CVE-2026-34480Disclosure(apache / log4j)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • log4j

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
log4j

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-11: 1Mentions · 2026-08-11: 1Technical Details · 2026-04-11: 104-1108-11
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-111
Disclosure1
2026-08-111
General1
Full discourse2 posts
  • arcserve Japan合同会社@Arcserve_jp
    General

    Arcserve Backup の新規サポート技術情報です🌟 Arcserve Backup 19 | Vulnerability | CVE-2026-34477, CVE-2026-34480, CVE-2025-68161, CVE-2026-34478, and CVE-2026-49844 https://support.arcserve.com/s/article/KB000011092?language=ja

    Post summary

    The post is a brief announcement of multiple CVEs for Arcserve Backup 19, with no further technical or patch details provided.

    00020296
    7.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34480 Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characte… https://www.cve.org/CVERecord?id=CVE-2026-34480

    Post summary

    The post discloses that Log4j Core's XmlLayout up to version 2.25.3 does not properly sanitize characters, indicating a potential vulnerability. No PoC, exploit, patch, or active exploitation details are mentioned.

    00010137
    57.1K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appapachelog4j---
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--

Explore more