{"id":"SUSE-SU-2026:1843-1","summary":"Security update for log4j","details":"This update for log4j fixes the following issues:\n\n- CVE-2026-34477: TLS connections vulnerable to interception due to incomplete hostname verification configuration\n  checks (bsc#1262050).\n- CVE-2026-34479: silent log event loss due to improper XML escaping in `Log4j1XmlLayout` (bsc#1262091).\n- CVE-2026-34480: silent log event loss due to improper XML escaping in `XmlLayout` (bsc#1262092).\n- CVE-2026-34481: silent log event loss due to improper serialization of non-finite floating-point values in\n  `JsonTemplateLayout` (bsc#1262093).\n","modified":"2026-05-14T08:15:06.939131353Z","published":"2026-05-13T15:24:57Z","related":["CVE-2026-34477","CVE-2026-34479","CVE-2026-34480","CVE-2026-34481"],"upstream":["CVE-2026-34477","CVE-2026-34479","CVE-2026-34480","CVE-2026-34481"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261843-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262050"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262091"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262092"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262093"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34477"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34480"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34481"}],"schema_version":"1.7.5"}