CVE-2026-49844General(apache / log4j)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache log4j systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • log4j

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-07-11); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
log4j

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-07-11: 1Mentions · 2026-07-13: 1Mentions · 2026-07-16: 1Mentions · 2026-08-11: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-13: 107-1107-1307-1608-11
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-111
Disclosure1
2026-07-131
Patch1
2026-07-161
General1
2026-08-111
General1
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A new Apache Log4j flaw, CVE-2026-49844, makes log4j-api emit invalid JSON from non-finite numbers. Patch to 2.25.5 or 2.26.1 now. #Log4j #CVE202649844 #ApacheLog4j #Vulnerability #CyberSecurity http://securityonline.info/apache-log4j-cve-2026-49844/

    Post summary

    CVE-2026-49844 causes Apache Log4j‑api to emit malformed JSON for non‑finite numbers, and a fix is available in versions 2.25.5 and 2.26.1.

    11011561.2K
    12.9K followersView on X
  • arcserve Japan合同会社@Arcserve_jp
    General

    Arcserve Backup の新規サポート技術情報です🌟 Arcserve Backup 19 | Vulnerability | CVE-2026-34477, CVE-2026-34480, CVE-2025-68161, CVE-2026-34478, and CVE-2026-49844 https://support.arcserve.com/s/article/KB000011092?language=ja

    Post summary

    The post merely lists several Arcserve Backup CVEs and points to a support article, offering no additional details on exploitation, patches, or technical specifics.

    00020296
    7.9K followersView on X
  • Virus Myths!@virusmyths
    General

    [주의] log4j 신규 취약점(CVE-2026-49844) (출처 : Virus My.. | 블로그) https://m.blog.naver.com/nologout/224345708781

    Post summary

    The brief Korean announcement notes a new log4j vulnerability (CVE-2026-49844) but offers no additional details, PoC, exploitation evidence, or remediation information.

    0000039
    22 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-49844: Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson() https://www.openwall.com/lists/oss-security/2026/07/11/1 cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing

    Post summary

    The post announces CVE‑2026‑49844, detailing a Log4j serialization flaw that produces malformed JSON and may corrupt logs, with no PoC, exploit, active use, or patch information supplied.

    00000537
    4.7K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appapachelog4j---
Appapachelog4j2.26.0--
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--
Appapachelog4j3.0.0--

Explore more