Junglewise Threat Intelligence

CVE-2026-34480: Apache Log4j Core invalid XML output in XmlLayout

CVE-2026-34480 · Severity: high · CVSS 7.5 · Published 2026-04-10

Technologies: Google Cloud Platform, Apache Software Foundation Log4j Core. Vendors: Apache, Google, Apache Software Foundation.

Executive brief

Apache Log4j Core, a widely used logging library for Java applications, contains a flaw in how it handles certain characters when generating XML logs. If a log message contains specific forbidden characters, it can cause log data to be silently lost or rejected by downstream monitoring systems. This could lead to gaps in audit trails or operational visibility, potentially hiding malicious activity or system errors.

Technical details

The vulnerability exists in the XmlLayout component of Apache Log4j Core due to improper encoding of XML 1.0 forbidden characters (CWE-116). When log messages or Mapped Diagnostic Context (MDC) values contain these characters, the resulting XML is malformed. Depending on the StAX implementation used, this either results in downstream parsers rejecting the log file as a fatal error (JRE built-in StAX) or an exception being thrown during the logging call itself, preventing the event from reaching its appender (Alternative StAX like Woodstox). This is reachable via any network-facing application that logs attacker-controlled input using XmlLayout. The issue is fixed in version 2.25.4.

Affected products

  • Apache Log4j Core >= 2.0-alpha1, < 2.25.4; >= 3.0.0-alpha1, <= 3.0.0-beta3

Timeline

  • 2026-04-10: disclosed
  • 2026-04-10: advisory
  • 2026-04-10: patched: Fixed in version 2.25.4

References

Related threats