DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-p263-j2mw-mpj5

Package

sonarqube

Component

log4j-core

Latest update

Fixed

Fixed version

26.7.0.124771-r0

Aliases

  • CVE-2026-34477
  • GHSA-6hg6-v5c8-fphq

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-34477

Updates

Status

Fixed

Fixed version

26.7.0.124771-r0

Status

Unspecified

Status

Pending upstream fix

Impact

This vulnerability exists in log4j-core which is bundled/shaded inside two upstream-controlled artifacts in the Elasticsearch tarball: (1) log4j-core 2.19.0 inside elasticsearch-log4j-*.jar (Elasticsearch's repackaging of log4j with JndiLookup.class stripped); (2) log4j-core 2.25.0 shaded inside elastic-apm-agent-java8-1.55.0.jar. As pre-built binary artifacts, the embedded dependencies cannot be updated independently. This requires a new upstream release of Elasticsearch with updated bundled dependencies. Latest Elasticsearch v8.19.14 and v9.3.3 still pin log4j=2.19.0; apm-agent 1.55.x still ships log4j-core 2.25.0. Fix version: 2.25.4.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.