Skip to main content

Vendor/product archive

apache / log4j CVEs

Beta · best-effort

20 CVEs tagged to apache / log4j6 Critical, 4 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2026-49844

Published Jul 10, 2026

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Lo…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-34481

Published Apr 10, 2026

Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output whe…

CVSS 6.3 · Medium
evidence mentions
7
Buzz score
38.8
Vendor/product tagsBeta · best-effort

CVE-2026-34480

Published Apr 10, 2026

Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden…

CVSS 6.9 · Medium
evidence mentions
7
Buzz score
38.8
Vendor/product tagsBeta · best-effort

CVE-2026-34479

Published Apr 10, 2026

The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers…

CVSS 6.9 · Medium
evidence mentions
7
Buzz score
43.3
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-34478

Published Apr 10, 2026

Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via C…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-34477

Published Apr 10, 2026

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerify…

CVSS 6.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2025-68161

Published Dec 18, 2025

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https:…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26464

Published Mar 10, 2023

** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1