DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-xc8q-3757-9675

Package

sonarqube

Component

log4j-core

Latest update

Fixed

Fixed version

26.7.0.124771-r0

Aliases

  • CVE-2026-34480
  • GHSA-3pxv-7cmr-fjr4

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-34480

Updates

Status

Fixed

Fixed version

26.7.0.124771-r0

Status

Unspecified

Status

Pending upstream fix

Impact

This vulnerability exists in log4j-core which is bundled/shaded inside two upstream-controlled artifacts in the Elasticsearch tarball: (1) log4j-core 2.19.0 inside elasticsearch-log4j-*.jar (Elasticsearch's repackaging of log4j with JndiLookup.class stripped per Log4Shell mitigation, see https://github.com/elastic/elasticsearch/blob/v8.19.14/libs/log4j/build.gradle); (2) log4j-core 2.25.0 shaded inside elastic-apm-agent-java8-1.55.0.jar. As pre-built binary artifacts, the embedded dependencies cannot be updated independently. This requires a new upstream release of Elasticsearch with updated bundled dependencies. Latest Elasticsearch v8.19.14 and v9.3.3 still pin log4j=2.19.0 in build-tools-internal/version.properties; the apm-agent 1.55.x line (latest v1.55.6) ships log4j-core 2.25.0 shaded. Fix version: 2.25.4.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.