CVE-2026-34478: Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
Apache Log4j Core's Rfc5424Layout
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Log4j Core (Rfc5424Layout)to a version that resolves this vulnerability.Fixed in 2.25.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34478?
CVE-2026-34478 has been rated as a medium severity vulnerability due to the risk of log injection impacting the integrity of log files.
How do I fix CVE-2026-34478?
To fix CVE-2026-34478, upgrade to Apache Log4j Core version 2.25.4 or later, which addresses the log injection vulnerability.
What versions of Apache Log4j Core are affected by CVE-2026-34478?
CVE-2026-34478 affects Apache Log4j Core versions from 2.21.0 to 2.25.3.
What kind of attacks can be executed using CVE-2026-34478?
CVE-2026-34478 allows attackers to perform log injection attacks, leading to potential information disclosure or unauthorized command execution.
Is CVE-2026-34478 a concern for all users of Apache Log4j Core?
Yes, all users of Apache Log4j Core in the affected versions should be concerned and take immediate steps to mitigate the vulnerability.