VendorsApachelog4j3.0.0
Vulnerabilities

Apache Software Foundation 3.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-34478
Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
Published 2026-04-10 · Analyzed
7.5EPSS 0.012
CVE-2026-34480
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Published 2026-04-10 · Analyzed
7.5EPSS 0.012
CVE-2026-34479
Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
Published 2026-04-10 · Analyzed
7.5EPSS 0.009
CVE-2026-34481
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
Published 2026-04-10 · Modified
7.5EPSS 0.009
CVE-2026-49844
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Published 2026-07-10 · Analyzed
6.3EPSS 0.008
CVE-2026-34477
Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
Published 2026-04-10 · Analyzed
6.3EPSS 0.005