PT-2026-31983 · Apache · Apache Log4Cxx
Olawale Titiloye
·
Published
2026-04-10
·
Updated
2026-04-16
·
CVE-2026-40023
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Log4cxx versions prior to 1.7.0
Description
Apache Log4cxx's XMLLayout fails to sanitize characters forbidden by the XML 1.0 specification in log messages, NDC, and MDC property keys and values, resulting in invalid XML output. This can cause downstream log processing systems to drop or fail to index affected records. An attacker who can influence logged data can exploit this to suppress individual log records, potentially impairing audit trails and detection of malicious activity.
Recommendations
Upgrade to Apache Log4cxx version 1.7.0.
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Log4Cxx