Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49844— Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()

AI Predicted 5.3 Difficulty: Easy EPSS 0.57% · P44

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

VendorProductVersion RangeStatus
Apache Software FoundationApache Log4j API2.13.1< 2.25.5affected
2.26.0< 2.26.1affected
3.0.0-alpha1≤ 3.0.0-beta2affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-49844

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Source: CVE Program / CVE List V5
Vulnerability Description
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对输出编码和转义不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Log4j API 输出处理不当漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Log4j API是美国Apache基金会开源的一款基于Java的日志记录组件。 Apache Log4j API存在输出处理不当漏洞,该漏洞源于MapMessage JSON序列化过程中对非有限浮点值的编码不当,导致输出无效JSON,可能破坏日志记录或中断下游日志解析。以下版本受到影响:2.13.1版本至2.25.4版本和2.26.0版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Apache Software FoundationApache Log4j API 2.13.1 ~ 2.25.5 cpe:2.3:a:apache:log4j_api:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-49844

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49844

登录查看更多情报信息。

Patches & Fixes for CVE-2026-49844 (1)

Same Patch Batch · Apache Software Foundation · 2026-07-10 · 9 CVEs total

CVE-2026-40454Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash clie
CVE-2026-40452Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to un
CVE-2026-40009Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themse
CVE-2026-40008Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
CVE-2026-40007Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language pr
CVE-2026-40006Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap
CVE-2026-40005Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
CVE-2026-28564Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials

IV. Related Vulnerabilities

V. Comments for CVE-2026-49844

No comments yet


Leave a comment