Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Vulnerability Description
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Vulnerability Type
对输出编码和转义不恰当
Vulnerability Title
Apache Log4j API 输出处理不当漏洞
Vulnerability Description
Apache Log4j API是美国Apache基金会开源的一款基于Java的日志记录组件。 Apache Log4j API存在输出处理不当漏洞,该漏洞源于MapMessage JSON序列化过程中对非有限浮点值的编码不当,导致输出无效JSON,可能破坏日志记录或中断下游日志解析。以下版本受到影响:2.13.1版本至2.25.4版本和2.26.0版本。
CVSS Information
N/A
Vulnerability Type
N/A