StackRadar

CVE-2026-49844

Medium

Advisory

Published 11 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
603
of 17,781 indexed, latest versions
Container images
570
deployed by those charts
Fix available
1 of 1
affected package

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Carried by container images the latest versions of 603 of 17,781 indexed charts deploy, on 570 images.

Affected packageAffected versionsFixed inImages
log4j-apimaven2.13.2, 2.13.3, 2.14.0, 2.14.1+24 more2.25.5, 2.26.1570
OSV records
GHSA-qv9r-c865-cp47

Charts affected

603 by stars
ChartLatestAffected imagesRadar Score
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
log4j-api@2.17.1
2.25.5

Open the chart page →

17,284
traccarjeffrescVerified publisher0.2.01 of 2See more

traccar jeffresc 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
traccar/traccar:6.7-alpine621c8d6d46fd
log4j-api@2.17.2
2.25.5

Open the chart page →

1,341
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
salehmir/jesse:1.10.101afa95f979e9
log4j-api@2.17.1
2.25.5

Open the chart page →

3,421
ipfix-generatorjfwenischVerified publisher0.3.16-feature-helm-package.01 of 1See more

ipfix-generator jfwenisch 0.3.16-feature-helm-package.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
log4j-api@2.24.3
2.25.5

Open the chart page →

697
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
log4j-api@2.17.2
2.25.5

Open the chart page →

2,067
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.01 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
log4j-api@2.20.0
2.25.5

Open the chart page →

14,130
kokukokuVerified publisher1.0.02 of 7See more

koku koku 1.0.0

2 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
log4j-api@2.17.1
2.25.5
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
log4j-api@2.24.3
2.25.5

Open the chart page →

12,019
auditflowlabs64io-helm-chartsVerified publisher0.12.11 of 3See more

auditflow labs64io-helm-charts 0.12.1

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
log4j-api@2.25.4
2.25.5

Open the chart page →

1,446
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.01 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
log4j-api@2.25.4
2.25.5

Open the chart page →

2,657
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
log4j-api@2.17.1
2.25.5

Open the chart page →

13,479
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
glarad/mc-service-registry:latest7b02b9e7f1ef
log4j-api@2.25.4
2.25.5

Open the chart page →

6,929
metabasemetabase-helmVerified publisher2.7.11 of 1See more

metabase metabase-helm 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
metabase/metabase:v0.46.09ebdc664a6b2
log4j-api@2.17.1
2.25.5

Open the chart page →

2,221
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
log4j-api@2.19.0
2.25.5

Open the chart page →

37,373
openccuopenccuVerified publisher3.89.81 of 1See more

openccu openccu 3.89.8

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
log4j-api@2.17.2
2.25.5

Open the chart page →

1,916
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
log4j-api@2.23.1
2.25.5

Open the chart page →

1,692
infinispanopenshift0.9.01 of 1See more

infinispan openshift 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/infinispan/server:16.282db6cbba3d9
log4j-api@2.26.0
2.26.1

Open the chart page →

41
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-kafka0601750a3ca4
log4j-api@2.25.4
2.25.5

Open the chart page →

22,420
todo-apipavanelthepu0.1.01 of 2See more

todo-api pavanelthepu 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
pavanelthepu/todo-api:1.0.2f47658e3b24c
log4j-api@2.14.1
2.25.5

Open the chart page →

2,544
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
log4j-api@2.17.2
2.25.5

Open the chart page →

7,576
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
log4j-api@2.17.1
2.25.5
treskon/portrait:DEV-latest88e813f22347
log4j-api@2.23.1
2.25.5

Open the chart page →

31,844
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
log4j-api@2.14.1
2.25.5

Open the chart page →

4,621
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
log4j-api@2.25.3
2.25.5

Open the chart page →

8,158
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
log4j-api@2.17.2
2.25.5

