GHSA-w35j-pv5h-q9q9 · Severity: medium · Ecosystem: maven — Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records. An attacker can exploit this issue only if both of the following conditions are met: * The application uses JsonTemplateLayout. * The application logs a MapMessage containing an attacker-controlled floating-point value. Users are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue.
Conclusion & alert: CVE-2026-34481 is rated Moderate Risk (40.3/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.56%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.06% | 0.56% | +0.50% |
| 2 | 2026-05-22 | 0.16% | 0.06% | -0.10% |
| 3 | 2026-04-16 | — | 0.16% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.3 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-w35j-pv5h-q9q9 · Severity: medium · Ecosystem: maven — Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2026-34481 unimportant priority: Debian including 2 source packages (apache-log4j1.2, apache-log4j2), 10 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5, resolved 5. | https://security-tracker.debian.org/tracker/CVE-2026-34481 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2026-34481 |
suse
|
medium | CVE-2026-34481 severity moderate: SUSE including 15 source package names (log4j, log4j-2.20.0-150200.4.33.1, …), 23 product×package rows across 8 product lines (SUSE Linux Enterprise Module for Basesystem 15 SP7, SUSE Linux Enterprise Server 12 SP4-LTSS, … (8 product lines)): Fixed 9, First Fixed 8, Known Not Affected 6. | https://www.suse.com/security/cve/CVE-2026-34481/ |
ubuntu
|
medium | CVE-2026-34481 medium priority: Ubuntu including 2 source packages (apache-log4j1.2, apache-log4j2), 15 status rows across 8 suites (bionic, focal, jammy, noble, questing, trusty, upstream, xenial): needs-triage 14, not-affected 1. | https://ubuntu.com/security/CVE-2026-34481 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | log4j | >= 2.14.0, < 2.25.4 | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* |
| apache | log4j | 3.0.0 | cpe:2.3:a:apache:log4j:3.0.0:alpha1:*:*:*:*:*:* |
| apache | log4j | 3.0.0 | cpe:2.3:a:apache:log4j:3.0.0:alpha1_rc1:*:*:*:*:*:* |
| apache | log4j | 3.0.0 | cpe:2.3:a:apache:log4j:3.0.0:alpha1_rc2:*:*:*:*:*:* |
| apache | log4j | 3.0.0 | cpe:2.3:a:apache:log4j:3.0.0:beta1:*:*:*:*:*:* |
| apache | log4j | 3.0.0 | cpe:2.3:a:apache:log4j:3.0.0:beta2:*:*:*:*:*:* |
| apache | log4j | 3.0.0 | cpe:2.3:a:apache:log4j:3.0.0:beta3:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/apache/logging-log4j2/pull/4080 | Issue Tracking |
| https://lists.apache.org/thread/n34zdv00gbkdbzt2rx9rf5mqz6lhopcv | Mailing List Vendor Advisory |
| https://logging.apache.org/cyclonedx/vdr.xml | Product |
| https://logging.apache.org/log4j/2.x/manual/json-template-layout.html | Technical Description |
| https://logging.apache.org/security.html#CVE-2026-34481 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/10/10 | Mailing List Third Party Advisory |