Improper Encoding or Escaping of Output in Apache Log4j - CVE-2026-34479
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause downstream log processing systems to drop or fail to index affected records.
The vulnerability exists due to improper output neutralization in Log4j1XmlLayout when producing XML log output containing characters forbidden by the XML 1.0 standard. A remote attacker can cause such characters to be included in logged data to cause downstream log processing systems to drop or fail to index affected records.
The issue affects configurations using Log4j1XmlLayout directly in a Log4j Core 2 configuration file or through the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
PowerVM NovaLink
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Virtual Environments: Data Protection for VMware
Integration Bus for z/OS
ApplinX
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Maximo Scheduler Optimizer
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Sterling Connect:Direct Web Services
IBM Tivoli Netcool/OMNIbus WebGUI
IBM SPSS Collaboration and Deployment Services
IBM SPSS Modeler
IBM Decision Optimization for Cloud Pak for Data
IBM License Metric Tool
IBM DB2
IBM InfoSphere Information Server
IBM App Connect Enterprise
IBM Disconnected Log Collector
log4j-javadoc
log4j-jcl
log4j
log4j-slf4j
How to mitigate CVE-2026-34479
PowerVM NovaLink - addressed in versions 2.2.1.1, 2.3.3
IBM Security Guardium Key Lifecycle Manager (GKLM) - addressed in versions 5.0.0 FP3, 5.1.0 FP2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41
IBM License Metric Tool - update to 9.2.44
IBM DB2 - addressed in versions 11.5.9, 12.1.4
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM App Connect Enterprise - addressed in versions 12.0.12.26, 13.0.7.2
IBM Disconnected Log Collector - update to 2.0.1
log4j-javadoc - update to 2.20.0-150200.4.33.1
log4j-jcl - update to 2.20.0-150200.4.33.1
log4j - update to 2.20.0-150200.4.33.1
log4j-slf4j - update to 2.20.0-150200.4.33.1
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
watsonx Assistant Cartridge - update to 5.4
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4
Maximo Scheduler Optimizer - addressed in versions 9.0.25, 9.1.14, 9.2.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Log4j
- SUSE update for log4j
- Multiple vulnerabilities in IBM App Connect Enterprise and IBM Integration Bus for z/OS
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus_GUI
- Multiple vulnerabilities in IBM SPSS Modeler
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in IBM ApplinX
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge
- Multiple vulnerabilities in IBM License Metric Tool
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM PowerVM Novalink
- IBM Maximo Scheduler Optimizer update for Apache Log4j
- IBM Db2 update for Apache Log4j
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in IBM Guardium Key Lifecycle Manager
- Multiple vulnerabilities in IBM Storage Protect Data Protection for Virtual Environments
- Multiple vulnerabilities in SPSS Collaboration and Deployment Services