Junglewise Threat Intelligence

CVE-2026-49844: Apache Log4j API improper JSON encoding of non-finite numbers

CVE-2026-49844 · Severity: medium · CVSS 4 · Published 2026-07-10

Vendors: Apache Software Foundation, Apache.

Executive brief

Apache Log4j API is a widely-used Java logging library. The vulnerability causes malformed JSON output when applications log special floating-point values (NaN, Infinity) through Log4j's JSON message formatting. An attacker who can control input values logged by the application could corrupt log records and disrupt downstream log analysis systems, affecting the reliability of security monitoring and audit trails.

Technical details

The vulnerability is an improper output encoding flaw (CWE-116) in the MapMessage.asJson() method. When a MapMessage contains a non-finite IEEE 754 value, the method emits bare JSON tokens (NaN, Infinity, -Infinity) which violate RFC 8259 and are rejected by conformant JSON parsers. The defect affects Log4j API versions 2.13.1–2.25.4 and 2.26.0. Exploitation requires two conditions: (1) the application uses JsonTemplateLayout's message resolver or another layout relying on MapMessage.asJson(), and (2) the application logs a MapMessage with an attacker-controlled floating-point value. The attack is network-reachable if the application logs untrusted input. Patches are available in versions 2.25.5 and 2.26.1, which emit RFC 8259-compliant JSON for non-finite values.

Affected products

  • Apache Log4j API 2.13.1 through 2.25.4, 2.26.0

Timeline

  • 2026-07-11: disclosed
  • 2026-07-10: advisory: NVD publication
  • 2026-07-11: patched: Versions 2.25.5 and 2.26.1 released

References