CVE Explorer
CVE-2026-34481
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records.
An attacker can exploit this issue only if both of the following conditions are met:
* The application
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://repo.maven.apache.org/maven2","cpes":["cpe:2.3:a:apache:log4j_layout_template_json:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","packageName":"org.apache.logging.log4j:log4j-layout-template-json","packageURL":"pkg:maven/org.apache.logging.log4j/log4j-layout-template-json","product":"Apache Log4j JSON Template Layout","vendor":"Apache Software Foundation","versions":[{"lessThan":"2.25.4","status":"affected","version":"2.14.0","versionType":"maven"},{"lessThanOrEqual":"3.0.0-beta3","status":"affected","version":"3.0.0-alpha1","versionType":"maven"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d96a01edd2c9abd5d1dee2b3ed31009f24ec0e82acf3cf67b744afa98f9ce22f · sha256:0537611f9bebef5e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d96a01edd2c9abd5d1dee2b3ed31009f24ec0e82acf3cf67b744afa98f9ce22f · sha256:0537611f9bebef5e… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-116","description":"CWE-116 Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d96a01edd2c9abd5d1dee2b3ed31009f24ec0e82acf3cf67b744afa98f9ce22f · sha256:0537611f9bebef5e… · /containers/cna/problemTypes/0/descriptions/0
Source references
6 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/04/10/10"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d96a01edd2c9abd5d1dee2b3ed31009f24ec0e82acf3cf67b744afa98f9ce22f · sha256:0537611f9bebef5e… · /containers/adp/0/references/0
{"tags":["patch"],"url":"https://github.com/apache/logging-log4j2/pull/4080"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d96a01edd2c9abd5d1dee2b3ed31009f24ec0e82acf3cf67b744afa98f9ce22f · sha256:0537611f9bebef5e… · /containers/cna/references/0
{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/n34zdv00gbkdbzt2rx9rf5mqz6lhopcv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d96a01edd2c9abd5d1dee2b3ed31009f24ec0e82acf3cf67b744afa98f9ce22f · sha256:0537611f9bebef5e… · /containers/cna/references/4
{"tags":["vendor-advisory"],"url":"https://logging.apache.org/cyclonedx/vdr.xml"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d96a01edd2c9abd5d1dee2b3ed31009f24ec0e82acf3cf67b744afa98f9ce22f · sha256:0537611f9bebef5e… · /containers/cna/references/2
{"tags":["related"],"url":"https://logging.apache.org/log4j/2.x/manual/json-template-layout.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d96a01edd2c9abd5d1dee2b3ed31009f24ec0e82acf3cf67b744afa98f9ce22f · sha256:0537611f9bebef5e… · /containers/cna/references/3
{"tags":["vendor-advisory"],"url":"https://logging.apache.org/security.html#CVE-2026-34481"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d96a01edd2c9abd5d1dee2b3ed31009f24ec0e82acf3cf67b744afa98f9ce22f · sha256:0537611f9bebef5e… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.