Open the chart page →

3,958
reportportalreportportal-ioOfficialVerified publisher26.8.123 of 15See more

reportportal reportportal-io 26.8.12

3 of the 15 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
reportportal/service-api:5.15.4bf193091525a
log4j-api@2.24.3
2.25.5
reportportal/service-authorization:5.15.16a954407b417
log4j-api@2.24.3
2.25.5
reportportal/service-jobs:5.15.299d27d58d6b4
log4j-api@2.21.1
2.25.5

Open the chart page →

11,869
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
log4j-api@2.17.2
2.25.5

Open the chart page →

6,639
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
log4j-api@2.24.3
2.25.5

Open the chart page →

7,432
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
log4j-api@2.17.2
2.25.5

Open the chart page →

9,837
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
log4j-api@2.14.1
2.25.5

Open the chart page →

10,120
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
log4j-api@2.17.1
2.25.5

Open the chart page →

6,045
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
log4j-api@2.17.1
2.25.5

Open the chart page →

7,529
sentinel-dashboardsentinel-dashboardVerified publisher0.1.01 of 1See more

sentinel-dashboard sentinel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
royalwang/sentinel-dashboard:1.8.4df99e2499f91
log4j-api@2.17.2
2.25.5

Open the chart page →

4,287
querysiakhooiVerified publisher1.0.01 of 1See more

query siakhooi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
siakhooi/query:1.0.0f1f4b5b1b870
log4j-api@2.25.3
2.25.5

Open the chart page →

1,792
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
log4j-api@2.23.1
2.25.5

Open the chart page →

2,406
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
log4j-api@2.24.3
2.25.5

Open the chart page →

1,482
stardogstardog3.1.01 of 3See more

stardog stardog 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
stardog/stardog:latest2714e5c4b3c1
log4j-api@2.25.4
2.25.5

Open the chart page →

293
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
log4j-api@2.17.2
2.25.5

Open the chart page →

13,486
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-api@2.16.0
2.25.5

Open the chart page →

24,930
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
log4j-api@2.24.3
2.25.5

Open the chart page →

2,826
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
log4j-api@2.20.0
2.25.5

Open the chart page →

7,835
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
log4j-api@2.20.0
2.25.5

Open the chart page →

2,168
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
log4j-api@2.20.0
2.25.5

Open the chart page →

2,326
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
log4j-api@2.20.0
2.25.5

Open the chart page →

2,853
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
log4j-api@2.17.1
2.25.5

Open the chart page →

7,713
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
log4j-api@2.20.0
2.25.5

Open the chart page →

2,221
quotes-provideraccount-serviceVerified publisher0.4.21 of 1See more

quotes-provider account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
log4j-api@2.20.0
2.25.5

Open the chart page →

2,205
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
log4j-api@2.25.2
2.25.5

Open the chart page →

3,188
migrationadeptia-automate-migration5.2.91 of 1See more

migration adeptia-automate-migration 5.2.9

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
log4j-api@2.25.3
2.25.5

Open the chart page →

395
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
log4j-api@2.23.1
2.25.5

Open the chart page →

854
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
log4j-api@2.17.2
2.25.5

Open the chart page →

1,413
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-49844.

Container imageDigestPackageFixed in
airbyte/server:2.2.070e125498a1c
log4j-api@2.25.2
2.25.5

