PT-2026-31942 · Apache · Apache Log4J Core

·

CVE-2026-34480

·

Published

2026-02-16

·

Updated

2026-08-13

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Log4j Core versions up to and including 2.25.3
Description Apache Log4j Core's XmlLayout fails to sanitize characters forbidden by the XML 1.0 specification, resulting in invalid XML output when log messages or MDC values contain such characters. The impact varies depending on the StAX implementation used. With the JRE built-in StAX, forbidden characters are silently written, leading to malformed XML that may be rejected by parsers. With alternative StAX implementations like Woodstox, an exception is thrown, preventing the log event from being delivered to its intended appender.
Recommendations Upgrade to Apache Log4j Core 2.25.4 to correct this issue.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10856
CLEANSTART-2026-CG99434
CLEANSTART-2026-CQ01177
CLEANSTART-2026-OI70918
CLEANSTART-2026-RS65756
CLEANSTART-2026-SH44648
CVE-2026-34480
GHSA-3PXV-7CMR-FJR4
OPENSUSE-SU-2026:10544-1
SUSE-SU-2026:1843-1

Affected Products

Apache Log4J Core