CVE-2026-34479
published 2026-04-10CVE-2026-34479: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.53%
41.5th percentile
The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records. Two groups of users are affected: * Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file. * Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class. Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue. Note: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | — | — |
| apache | log4j | >= 2.7 < 2.25.4 | 2.25.4 |
| apache_software_foundation | apache_log4j_1_to_log4j_2_bridge | >= 2.7 < 2.25.4 | 2.25.4 |
| apache_software_foundation | apache_log4j_1_to_log4j_2_bridge | 3.0.0-alpha1 – 3.0.0-beta2 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.logging.log4j/log4j-1.2-api: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping
vendor_redhat·2026-04-10·CVSS 6.9
CVE-2026-34479 [MEDIUM] CWE-91 org.apache.logging.log4j/log4j-1.2-api: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping
org.apache.logging.log4j/log4j-1.2-api: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping
A flaw was found in the Apache Log4j 1-to-Log4j 2 bridge. The Log4j1XmlLayout component fails to properly escape characters forbidden by the XML 1.0 standard. This improper handling of characters results in malformed XML output, which can cause downstream log processing systems to drop or fail to index affected records. The primary consequence is a denial of service for log analysis, potentially hindering security monitoring and incident response.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespr
VulDB
Apache Log4j 1 to Log4j 2 Bridge up to 2.25.3/3.0.0-beta2 Log4j1XmlLayout escape output (Nessus ID 306044)
vuldb·2026-04-13·CVSS 6.9
CVE-2026-34479 [MEDIUM] Apache Log4j 1 to Log4j 2 Bridge up to 2.25.3/3.0.0-beta2 Log4j1XmlLayout escape output (Nessus ID 306044)
A vulnerability was found in Apache Log4j 1 to Log4j 2 Bridge up to 2.25.3/3.0.0-beta2. It has been classified as problematic. This affects an unknown function of the component Log4j1XmlLayout. The manipulation leads to escaping of output.
This vulnerability is uniquely identified as CVE-2026-34479. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
GHSA-h383-gmxw-35v2: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1
ghsa_unreviewed·2026-04-10
CVE-2026-34479 [MEDIUM] CWE-116 GHSA-h383-gmxw-35v2: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1
The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.
Two groups of users are affected:
* Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file.
* Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class.
Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue.
Note: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. User
GHSA
Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
ghsa·2026-04-10
CVE-2026-34479 [MEDIUM] CWE-116 Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
The `Log4j1XmlLayout` from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.
Two groups of users are affected:
* Those using `Log4j1XmlLayout` directly in a Log4j Core 2 configuration file.
* Those using the Log4j 1 configuration compatibility layer with `org.apache.log4j.xml.XMLLayout` specified as the layout class.
Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version `2.25.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34479 log4j: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34479 [MEDIUM] CVE-2026-34479 log4j: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
CVE-2026-34479 log4j: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34479 flexmark-java: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34479 [MEDIUM] CVE-2026-34479 flexmark-java: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
CVE-2026-34479 flexmark-java: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Log4j is only used for the tests and in the flexmark-docx-converter module. We do not build the flexmark-docx-converter module in Fedora because we do not have the docx4j dependency. Inputs to log4j are strictly controlled by the tests and so are not vulnerable.
Bugzilla
CVE-2026-34479 apache-commons-logging: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34479 [MEDIUM] CVE-2026-34479 apache-commons-logging: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
CVE-2026-34479 apache-commons-logging: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34479 apache-commons-configuration: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
bugzilla·2026-04-13·CVSS 6.9
CVE-2026-34479 [MEDIUM] CVE-2026-34479 apache-commons-configuration: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
CVE-2026-34479 apache-commons-configuration: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
The log4j functionality is only used for the tests, which are not shipped in any binary RPM. It also doesn't use the log4j 1-to-log4j 2 bridge, so there is no way to trigger this vulnerability.
Bugzilla
CVE-2026-34479 org.apache.logging.log4j/log4j-1.2-api: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping
bugzilla·2026-04-10·CVSS 6.9
CVE-2026-34479 [MEDIUM] CVE-2026-34479 org.apache.logging.log4j/log4j-1.2-api: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping
CVE-2026-34479 org.apache.logging.log4j/log4j-1.2-api: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping
The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.
Two groups of users are affected:
* Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file.
* Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class.
Users are advised to upgrade to Apache Log4j 1-to-Log4
https://github.com/apache/logging-log4j2/pull/4078https://lists.apache.org/thread/gd0hp6mj17rn3kj279vgy4p7kd4zz5onhttps://logging.apache.org/cyclonedx/vdr.xmlhttps://logging.apache.org/log4j/2.x/migrate-from-log4j1.htmlhttps://logging.apache.org/security.html#CVE-2026-34479http://www.openwall.com/lists/oss-security/2026/04/10/8
2026-04-10
Published