UBUNTU-CVE-2026-34481
Apache Log4j's JsonTemplateLayout up to version 2.25.3 produces invalid JSON output when logging non-finite floating-point values (NaN, Infinity, -Infinity), violating RFC 8259. This can cause downstream log processing systems to reject or fail to index affected log records. Exploitation requires the application to use JsonTemplateLayout and log attacker-controlled floating-point values within MapMessage or ObjectMessage. Users are advised to upgrade to version 2.25.4 or later, noting that some code paths were not fully fixed until versions 2.25.5 and 2.26.1.
AI Analysis
Technical Summary
The vulnerability in Apache Log4j's JsonTemplateLayout up to version 2.25.3 causes invalid JSON output when log events include non-finite floating-point values such as NaN, Infinity, or -Infinity. These values are disallowed by RFC 8259, potentially causing downstream log processing failures. Exploitation requires that the application uses JsonTemplateLayout and logs attacker-controlled floating-point values either in MapMessage or directly via ObjectMessage. The issue is fixed in version 2.25.4, but some affected code paths remain vulnerable and are addressed in subsequent versions 2.25.5 and 2.26.1 under CVE-2026-49844.
Potential Impact
Invalid JSON output from logging non-finite floating-point values may cause downstream log processing systems to reject or fail to index affected log records. This can impact log integrity and availability for monitoring or forensic analysis. No direct code execution or privilege escalation is indicated. Exploitation requires specific logging configurations and attacker-controlled floating-point input.
Mitigation Recommendations
Users are advised to upgrade Apache Log4j JSON Template Layout to version 2.25.4 or later to correct this issue. Note that version 2.25.4 does not cover all affected code paths; therefore, upgrading to versions 2.25.5 or 2.26.1 is recommended to fully mitigate the vulnerability. No other mitigation actions are indicated.
UBUNTU-CVE-2026-34481
Description
Apache Log4j's JsonTemplateLayout up to version 2.25.3 produces invalid JSON output when logging non-finite floating-point values (NaN, Infinity, -Infinity), violating RFC 8259. This can cause downstream log processing systems to reject or fail to index affected log records. Exploitation requires the application to use JsonTemplateLayout and log attacker-controlled floating-point values within MapMessage or ObjectMessage. Users are advised to upgrade to version 2.25.4 or later, noting that some code paths were not fully fixed until versions 2.25.5 and 2.26.1.
CVSS v4.0
Affected software
pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/[email protected]+deb10u1ubuntu0.2?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Apache Log4j's JsonTemplateLayout up to version 2.25.3 causes invalid JSON output when log events include non-finite floating-point values such as NaN, Infinity, or -Infinity. These values are disallowed by RFC 8259, potentially causing downstream log processing failures. Exploitation requires that the application uses JsonTemplateLayout and logs attacker-controlled floating-point values either in MapMessage or directly via ObjectMessage. The issue is fixed in version 2.25.4, but some affected code paths remain vulnerable and are addressed in subsequent versions 2.25.5 and 2.26.1 under CVE-2026-49844.
Potential Impact
Invalid JSON output from logging non-finite floating-point values may cause downstream log processing systems to reject or fail to index affected log records. This can impact log integrity and availability for monitoring or forensic analysis. No direct code execution or privilege escalation is indicated. Exploitation requires specific logging configurations and attacker-controlled floating-point input.
Mitigation Recommendations
Users are advised to upgrade Apache Log4j JSON Template Layout to version 2.25.4 or later to correct this issue. Note that version 2.25.4 does not cover all affected code paths; therefore, upgrading to versions 2.25.5 or 2.26.1 is recommended to fully mitigate the vulnerability. No other mitigation actions are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-34481
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 4.0
Threat ID: 6a58b4cc68715ace43dab031
Added to database: 07/16/2026, 10:39:08 UTC
Last enriched: 07/16/2026, 13:21:59 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.