{"id":"GHSA-h383-gmxw-35v2","summary":"Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters","details":"The `Log4j1XmlLayout` from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.\n\nTwo groups of users are affected:\n\n* Those using `Log4j1XmlLayout` directly in a Log4j Core 2 configuration file.\n* Those using the Log4j 1 configuration compatibility layer with `org.apache.log4j.xml.XMLLayout` specified as the layout class.\n\nUsers are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version `2.25.4`, which corrects this issue.\n\n\u003e [!NOTE]\n\u003e The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the\n\u003e [Log4j 1 to Log4j 2 migration guide](https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html), and specifically the section on eliminating reliance on the bridge.","aliases":["CVE-2026-34479"],"modified":"2026-07-17T21:09:29.827297584Z","published":"2026-04-10T18:31:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-04-14T00:10:59Z","nvd_published_at":"2026-04-10T16:16:31Z","cwe_ids":["CWE-116"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34479"},{"type":"WEB","url":"https://github.com/apache/logging-log4j2/pull/4078"},{"type":"PACKAGE","url":"https://github.com/apache/logging-log4j2"},{"type":"WEB","url":"https://lists.apache.org/thread/gd0hp6mj17rn3kj279vgy4p7kd4zz5on"},{"type":"WEB","url":"https://logging.apache.org/cyclonedx/vdr.xml"},{"type":"WEB","url":"https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html"},{"type":"WEB","url":"https://logging.apache.org/security.html#CVE-2026-34479"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/10/8"}],"affected":[{"package":{"name":"org.apache.logging.log4j:log4j-1.2-api","ecosystem":"Maven","purl":"pkg:maven/org.apache.logging.log4j/log4j-1.2-api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7"},{"fixed":"2.25.4"}]}],"versions":["2.10.0","2.11.0","2.11.1","2.11.2","2.12.0","2.12.1","2.12.2","2.12.3","2.12.4","2.13.0","2.13.1","2.13.2","2.13.3","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0","2.17.1","2.17.2","2.18.0","2.19.0","2.20.0","2.21.0","2.21.1","2.22.0","2.22.1","2.23.0","2.23.1","2.24.0","2.24.1","2.24.2","2.24.3","2.25.0","2.25.1","2.25.2","2.25.3","2.7","2.8","2.8.1","2.8.2","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-h383-gmxw-35v2/GHSA-h383-gmxw-35v2.json"}},{"package":{"name":"org.apache.logging.log4j:log4j-1.2-api","ecosystem":"Maven","purl":"pkg:maven/org.apache.logging.log4j/log4j-1.2-api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0-beta1"},{"last_affected":"3.0.0-beta2"}]}],"versions":["3.0.0-beta1","3.0.0-beta2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-h383-gmxw-35v2/GHSA-h383-gmxw-35v2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}