Threats Tagged 'cve-2026-34478'
View all threats tagged with 'cve-2026-34478'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-34478'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Security Advisory: Red Hat Offline Knowledge Portal security and content updateCVE-2025-11143 0 The Red Hat Offline Knowledge Portal has been updated to upgrade Solr from version 9. 8. 1 to 10. 0. 0 and to fix multiple security vulnerabilities identified by several CVEs including CVE-2025-11143 and CVE-2026-2332. This update addresses security issues related to the underlying components such as jetty-http and Solr, improving the security posture of the portal. The update also includes content updates as of May 26, 2026. No known exploits are reported in the wild for these vulnerabilities. The update is distributed as a container image available from the Red Hat container registry. Join the discussion | GCVE Database | 05/28/2026, 22:46:23 UTC Added: 05/29/2026, 21:01:50 UTC |
CVE-2026-34478: CWE-684 Incorrect Provision of Specified Functionality in Apache Software Foundation Apache Log4j CoreCVE-2026-34478 0 Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes. Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly: * The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output. * The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping. Users of the SyslogAppender are not affected, as its configuration attributes were not modified. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue. Join the discussion | CVE Database V5 | 04/10/2026, 15:40:17 UTC Added: 04/10/2026, 16:05:50 UTC |
Showing 1 to 2 of 2 results