An attacker can exploit this issue only if both of the following conditions are met:
* The application uses JsonTemplateLayout.
* The application logs a MapMessage containing an attacker-controlled floating-point value.
Users are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w35j-pv5h-q9q9 | Apache Log4j's JsonTemplateLayout produces invalid JSON output when log events contain non-finite floating-point values |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 10 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 10 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records. An attacker can exploit this issue only if both of the following conditions are met: * The application uses JsonTemplateLayout. * The application logs a MapMessage containing an attacker-controlled floating-point value. Users are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue. | |
| Title | Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout | |
| First Time appeared |
Apache
Apache log4j Layout Template Json |
|
| Weaknesses | CWE-116 | |
| CPEs | cpe:2.3:a:apache:log4j_layout_template_json:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache log4j Layout Template Json |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-10T17:41:38.229Z
Reserved: 2026-03-28T19:23:37.127Z
Link: CVE-2026-34481
Updated: 2026-04-10T16:18:20.891Z
Status : Received
Published: 2026-04-10T16:16:31.663
Modified: 2026-04-10T17:17:02.747
Link: CVE-2026-34481
No data.
OpenCVE Enrichment
No data.
Github GHSA