PT-2026-31983 · Apache · Apache Log4Cxx

Olawale Titiloye

·

Published

2026-04-10

·

Updated

2026-04-16

·

CVE-2026-40023

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Apache Log4cxx versions prior to 1.7.0
Description Apache Log4cxx's XMLLayout fails to sanitize characters forbidden by the XML 1.0 specification in log messages, NDC, and MDC property keys and values, resulting in invalid XML output. This can cause downstream log processing systems to drop or fail to index affected records. An attacker who can influence logged data can exploit this to suppress individual log records, potentially impairing audit trails and detection of malicious activity.
Recommendations Upgrade to Apache Log4cxx version 1.7.0.

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2026-40023
OPENSUSE-SU-2026:10566-1

Affected Products

Apache Log4Cxx