Executive brief
Apache Log4j Core, a widely used logging library for Java applications, contains a flaw that can allow attackers to inject malicious entries into system logs. This occurs because certain security settings were accidentally disabled during a software update, potentially allowing attackers to hide their activities or spoof log data. Organizations using specific syslog configurations should update to ensure their audit logs remain accurate and secure.
Technical details
Apache Log4j Core's Rfc5424Layout component is vulnerable to log injection via CRLF sequences. The vulnerability stems from the undocumented renaming of two configuration attributes: 'newLineEscape' and 'useTlsMessageFormat'. When users configure Rfc5424Layout directly, the 'newLineEscape' rename causes newline escaping to fail for TCP framing (RFC 6587), while the 'useTlsMessageFormat' rename causes a silent downgrade from TLS framing (RFC 5425) to unframed TCP without escaping. Attackers can exploit this via the network to inject arbitrary log entries. Users of SyslogAppender are unaffected. A fix is available in version 2.25.4.
Affected products
- Apache Log4j Core >= 2.21.0, < 2.25.4; >= 3.0.0-beta1, <= 3.0.0-beta3
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory
- 2026-04-10: patched: Fixed in version 2.25.4