PT-2026-31942 · Apache · Apache Log4J Core

·

CVE-2026-34480

·

Published

2026-04-10

·

Updated

2026-06-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Log4j Core versions up to and including 2.25.3
Description Apache Log4j Core's XmlLayout fails to sanitize characters forbidden by the XML 1.0 specification, resulting in invalid XML output when log messages or MDC values contain such characters. The impact varies depending on the StAX implementation used. With the JRE built-in StAX, forbidden characters are silently written, leading to malformed XML that may be rejected by parsers. With alternative StAX implementations like Woodstox, an exception is thrown, preventing the log event from being delivered to its intended appender.
Recommendations Upgrade to Apache Log4j Core 2.25.4 to correct this issue.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34480
GHSA-3PXV-7CMR-FJR4
OPENSUSE-SU-2026:10544-1
SUSE-SU-2026:1843-1

Affected Products

Apache Log4J Core