigo:8.4.3ae605bfcda05
log4j-api@2.25.4
2.25.5
1
library/crate:4.7.0c7984a05e15b
log4j-api@2.17.1
2.25.5
1
library/elasticsearch:8.17.32cc40b15dff8
log4j-api@2.19.0
2.25.5
1
library/elasticsearch:8.15.0310b9fc03b06
log4j-api@2.19.0
2.25.5
1
library/elasticsearch:7.17.0332c6d416808
log4j-api@2.17.1
2.25.5
1
library/elasticsearch:7.17.1588c2ec10c7f2
log4j-api@2.17.1
2.25.5
1
library/elasticsearch:9.5.38d09295845fe
log4j-api@2.25.4
2.25.5
1
library/elasticsearch:9.5.19656a9ca03f8
log4j-api@2.25.4
2.25.5
1
library/elasticsearch:7.17.8fdc73b3249c1
log4j-api@2.17.1
2.25.5
1
library/flink:1.14.6-scala_2.122461f02672b3
log4j-api@2.17.1
2.25.5
1
library/logstash:7.17.817a4f64e9cf5
log4j-api@2.17.1
2.25.5
1
library/logstash:9.1.233eae14f0867
log4j-api@2.17.2
2.25.5
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
log4j-api@2.25.4
2.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.