CVE-2026-40023
published 2026-04-10CVE-2026-40023: Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.50%
39.2th percentile
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in log messages, NDC, and MDC property keys and values, producing invalid XML output. Conforming XML parsers must reject such documents with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.
An attacker who can influence logged data can exploit this to suppress individual log records, impairing audit trails and detection of malicious activity.
Users are advised to upgrade to Apache Log4cxx 1.7.0, which fixes this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4cxx | < 1.7.0 | 1.7.0 |
| apache_software_foundation | apache_log4cxx | < 1.7.0 | 1.7.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Log4cxx up to 1.6.x escape output (Nessus ID 306018)
vuldb·2026-04-11·CVSS 6.3
CVE-2026-40023 [MEDIUM] Apache Log4cxx up to 1.6.x escape output (Nessus ID 306018)
A vulnerability categorized as problematic has been discovered in Apache Log4cxx up to 1.6.x. Affected by this vulnerability is an unknown functionality. Such manipulation leads to escaping of output.
This vulnerability is referenced as CVE-2026-40023. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-q8qr-wp2r-738r: Apache Log4cxx's XMLLayout https://logging
ghsa_unreviewed·2026-04-10
CVE-2026-40023 [MEDIUM] CWE-116 GHSA-q8qr-wp2r-738r: Apache Log4cxx's XMLLayout https://logging
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in log messages, NDC, and MDC property keys and values, producing invalid XML output. Conforming XML parsers must reject such documents with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.
An attacker who can influence logged data can exploit this to suppress individual log records, impairing audit trails and detection of malicious activity.
Users are advised to upgrade to Apache Log4cxx 1.7.0, which fixes this issue.
Red Hat
Apache Log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters
vendor_redhat·2026-04-10·CVSS 6.3
CVE-2026-40023 [MEDIUM] CWE-117 Apache Log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters
Apache Log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters
A flaw was found in Apache Log4cxx. An attacker who can influence logged data can exploit this by injecting characters forbidden by the XML 1.0 specification (a standard for encoding documents) into log messages, Network Device Configuration (NDC), and Mapped Diagnostic Context (MDC) property keys and values. This results in invalid XML output, causing downstream log processing systems to drop or fail to index affected records. The primary impact is the impairment of audit trails and the detection of malicious activity, leading to a Denial of Service (DoS) for log processing.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Pr
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [epel-all]
bugzilla·2026-04-13·CVSS 6.3
CVE-2026-40023 [MEDIUM] CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [epel-all]
CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [fedora-all]
bugzilla·2026-04-13·CVSS 6.3
CVE-2026-40023 [MEDIUM] CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [fedora-all]
CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40023 Apache Log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters
bugzilla·2026-04-10·CVSS 6.3
CVE-2026-40023 [MEDIUM] CVE-2026-40023 Apache Log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters
CVE-2026-40023 Apache Log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in log messages, NDC, and MDC property keys and values, producing invalid XML output. Conforming XML parsers must reject such documents with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.
An attacker who can influence logged data can exploit this to suppress individual log records, impairing audit trails and detection of malicious activity.
Users are advised to upgrade to Apache Log4cxx 1
https://github.com/apache/logging-log4cxx/pull/609https://lists.apache.org/thread/y15cv3zblg3dfwr5vy6ddbnl4zyrzr8bhttps://logging.apache.org/cyclonedx/vdr.xmlhttps://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.htmlhttps://logging.apache.org/security.html#CVE-2026-40023http://www.openwall.com/lists/oss-security/2026/04/10/12
2026-04-10
Published