← Back to feed Search feed

Log4j vulnerabilities

4 entries matching log4j — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-34477Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypassUNKNOWN34%ileMicrosoft2026-04-14
CVE-2026-34481Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayoutUNKNOWN49%ileMicrosoft2026-04-14
CVE-2026-34479Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden charactersUNKNOWN42%ileMicrosoft2026-04-14
CVE-2026-34480Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden charactersUNKNOWN55%ileMicrosoft2026-04-14