Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2449 articles · 160578 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-34479EXPLOITEDPATCHED
apache · log4j

Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters

Description

The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records. Two groups of users are affected: * Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file. * Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class. Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue. Note: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.

Affected Products

VendorProductVersions
apachelog4jmaven/org.apache.logging.log4j:log4j-1.2-api: >= 2.7, < 2.25.4, maven/org.apache.logging.log4j:log4j-1.2-api: >= 3.0.0-beta1, <= 3.0.0-beta2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachelog4jcert_advisory90%
mavenorg.apache.logging.log4j:log4j-1.2-apiGHSA85%

References

  • https://github.com/apache/logging-log4j2/pull/4078(patch)
  • https://logging.apache.org/security.html#CVE-2026-34479(vendor-advisory)
  • https://logging.apache.org/cyclonedx/vdr.xml(vendor-advisory)
  • https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html(related)
  • https://lists.apache.org/thread/gd0hp6mj17rn3kj279vgy4p7kd4zz5on(vendor-advisory)

Related News (6 articles)

Tier B
CERT-FR1d ago
Multiples vulnérabilités dans les produits IBM (05 juin 2026)
→ No new info (linked only)
Tier A
Microsoft MSRC51d ago
CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
→ No new info (linked only)
Tier B
BSI Advisories53d ago
[NEU] [mittel] Apache log4j: Mehrere Schwachstellen ermöglichen Manipulation von Dateien
→ No new info (linked only)
Tier C
VulDB56d ago
CVE-2026-34479 | Apache Log4j 1 to Log4j 2 Bridge up to 2.25.3/3.0.0-beta2 Log4j1XmlLayout escape output
→ No new info (linked only)
Tier C
oss-security56d ago
CVE-2026-34479: Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
→ No new info (linked only)
Tier B
BSI Advisories59d ago
[UPDATE] [niedrig] Apache log4j: Schwachstelle ermöglicht Offenlegung von Informationen
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.apache.logging.log4j:log4j-1.2-api@2.25.4
CWECWE-116
PublishedApr 10, 2026
Last enriched56d agov3
Tags
information disclosureremote exploit
Trending Score65
Source articles6
Independent5
Info Completeness9/14
Missing: cvss, epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-34197EXPKEV
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Trending: 150
MEDIUMCVE-2026-34480EXP
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Trending: 65
CRITICALCVE-2026-50076EXP
Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass
Trending: 63
MEDIUMCVE-2026-34477EXP
Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
Trending: 57
MEDIUMCVE-2026-34478
Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
Trending: 47

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 10, 2026
Discovered by ZDM
Apr 10, 2026
Updated: affectedVersions, severity
Apr 10, 2026
Updated: affectedVersions, severity, exploitAvailable, activelyExploited
Apr 10, 2026
Actively Exploited
Apr 10, 2026
Exploit Available
Apr 10, 2026
Patch Available
Apr 10, 2026

Version History

v3
Last enriched 56d ago
v3Tier C56d ago

Updated affected versions, changed severity to MEDIUM, and marked the vulnerability as actively exploited with an available exploit.

affectedVersionsseverityexploitAvailableactivelyExploited
via oss-security
v2Tier C56d ago

Updated affected versions to include 2.25.3 and 3.0.0-beta2, changed severity to HIGH, and noted that no exploit exists.

affectedVersionsseverity
via VulDB
v156d ago

Initial creation