Improper Encoding or Escaping of Output in Apache Log4j - CVE-2026-34481
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause downstream log processing systems to reject or fail to index affected records.
The vulnerability exists due to improper serialization of non-finite floating-point values in JsonTemplateLayout when processing log events containing a MapMessage with an attacker-controlled floating-point value. A remote attacker can supply a non-finite floating-point value to cause downstream log processing systems to reject or fail to index affected records.
Exploitation is possible only if the application uses JsonTemplateLayout and logs a MapMessage containing the attacker-controlled value.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Netcool/OMNIbus
log4j-jcl
log4j-javadoc
log4j-slf4j
log4j
JBoss Data Grid
How to mitigate CVE-2026-34481
Netcool/OMNIbus - update to 8.1.0.37
log4j-jcl - update to 2.20.0-150200.4.33.1
log4j-javadoc - update to 2.20.0-150200.4.33.1
log4j-slf4j - update to 2.20.0-150200.4.33.1
log4j - update to 2.20.0-150200.4.33.1
JBoss Data Grid - update to 8.6.1