Log4j 2.25.4 Vulnerability in OpenSearch 3.8.0

Versions:

OpenSearch 3.8.0 & Log4j 2.25.4

Describe the issue:

OpenSearch 3.8.0 uses Log4j 2.25.4 which has a vulnerability, CVE-2026-49844.
Does CVE-2026-49844 impact OpenSearch?
Any plans to upgrade Log4j version? Or explore a log4j alternative to avoid the endless log4j vulnerability stream?

Configuration:

Relevant Logs or Screenshots:

ls /usr/share/opensearch/lib | grep log4j
log4j-api-2.25.4.jar
log4j-core-2.25.4.jar
log4j-jul-2.25.4.jar

Hi Scott, the OpenSearch project patches all dependencies with known vulnerabilities during the release cycle. The upgrade of this dependency was merged into the main branch of core (Update log4j to 2.25.5 by DarshitChanpura · Pull Request #22923 · opensearch-project/OpenSearch · GitHub) and will be released in 3.9.0. You can find the release calendar and patching policy on https://opensearch.org/releases/