CVE detail
CVE-2026-34478
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes. Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly: * The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output. * The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping. Users of the SyslogAppender are not affected, as its configuration attributes were not modified. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- http://www.openwall.com/lists/oss-security/2026/04/10/7www.openwall.com
No excerpt available.
Exploitwww.openwall.comApr 10, 2026, 4:16 PM - https://logging.apache.org/security.html#CVE-2026-34478logging.apache.org
No excerpt available.
Vendor Advisorylogging.apache.orgApr 10, 2026, 4:16 PM - https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layoutlogging.apache.org
No excerpt available.
Vendor Advisorylogging.apache.orgApr 10, 2026, 4:16 PM - https://logging.apache.org/cyclonedx/vdr.xmllogging.apache.org
No excerpt available.
Vendor Advisorylogging.apache.orgApr 10, 2026, 4:16 PM - https://lists.apache.org/thread/3k1clr2l6vkdnl4cbhjrnt1nyjvb5gwtlists.apache.org
No excerpt available.
Vendor Advisorylists.apache.orgApr 10, 2026, 4:16 PM No excerpt available.
Exploitgithub.comApr 10, 2026, 4:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-62948CVSS 9.6 · Critical
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefi…
- CVE-2026-12616CVSS 6.9 · Medium
The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled, then interpolates that string into three log statements be…
- CVE-2026-10745CVSS 7.9 · High
Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampering-Forging. This issue affect…
- CVE-2026-20260CVSS 4.3 · Medium
In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escap…
- CVE-2026-45565CVSS 8.1 · High
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is t…
- CVE-2026-9016CVSS 5.3 · Medium
The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and including,…