Description
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.

The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.

The defect is reachable only when both of the following conditions hold:

* The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}).
* The application logs a MapMessage that contains an attacker-controlled floating-point value.


An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.

Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.
Published: 2026-07-10
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from the MapMessage JSON serializer emitting tokens for non‑finite IEEE 754 values such as NaN, Infinity, or –Infinity. The RFC 8259 standard forbids these tokens, so an attacker who can insert a non‑finite value into a MapMessage causes the resulting JSON to be syntactically incorrect. A conformant parser will reject or misinterpret the malformed record, which can corrupt the surrounding log entry or prevent downstream services from ingesting the log data, leading to operational disruption or loss of critical audit information.

Affected Systems

The flaw affects the Apache Log4j API version 2.13.1 through 2.25.4 and 2.26.0. It is exploitable only when an application uses the JsonTemplateLayout message resolver or any layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}) and logs a MapMessage containing an attacker‑controlled floating‑point value.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity, and the EPSS score of < 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires both an input path that allows injection of a non‑finite value into a MapMessage and a layout that serializes it to JSON, making the attack vector likely to be application‑level input that ends up in logs. Successful exploitation can result in malformed logs that disrupt downstream log ingestion or correlate logs, providing a denial‑of‑service path.

Generated by OpenCVE AI on July 25, 2026 at 19:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Log4j API to version 2.25.5 or 2.26.1, which emit RFC 8259‑compliant JSON for non‑finite values.
  • Sanitize or validate floating‑point values before inserting them into MapMessage objects, replacing NaN and Infinity with finite values or omitting them entirely.
  • Disable or replace JsonTemplateLayout or any layout that depends on MapMessage.asJson() if an immediate upgrade is not feasible, thereby removing the code path that can produce malformed output.

Generated by OpenCVE AI on July 25, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Description Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.
Title Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
First Time appeared Apache
Apache log4j Api
Weaknesses CWE-116
CPEs cpe:2.3:a:apache:log4j_api:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache log4j Api
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Apache Log4j Api
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-14T14:35:11.005Z

Reserved: 2026-06-01T20:15:42.977Z

Link: CVE-2026-49844

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T20:00:04Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output