OVERVIEW CVE-2026-34478 affects Apache Log4j Core versions 2.21.0 through 2.25.3 and involves critical configuration attribute renaming in the RFC5424Layout component used for syslog logging. The vulnerability introduces two distinct security issues: undocumented renaming of the newLineEscape attribute, which disables CRLF protection for TCP-based syslog services, and renaming of the useTlsMessageFormat attribute, which silently downgrades TLS-protected connections to unencrypted TCP without newline escaping. Organizations using RFC5424Layout directly for syslog integration are affected, though users of the SyslogAppender are not impacted. SEVERITY The vulnerability enables log injection attacks through CRLF sequence manipulation, allowing attackers to inject malicious content into log streams sent to syslog services. The attack vector is network-based with low complexity, requiring only the ability to influence log input. Potential impacts include log tampering, sidestepping security controls, and deceiving downstream log analysis systems. The CVSS score is not yet assigned, though the FAUCET Risk Score of 46.0/100 and EPSS probability of 0.0019 suggest moderate concern relative to other vulnerabilities. EXPLOITATION STATUS This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. No publicly available exploit code has been identified. Community attention remains limited, reflecting the specific nature of the affected configuration. Organizations should prioritize upgrading to Apache Log4j Core version 2.25.4 to remediate this issue, particularly those operating syslog infrastructure with RFC5424Layout configured.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.21.0, < 2.25.4CPE matchmatch criteria | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:3.0.0:beta1:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:3.0.0:beta2:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:apache:log4j:3.0.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
Apr 10, 2026CVE-2026-34478: Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
Apr 10, 2026