GHSA-h383-gmxw-35v2
MODERATECVE-2026-34479The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.
- Affected
- >= 2.7, < 2.25.4
- Fixed in
- 2.25.4
- Weakness
- CWE-116
- Published
- 2026-04-10
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference