{"id":"CVE-2026-34479","aliases":["GHSA-h383-gmxw-35v2"],"url":"https://o3.security/vulnerability/CVE-2026-34479","summary":"Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters","details":"The `Log4j1XmlLayout` from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.\n\nTwo groups of users are affected:\n\n* Those using `Log4j1XmlLayout` directly in a Log4j Core 2 configuration file.\n* Those using the Log4j 1 configuration compatibility layer with `org.apache.log4j.xml.XMLLayout` specified as the layout class.\n\nUsers are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version `2.25.4`, which corrects this issue.\n\n> [!NOTE]\n> The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the\n> [Log4j 1 to Log4j 2 migration guide](https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html), and specifically the section on eliminating reliance on the bridge.","published":"2026-04-10T15:41:07.888Z","modified":"2026-08-12T03:51:48.498932408Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.logging.log4j:log4j-1.2-api","fixedVersion":"2.25.4"},{"ecosystem":"Maven","name":"org.apache.logging.log4j:log4j-1.2-api","fixedVersion":null}],"fix":{"url":"https://github.com/apache/logging-log4j2/pull/4078","label":"apache/logging-log4j2#4078"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/10/8"},{"type":"WEB","url":"https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html"},{"type":"WEB","url":"https://repo.maven.apache.org/maven2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34479.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/gd0hp6mj17rn3kj279vgy4p7kd4zz5on"},{"type":"ADVISORY","url":"https://logging.apache.org/cyclonedx/vdr.xml"},{"type":"ADVISORY","url":"https://logging.apache.org/security.html#CVE-2026-34479"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34479"},{"type":"FIX","url":"https://github.com/apache/logging-log4j2/pull/4078"},{"type":"PACKAGE","url":"https://github.com/apache/logging-log4j2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.498932408Z"}}