Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.apache.logging.log4j/log4j-core

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.

Join the discussion

Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes. Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly: * The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output. * The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping. Users of the SyslogAppender are not affected, as its configuration attributes were not modified. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.

Join the discussion

CVE-2026-34477 is a vulnerability in Apache Log4j Core affecting versions from 2.12.0 through 2.25.3. It involves improper validation of TLS certificates when hostname verification is configured via the <Ssl> element's verifyHostName attribute, which was silently ignored in these versions. This flaw allows a network attacker to potentially perform man-in-the-middle attacks if certain conditions are met, such as using SMTP, Socket, or Syslog appenders with TLS configured and the attacker presenting a trusted certificate. The issue does not affect the HTTP appender, which verifies hostnames correctly. Users are advised to upgrade to version 2.25.

Join the discussion

Apache Log4j Core versions 2.0-beta9 through 2.25.2 contain a vulnerability in the Socket Appender where TLS hostname verification is not properly performed, even if configured to do so. This flaw can allow a man-in-the-middle attacker to intercept or redirect log traffic if they can present a trusted certificate and intercept network traffic. The issue is addressed in version 2.25.3. Users can alternatively mitigate by restricting the trust root to limit trusted certificates.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:maven/org.apache.logging.log4j/log4j-core
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses