๐Ÿ” CVE Alert

CVE-2026-34480

UNKNOWN 0.0

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.

CWE CWE-116
Vendor apache software foundation
Product apache log4j core
Published Apr 10, 2026
Last Updated Apr 10, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache log4j core

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache log4j core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Log4j Core
2.0-alpha1 < 2.25.4 3.0.0-alpha1 โ‰ค 3.0.0-beta3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/logging-log4j2/pull/4077 logging.apache.org: https://logging.apache.org/security.html#CVE-2026-34480 logging.apache.org: https://logging.apache.org/cyclonedx/vdr.xml logging.apache.org: https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout lists.apache.org: https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb openwall.com: http://www.openwall.com/lists/oss-security/2026/04/10/9

Credits

Ap4sh (Samy Medjahed) and Ethicxz (Eliott Laurie) (original reporters) jabaltarik1 (independently)