CVE-2026-34480
Last modified
CVE-2026-34480 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Log4j | >= 2.0, < 2.25.4 | — |
| Apache | Log4j | 3.0.0 | Alpha1 |
References
- https://github.com/apache/logging-log4j2/pull/4077Issue Tracking, Patch
- https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhbMailing List, Vendor Advisory
- https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayoutTechnical Description
- https://logging.apache.org/security.html#CVE-2026-34480Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/04/10/9Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-34480?
How severe is CVE-2026-34480?
How do I fix CVE-2026-34480?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34474Sensitive data exposure leading to admin/WLAN credential lea…7.5
- CVE-2026-34475Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0…9.8
- CVE-2026-34476Server-Side Request Forgery via SW-URL Header vulnerability …7.1
- CVE-2026-34477The fix for CVE-2025-68161 https://logging.apache.org/secur…5.9
- CVE-2026-34478Apache Log4j Core's Rfc5424Layout https://logging.apache.or…7.5
- CVE-2026-34479The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridg…7.5
- CVE-2026-34481Apache Log4j's JsonTemplateLayout https://logging.apache.or…7.5
- CVE-2026-34483Improper Encoding or Escaping of Output vulnerability in the…7.5
- CVE-2026-34486Missing Encryption of Sensitive Data vulnerability in Apache…7.5
- CVE-2026-34487Insertion of Sensitive Information into Log File vulnerabili…7.5
- CVE-2026-34488IP Setting Software contains an issue with the DLL search pa…7.3
- CVE-2026-3449Versions of the package @tootallnate/once before 3.0.1 are v…3.3
Are you affected by CVE-2026-34480?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
