CVE-2026-34479
Java vulnerability analysis and mitigation

The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.

Two groups of users are affected:

  • Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file.
  • Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class. Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue. Note: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.

SourceNVD

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-35582HIGH8.8
  • JavaJava
  • gov.nsa.emissary:emissary
NoYesApr 13, 2026
CVE-2026-40180HIGH7.7
  • JavaJava
  • io.quarkiverse.openapi.generator:quarkus-openapi-generator
NoYesApr 10, 2026
CVE-2026-34479MEDIUM6.9
  • JavaJava
  • org.apache.logging.log4j:log4j-1.2-api
NoYesApr 10, 2026
GHSA-cmxv-58fp-fm3gMEDIUM6.8
  • JavaJava
  • org.asynchttpclient:async-http-client
NoYesApr 14, 2026
CVE-2026-34481MEDIUM6.3
  • JavaJava
  • apache-log4j2
NoYesApr 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management