PT-2026-31943 · Apache · Apache Log4J+1

Ap4Sh

·

Published

2026-04-10

·

Updated

2026-04-14

·

CVE-2026-34481

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Log4j versions up to and including 2.25.3
Description Apache Log4j's JsonTemplateLayout generates invalid JSON output when processing log events that include non-finite floating-point values (NaN, Infinity, or -Infinity), violating RFC 8259 standards. This can lead to downstream log processing systems rejecting or failing to index affected records. Exploitation requires the application to use JsonTemplateLayout and log a MapMessage containing a floating-point value controlled by an attacker.
Recommendations Upgrade to Apache Log4j JSON Template Layout 2.25.4.

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2026-34481
GHSA-W35J-PV5H-Q9Q9
OPENSUSE-SU-2026:10544-1

Affected Products

Apache Log4J
Jsontemplatelayout