CVE-2026-34481

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
10/04/2026
Last modified:
24/04/2026

Description

Apache Log4j&amp;#39;s JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records.<br /> <br /> An attacker can exploit this issue only if both of the following conditions are met:<br /> <br /> * The application uses JsonTemplateLayout.<br /> * The application logs a MapMessage containing an attacker-controlled floating-point value.<br /> <br /> <br /> Users are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* 2.14.0 (including) 2.25.4 (excluding)
cpe:2.3:a:apache:log4j:3.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:apache:log4j:3.0.0:alpha1_rc1:*:*:*:*:*:*
cpe:2.3:a:apache:log4j:3.0.0:alpha1_rc2:*:*:*:*:*:*
cpe:2.3:a:apache:log4j:3.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:apache:log4j:3.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:apache:log4j:3.0.0:beta3:*:*:*:*:*:*