Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Apache Log4j

Apache Log4jбиблиотека журналирования (логирования) Java-программ

Релизный цикл, информация об уязвимостях

Продукт: Apache Log4j
Вендор: apache

График релизов

2.212.222.232.242.252.2620232024202520262027

Релизные элементы

KBВерсияБилдДата доступности

Показывать по

Недавние уязвимости Apache Log4j

Количество 144

github логотип

GHSA-qv9r-c865-cp47

2 месяца назад

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

EPSS: Низкий
nvd логотип

CVE-2026-49844

2 месяца назад

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attac

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-49844

2 месяца назад

Improper encoding of non-finite floating-point values during MapMessag ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2026-49844

2 месяца назад

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who...

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-49844

2 месяца назад

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker wh...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-w35j-pv5h-q9q9

5 месяцев назад

Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout

EPSS: Низкий
github логотип

GHSA-h383-gmxw-35v2

5 месяцев назад

Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters

EPSS: Низкий
github логотип

GHSA-6hg6-v5c8-fphq

5 месяцев назад

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

EPSS: Низкий
github логотип

GHSA-3pxv-7cmr-fjr4

5 месяцев назад

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

EPSS: Низкий
github логотип

GHSA-445c-vh5m-36rj

5 месяцев назад

Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-qv9r-c865-cp47

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-49844

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attac

CVSS3: 5.9
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-49844

Improper encoding of non-finite floating-point values during MapMessag ...

CVSS3: 5.9
1%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-49844

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who...

CVSS3: 5.9
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-49844

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker wh...

CVSS3: 5.9
1%
Низкий
2 месяца назад
github логотип
GHSA-w35j-pv5h-q9q9

Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout

1%
Низкий
5 месяцев назад
github логотип
GHSA-h383-gmxw-35v2

Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters

1%
Низкий
5 месяцев назад
github логотип
GHSA-6hg6-v5c8-fphq

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

0%
Низкий
5 месяцев назад
github логотип
GHSA-3pxv-7cmr-fjr4

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

1%
Низкий
5 месяцев назад
github логотип
GHSA-445c-vh5m-36rj

Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility

1%
Низкий
5 месяцев назад

Уязвимостей на страницу


Поделиться