Improper Encoding or Escaping of Output in Apache Log4j - CVE-2026-34480

 

Improper Encoding or Escaping of Output in Apache Log4j - CVE-2026-34480

Published: April 28, 2026


Vulnerability identifier: #VU128402
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34480
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause log event loss.

The vulnerability exists due to improper output neutralization in XmlLayout when processing log messages or MDC values containing XML 1.0 forbidden characters. A remote attacker can supply crafted input containing forbidden characters to cause log event loss.

The impact depends on the StAX implementation in use: built-in JRE StAX may produce malformed XML that downstream parsers reject, while alternative implementations may throw an exception during the logging call so the event is delivered only to Log4j's internal status logger.


Affected software

Apache Log4j
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
PowerVM NovaLink
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Integration Bus for z/OS
ApplinX
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Maximo Scheduler Optimizer
webMethods BPM
IBM Content Navigator
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Sterling External Authentication Server
IBM Sterling Connect:Direct Web Services
IBM Tivoli Netcool/OMNIbus WebGUI
Netcool/OMNIbus
IBM SPSS Collaboration and Deployment Services
IBM SPSS Modeler
IBM Operator for Apache Flink
IBM Decision Optimization for Cloud Pak for Data
IBM Qradar SIEM
IBM License Metric Tool
JBoss Data Grid
IBM DB2
IBM InfoSphere Information Server
IBM App Connect Enterprise
IBM Disconnected Log Collector
log4j-javadoc
log4j-jcl
log4j-slf4j
log4j

How to mitigate CVE-2026-34480

Install security update from vendor's website.

Apache Log4j - update to 2.25.4
PowerVM NovaLink - addressed in versions 2.2.1.1, 2.3.3
IBM Security Guardium Key Lifecycle Manager (GKLM) - addressed in versions 5.0.0 FP3, 5.1.0 FP2
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
IBM Qradar SIEM - update to 7.5.0 Update Pack 16
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.2.0
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.2.0
Netcool/OMNIbus - update to 8.1.0.37
IBM License Metric Tool - update to 9.2.44
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM App Connect Enterprise - addressed in versions 12.0.12.26, 13.0.7.2
IBM Operator for Apache Flink - update to 1.5.5
IBM Disconnected Log Collector - update to 2.0.1
log4j-javadoc - update to 2.20.0-150200.4.33.1
log4j-jcl - update to 2.20.0-150200.4.33.1
log4j-slf4j - update to 2.20.0-150200.4.33.1
log4j - update to 2.20.0-150200.4.33.1
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
watsonx Assistant Cartridge - update to 5.4
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4
JBoss Data Grid - update to 8.6.1
Maximo Scheduler Optimizer - addressed in versions 9.0.25, 9.1.14, 9.2.1
webMethods BPM - addressed in versions 10.15 Fix 2, 11.1 Fix 2, 12.1 Fix 1

External References

Related Security Bulletins