Improper Encoding or Escaping of Output in Apache Log4j - CVE-2026-34481

 

Improper Encoding or Escaping of Output in Apache Log4j - CVE-2026-34481

Published: April 28, 2026


Vulnerability identifier: #VU128403
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34481
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause downstream log processing systems to reject or fail to index affected records.

The vulnerability exists due to improper serialization of non-finite floating-point values in JsonTemplateLayout when processing log events containing a MapMessage with an attacker-controlled floating-point value. A remote attacker can supply a non-finite floating-point value to cause downstream log processing systems to reject or fail to index affected records.

Exploitation is possible only if the application uses JsonTemplateLayout and logs a MapMessage containing the attacker-controlled value.


Affected software

Apache Log4j
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Netcool/OMNIbus
log4j-jcl
log4j-javadoc
log4j-slf4j
log4j
JBoss Data Grid

How to mitigate CVE-2026-34481

Install security update from vendor's website.

Apache Log4j - update to 2.25.4
Netcool/OMNIbus - update to 8.1.0.37
log4j-jcl - update to 2.20.0-150200.4.33.1
log4j-javadoc - update to 2.20.0-150200.4.33.1
log4j-slf4j - update to 2.20.0-150200.4.33.1
log4j - update to 2.20.0-150200.4.33.1
JBoss Data Grid - update to 8.6.1

External References

Related Security Bulletins