CVE-2026-34478
published 2026-04-10CVE-2026-34478: Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.83%
53.5th percentile
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes. Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly: * The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output. * The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping. Users of the SyslogAppender are not affected, as its configuration attributes were not modified. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | — | — |
| apache | log4j | >= 2.21.0 < 2.25.4 | 2.25.4 |
| apache_software_foundation | apache_log4j_core | >= 2.21.0 < 2.25.4 | 2.25.4 |
| apache_software_foundation | apache_log4j_core | 3.0.0-beta1 – 3.0.0-beta3 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Log4j Core up to 2.25.3/3.0.0-beta3 Configuration incorrect provision of specified functionality (Nessus ID 306185 / WID-SEC-2026-1067)
vuldb·2026-06-24·CVSS 7.5
CVE-2026-34478 [HIGH] Apache Log4j Core up to 2.25.3/3.0.0-beta3 Configuration incorrect provision of specified functionality (Nessus ID 306185 / WID-SEC-2026-1067)
A vulnerability labeled as problematic has been found in Apache Log4j Core up to 2.25.3/3.0.0-beta3. This affects an unknown part of the component Configuration Handler. Executing a manipulation can lead to incorrect provision of specified functionality.
This vulnerability is tracked as CVE-2026-34478. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
GHSA
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
ghsa·2026-04-10
CVE-2026-34478 [MEDIUM] CWE-117 Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
Apache Log4j Core's [`Rfc5424Layout`](https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout), in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.
Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:
* The `newLineEscape` attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output.
* The `useTlsMessageFormat` attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6
GHSA
GHSA-445c-vh5m-36rj: Apache Log4j Core's Rfc5424Layout https://logging
ghsa_unreviewed·2026-04-10
CVE-2026-34478 [MEDIUM] CWE-117 GHSA-445c-vh5m-36rj: Apache Log4j Core's Rfc5424Layout https://logging
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.
Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:
* The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output.
* The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping.
Users of the SyslogAppender are not affected, as its configuration attr
Red Hat
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
vendor_redhat·2026-04-10·CVSS 6.9
CVE-2026-34478 [MEDIUM] CWE-93 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
A flaw was found in Apache Log4j Core. This vulnerability allows for log injection through the use of Carriage Return Line Feed (CRLF) sequences. This occurs because security-related configuration attributes were silently renamed, impacting users who directly configure Rfc5424Layout with stream-based syslog services. An attacker could exploit this to inject malicious data into log files, potentially obscuring critical security events or manipulating system records.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34478 apache-commons-configuration: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34478 [MEDIUM] CVE-2026-34478 apache-commons-configuration: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
CVE-2026-34478 apache-commons-configuration: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
The log4j functionality is only used for the tests, which are not shipped in any binary RPM. The inputs to log4j are strictly controlled by the tests, so this vulnerability cannot be triggered.
Bugzilla
CVE-2026-34478 flexmark-java: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34478 [MEDIUM] CVE-2026-34478 flexmark-java: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
CVE-2026-34478 flexmark-java: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Log4j is only used for the tests and in the flexmark-docx-converter module. We do not build the flexmark-docx-converter module in Fedora because we do not have the docx4j dependency. Inputs to log4j are strictly controlled by the tests and so are not vulnerable.
Bugzilla
CVE-2026-34478 ceph: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34478 [MEDIUM] CVE-2026-34478 ceph: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
CVE-2026-34478 ceph: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34478 log4j: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34478 [MEDIUM] CVE-2026-34478 log4j: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
CVE-2026-34478 log4j: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34478 resteasy: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34478 [MEDIUM] CVE-2026-34478 resteasy: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
CVE-2026-34478 resteasy: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34478 cldr-emoji-annotation: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34478 [MEDIUM] CVE-2026-34478 cldr-emoji-annotation: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
CVE-2026-34478 cldr-emoji-annotation: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34478 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
bugzilla·2026-04-10·CVSS 6.9
CVE-2026-34478 [MEDIUM] CVE-2026-34478 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
CVE-2026-34478 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.
Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:
* The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output.
* The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be sil
https://github.com/apache/logging-log4j2/pull/4074https://lists.apache.org/thread/3k1clr2l6vkdnl4cbhjrnt1nyjvb5gwthttps://logging.apache.org/cyclonedx/vdr.xmlhttps://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layouthttps://logging.apache.org/security.html#CVE-2026-34478http://www.openwall.com/lists/oss-security/2026/04/10/7
2026-04-10
Published