PT-2026-31940 · Apache · Log4J Core

Samuli Leinonen

·

Published

2025-12-25

·

Updated

2026-05-15

·

CVE-2026-34478

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Log4j Core versions 2.21.0 through 2.25.3
Description The Rfc5424Layout component is susceptible to log injection via CRLF (Carriage Return Line Feed) sequences. This occurs because security-relevant configuration attributes were renamed without documentation, affecting users of stream-based syslog services who configure Rfc5424Layout directly. Specifically, the renaming of the newLineEscape attribute disables newline escaping for TCP framing (RFC 6587), and the renaming of the useTlsMessageFormat attribute causes TLS framing (RFC 5425) to downgrade to unframed TCP (RFC 6587) without newline escaping. This can allow a remote attacker to impact the integrity of the protected log information.
Recommendations Upgrade to version 2.25.4.

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-05260
CVE-2026-34478
GHSA-445C-VH5M-36RJ

Affected Products

Log4J Core