Open the chart page →

12,473

Container images carrying it

570 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hazelcast/hazelcast:5.3.18fe26efde8e1
log4j-api@2.20.0
2.25.5
1
hazelcast/hazelcast:latestf086bf0ecb23
log4j-api@2.25.4
2.25.5
1
hazelcast/hazelcast-enterprise:5.7.1cf244da155eb
log4j-api@2.25.4
2.25.5
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
log4j-api@2.17.0
2.25.5
1
hazelcast/management-center:5.3.2f9d34300d330
log4j-api@2.17.2
2.25.5
1
hmediade/printserver:latest481a552c8e1c
log4j-api@2.17.2
2.25.5
1
housewrecker/gaps:latestf417dd0a7547
log4j-api@2.17.0
2.25.5
1
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
log4j-api@2.20.0
2.25.5
1
huertaslopez/i.huertas.2021-v.martinp.2021-planner:2.0.0e2c18bd65472
log4j-api@2.14.1
2.25.5
1
hugohg34/planner:0.0.2171f61e8d7e2
log4j-api@2.14.1
2.25.5
1
hugohg34/toposervice:0.0.2812a03b3f274
log4j-api@2.14.1
2.25.5
1
iamdorsah/bastillion:v0.1db83a0254d81
log4j-api@2.17.1
2.25.5
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
log4j-api@2.21.1
2.25.5
1
j4ckhunter/consumer:1.00bb7a429e3e75
log4j-api@2.17.2
2.25.5
1
j4ckhunter/producer:1.006ba447609b12
log4j-api@2.17.2
2.25.5
1
jacobalberty/unifi:v7.1.664a3616625dda
log4j-api@2.17.2
2.25.5
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
log4j-api@2.17.2
2.25.5
1
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
log4j-api@2.21.1
2.25.5
1
jhidalgo3/spring-echo-example:lateste08733191ea0
log4j-api@2.13.3
2.25.5
1
jhipster/jhipster-registry:latest7184525acd4d
log4j-api@2.17.2
2.25.5
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
log4j-api@2.17.2
2.25.5
1
just1not2/streama:1.10.48a2305192dec
log4j-api@2.17.1
2.25.5
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
log4j-api@2.20.0
2.25.5
1
keyfactor/signserver-ce:7.3.2798fbbe00283
log4j-api@2.23.1
2.25.5
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
log4j-api@2.25.4
2.25.5
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
log4j-api@2.13.3
2.25.5
1
krontechnology/aapm-service:1.1.39dd602db8baa
log4j-api@2.24.3
2.25.5
1
kubebb/gateway-api:v5.6.04d062f20309c
log4j-api@2.17.2
2.25.5
1
kubebb/mesh-api:v5.7.0a3879931dfa1
log4j-api@2.17.1
2.25.5
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
log4j-api@2.23.1
2.25.5
1
labs64/auditflowc7b26d3ca11c
log4j-api@2.25.4
2.25.5
1
labs64/payment-gateway:0.0.10c66feefca17
log4j-api@2.25.4
2.25.5
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
log4j-api@2.13.3
2.25.5
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
log4j-api@2.13.3
2.25.5
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
log4j-api@2.13.3
2.25.5
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
log4j-api@2.17.0
2.25.5
1
lavandadelpatio/tmdb:latestded9377636e9
log4j-api@2.20.0
2.25.5
1
lavandadelpatio/tmdb:0.0.2f36af885e915
log4j-api@2.13.3
2.25.5
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
log4j-api@2.19.0
2.25.5
1
library/convertigo:8.4.3ae605bfcda05
log4j-api@2.25.4
2.25.5
1
library/crate:4.7.0c7984a05e15b
log4j-api@2.17.1
2.25.5
1
library/elasticsearch:8.17.32cc40b15dff8
log4j-api@2.19.0
2.25.5
1
library/elasticsearch:8.15.0310b9fc03b06
log4j-api@2.19.0
2.25.5
1
library/elasticsearch:7.17.0332c6d416808
log4j-api@2.17.1
2.25.5
1
library/elasticsearch:7.17.1588c2ec10c7f2
log4j-api@2.17.1
2.25.5
1
library/elasticsearch:9.5.38d09295845fe
log4j-api@2.25.4
2.25.5
1
library/elasticsearch:9.5.19656a9ca03f8
log4j-api@2.25.4
2.25.5
1
library/elasticsearch:7.17.8fdc73b3249c1
log4j-api@2.17.1
2.25.5
1
library/flink:1.14.6-scala_2.122461f02672b3
log4j-api@2.17.1
2.25.5
1
library/logstash:7.17.817a4f64e9cf5
log4j-api@2.17.1
2.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.