<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:40:38 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-49844 — Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-49844</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Log4j API&lt;/p&gt;
&lt;p&gt;Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.&lt;/p&gt;
&lt;p&gt;The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.&lt;/p&gt;
&lt;p&gt;The defect is reachable only when both of the following conditions hold:&lt;/p&gt;
&lt;p&gt;*  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{&amp;#34;JSON&amp;#34;}).
  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.&lt;/p&gt;
&lt;p&gt;An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.&lt;/p&gt;
&lt;p&gt;Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Log4j API&lt;/p&gt;
&lt;p&gt;Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.&lt;/p&gt;
&lt;p&gt;The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.&lt;/p&gt;
&lt;p&gt;The defect is reachable only when both of the following conditions hold:&lt;/p&gt;
&lt;p&gt;*  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{&amp;#34;JSON&amp;#34;}).
  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.&lt;/p&gt;
&lt;p&gt;An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.&lt;/p&gt;
&lt;p&gt;Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-49844</guid>
    </item>
  </channel>
</rss>
