Executive brief
A vulnerability in the Apache Log4j 1-to-Log4j 2 bridge component can cause critical log data to be lost. When certain characters are included in log messages, the system generates invalid XML that downstream monitoring and security tools may fail to process or index. This can lead to gaps in audit trails and operational visibility, potentially hiding malicious activity or system errors.
Technical details
The Log4j1XmlLayout (and the Log4j 1 compatibility layer XMLLayout) fails to properly escape characters forbidden by the XML 1.0 standard. When these characters are present in log events, the component produces malformed XML. Because conforming XML parsers are required to treat such characters as fatal errors, downstream log aggregators, indexers, or SIEMs may reject the entire log document, leading to silent log event loss. This is classified as an improper encoding/escaping issue (CWE-116). The vulnerability is resolved in version 2.25.4.
Affected products
- Apache Log4j 1-to-Log4j 2 bridge (log4j-1.2-api) >= 2.7, < 2.25.4; >= 3.0.0-beta1, <= 3.0.0-beta2
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory
- 2026-04-10: patched