Package
elasticsearch-8.19-iamguarded
Component
log4j-api
Latest update
Fixed version
8.19.20-r2
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
8.19.20-r2Status
Impact
CVE-2026-49844 (GHSA-qv9r-c865-cp47, MODERATE): Apache Log4j API improperly encodes non-finite floating-point values during MapMessage JSON serialization. It affects org.apache.logging.log4j:log4j-api in the ranges >=2.13.1,<2.25.5 (fixed in 2.25.5) and >=2.26.0,<2.26.1 (fixed in 2.26.1).
Elasticsearch's own logging dependency ships a fixed log4j-api (2.26.1) and is not affected. The remaining detection is a separate copy of log4j-api 2.25.4 bundled inside the prebuilt Elastic APM Java agent (elastic-apm-agent-java8) that Elasticsearch ships in its apm module. Because this log4j-api is shaded inside a third-party agent JAR distributed as a prebuilt binary, it cannot be remediated by rebuilding Elasticsearch or by changing Elasticsearch's own dependency versions.
Remediation depends on an upstream release of the Elastic APM Java agent that bundles a patched log4j-api (>=2.25.5), adopted by a subsequent Elasticsearch release. Pending that upstream fix.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-49844 ; https://github.com/advisories/GHSA-qv9r-c865-cp47 ; https://logging.apache.org/log4j/2.x/security.html
Batch: 2026-08-27-A
Status