CVE-2026-34481P3HIGHCVSS 7.5≥ 2.13.1, < 2.25.5·≥ 2.26.0, < 2.26.1+1 more2026-04-10
CVE-2026-34481 [HIGH] CWE-116 CVE-2026-34481: Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to rejec
nvd