PT-2026-31943 · Apache · Apache Log4J+1

·

CVE-2026-34481

·

Published

2026-04-10

·

Updated

2026-07-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Log4j versions up to and including 2.25.3
Description Apache Log4j's JsonTemplateLayout generates invalid JSON output when processing log events that include non-finite floating-point values (NaN, Infinity, or -Infinity), violating RFC 8259 standards. This can lead to downstream log processing systems rejecting or failing to index affected records. Exploitation requires the application to use JsonTemplateLayout and log a MapMessage containing a floating-point value controlled by an attacker.
Recommendations Upgrade to Apache Log4j JSON Template Layout 2.25.4.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-CG99434
CVE-2026-34481
GHSA-W35J-PV5H-Q9Q9
OESA-2026-3153
OPENSUSE-SU-2026:10544-1
SUSE-SU-2026:1843-1

Affected Products

Apache Log4J
Jsontemplatelayout