Improper Output Neutralization for Logs in Apache Log4j - CVE-2026-34478

 

Improper Output Neutralization for Logs in Apache Log4j - CVE-2026-34478

Published: April 28, 2026


Vulnerability identifier: #VU128400
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34478
CWE-ID: CWE-117
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary log entries.

The vulnerability exists due to improper neutralization of CRLF sequences in Rfc5424Layout when processing logged data with direct Rfc5424Layout configuration using TCP framing. A remote attacker can supply specially crafted input containing CRLF sequences to inject arbitrary log entries.

Only users of stream-based syslog services who configure Rfc5424Layout directly are affected. Users of the SyslogAppender are not affected.


Affected software

Apache Log4j
Db2 Developer Extension
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Integration Bus for z/OS
webMethods BPM
ApplinX
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Maximo Scheduler Optimizer
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Sterling Connect:Direct Web Services
Netcool/OMNIbus
IBM Tivoli Netcool/OMNIbus WebGUI
IBM SPSS Collaboration and Deployment Services
IBM Decision Optimization for Cloud Pak for Data
IBM License Metric Tool
JBoss Data Grid
IBM DB2
IBM InfoSphere Information Server
IBM App Connect Enterprise

How to mitigate CVE-2026-34478

Install security update from vendor's website.

Apache Log4j - update to 2.25.4
Db2 Developer Extension - update to 1.1.2
IBM Security Guardium Key Lifecycle Manager (GKLM) - addressed in versions 5.0.0 FP3, 5.1.0 FP2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
Netcool/OMNIbus - update to 8.1.0.37
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41
IBM License Metric Tool - update to 9.2.44
webMethods BPM - addressed in versions 10.15 Fix 2, 11.1 Fix 2, 12.1 Fix 1
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM App Connect Enterprise - addressed in versions 12.0.12.26, 13.0.7.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
watsonx Assistant Cartridge - update to 5.4
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4
JBoss Data Grid - update to 8.6.1
Maximo Scheduler Optimizer - addressed in versions 9.0.25, 9.1.14, 9.2.1

External References

Related Security Bulletins