CVE-2025-54813 is an Improper Output Neutralization for Logs vulnerability in Apache Log4cxx versions prior to 1.5.0. When using JSONLayout, certain non-printable characters in attacker-supplied messages are not properly escaped, potentially preventing log-consuming applications from correctly interpreting the JSON output. This vulnerability has a CVSS score of 7.5 (High), indicating a high impact on integrity with low attack complexity and no user interaction required. There is currently no public exploit code available, nor is it listed on the CISA KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.0CPE matchmatch criteria | cpe:2.3:a:apache:log4cxx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.