{"id":"GHSA-445c-vh5m-36rj","summary":"Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility","details":"Apache Log4j Core's [`Rfc5424Layout`](https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout), in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.\n\nTwo distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:\n\n  *  The `newLineEscape` attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output.\n  *  The `useTlsMessageFormat` attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping.\n\nUsers of the `SyslogAppender` are not affected, as its configuration attributes were not modified.\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.","aliases":["CVE-2026-34478"],"modified":"2026-07-17T21:12:48.184498351Z","published":"2026-04-10T18:31:17Z","database_specific":{"cwe_ids":["CWE-117","CWE-684"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-14T00:13:29Z","nvd_published_at":"2026-04-10T16:16:31Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34478"},{"type":"WEB","url":"https://github.com/apache/logging-log4j2/pull/4074"},{"type":"PACKAGE","url":"https://github.com/apache/logging-log4j2"},{"type":"WEB","url":"https://lists.apache.org/thread/3k1clr2l6vkdnl4cbhjrnt1nyjvb5gwt"},{"type":"WEB","url":"https://logging.apache.org/cyclonedx/vdr.xml"},{"type":"WEB","url":"https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout"},{"type":"WEB","url":"https://logging.apache.org/security.html#CVE-2026-34478"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/10/7"}],"affected":[{"package":{"name":"org.apache.logging.log4j:log4j-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.logging.log4j/log4j-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.21.0"},{"fixed":"2.25.4"}]}],"versions":["2.21.0","2.21.1","2.22.0","2.22.1","2.23.0","2.23.1","2.24.0","2.24.1","2.24.2","2.24.3","2.25.0","2.25.1","2.25.2","2.25.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-445c-vh5m-36rj/GHSA-445c-vh5m-36rj.json"}},{"package":{"name":"org.apache.logging.log4j:log4j-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.logging.log4j/log4j-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0-beta1"},{"last_affected":"3.0.0-beta3"}]}],"versions":["3.0.0-beta1","3.0.0-beta2","3.0.0-beta3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-445c-vh5m-36rj/GHSA-445c-vh5m-36rj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}