PT-2026-31939 · Apache · Log4J Core

·

CVE-2026-34477

·

Published

2025-12-20

·

Updated

2026-07-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Apache Log4j Core versions 2.12.0 through 2.25.3
Description A flaw exists where hostname verification is ignored when configured through the verifyHostName attribute of the '' element. This occurs even if the attribute is explicitly set, leaving TLS connections susceptible to interception. A network-based attacker could perform a man-in-the-middle attack if an SMTP, Socket, or Syslog appender is used, TLS is configured via a nested '' element, and the attacker possesses a certificate issued by a CA trusted by the configured or default Java trust store.
Recommendations Upgrade to Apache Log4j Core 2.25.4.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10858
CLEANSTART-2026-CG99434
CLEANSTART-2026-CQ01177
CLEANSTART-2026-OI70918
CLEANSTART-2026-RS65756
CLEANSTART-2026-SH44648
CVE-2026-34477
GHSA-6HG6-V5C8-FPHQ
OPENSUSE-SU-2026:10544-1
SUSE-SU-2026:1843-1

Affected Products

Log4J Core