UBUNTU-CVE-2026-49844
Apache Log4j API versions 2.13.1 through 2.25.4 and 2.26.0 improperly encode non-finite floating-point values (NaN, Infinity, -Infinity) during MapMessage JSON serialization. This results in output that is not valid JSON according to RFC 8259, potentially causing malformed log records or disruption in downstream log processing. The issue occurs only if the application uses JsonTemplateLayout or other layouts relying on MapMessage.asJson() and logs attacker-controlled non-finite floating-point values. Fixed in versions 2.25.5 and 2.26.1.
AI Analysis
Technical Summary
This vulnerability in Apache Log4j API affects versions 2.13.1 through 2.25.4 and 2.26.0. The flaw arises because MapMessage.asJson() emits bare tokens for non-finite IEEE 754 floating-point values (NaN, Infinity, -Infinity), which are not permitted by RFC 8259 JSON standards. This can cause JSON parsing failures in log consumers. The defect is reachable only when an application uses the message resolver of JsonTemplateLayout or similar layouts relying on MapMessage.asJson() and logs MapMessages containing attacker-controlled non-finite floating-point values. The issue was not fully addressed by the fix for CVE-2026-34481. Upgrading to Apache Log4j API 2.25.5 or 2.26.1 resolves the issue by producing RFC 8259-compliant JSON output for these values.
Potential Impact
Malformed JSON output in log records can corrupt logs or disrupt downstream log ingestion and parsing systems. This may affect log reliability and monitoring but does not directly lead to code execution or data breach. The impact is limited to log integrity and processing.
Mitigation Recommendations
Users should upgrade affected Apache Log4j API versions to 2.25.5 or 2.26.1, which include fixes emitting RFC 8259-compliant JSON for non-finite floating-point values. No other mitigation is indicated. Patch status is confirmed by the advisory.
UBUNTU-CVE-2026-49844
Description
Apache Log4j API versions 2.13.1 through 2.25.4 and 2.26.0 improperly encode non-finite floating-point values (NaN, Infinity, -Infinity) during MapMessage JSON serialization. This results in output that is not valid JSON according to RFC 8259, potentially causing malformed log records or disruption in downstream log processing. The issue occurs only if the application uses JsonTemplateLayout or other layouts relying on MapMessage.asJson() and logs attacker-controlled non-finite floating-point values. Fixed in versions 2.25.5 and 2.26.1.
CVSS v4.0
Affected software
pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Apache Log4j API affects versions 2.13.1 through 2.25.4 and 2.26.0. The flaw arises because MapMessage.asJson() emits bare tokens for non-finite IEEE 754 floating-point values (NaN, Infinity, -Infinity), which are not permitted by RFC 8259 JSON standards. This can cause JSON parsing failures in log consumers. The defect is reachable only when an application uses the message resolver of JsonTemplateLayout or similar layouts relying on MapMessage.asJson() and logs MapMessages containing attacker-controlled non-finite floating-point values. The issue was not fully addressed by the fix for CVE-2026-34481. Upgrading to Apache Log4j API 2.25.5 or 2.26.1 resolves the issue by producing RFC 8259-compliant JSON output for these values.
Potential Impact
Malformed JSON output in log records can corrupt logs or disrupt downstream log ingestion and parsing systems. This may affect log reliability and monitoring but does not directly lead to code execution or data breach. The impact is limited to log integrity and processing.
Mitigation Recommendations
Users should upgrade affected Apache Log4j API versions to 2.25.5 or 2.26.1, which include fixes emitting RFC 8259-compliant JSON for non-finite floating-point values. No other mitigation is indicated. Patch status is confirmed by the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-49844
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 4.0
Threat ID: 6a58b49168715ace43da79b6
Added to database: 07/16/2026, 10:38:09 UTC
Last enriched: 07/16/2026, 12:25:29 UTC
Last updated: 07/31/2026, 19:24:49 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.