Bug 2457323 (CVE-2026-34478)

Summary: CVE-2026-34478 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abrianik, alinfoot, aprice, asoldano, ataylor, bbaranow, bbrownin, bmaxwell, bstansbe, caswilli, chfoley, csutherl, dbruscin, dlofthou, drosa, dsoumis, dtrifiro, ewittman, fmariani, ggrzybek, gmalinko, istudens, ivassile, iweiss, janstey, jclere, jkoehler, jraez, jsamir, jwon, kaycoth, kgaikwad, kvanderr, lphiri, mcarlett, mnovotny, mosmerov, mstipich, msvehla, nipatil, nwallace, oezr, pantinor, parichar, pberan, pbizzarr, pdelbell, pesilva, pjindal, plodge, pmackay, rbryant, rexwhite, rgodfrey, rhel-process-autobot, rkubis, rmaucher, rstancel, rstepani, sausingh, smaestri, sthirugn, swoodman, szappis, tasato, tcunning, thjenkin, vdosoudi, watson-tool-maintainers, weaton, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Apache Log4j Core. This vulnerability allows for log injection through the use of Carriage Return Line Feed (CRLF) sequences. This occurs because security-related configuration attributes were silently renamed, impacting users who directly configure Rfc5424Layout with stream-based syslog services. An attacker could exploit this to inject malicious data into log files, potentially obscuring critical security events or manipulating system records.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2457896, 2457899, 2457900, 2457895, 2457897, 2457898    
Bug Blocks:    

Description OSIDB Bzimport 2026-04-10 16:02:16 UTC
Apache Log4j Core's  Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.

Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:

  *  The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output.
  *  The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping.


Users of the SyslogAppender are not affected, as its configuration attributes were not modified.

Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.

Comment 2 errata-xmlrpc 2026-06-02 17:41:21 UTC
This issue has been addressed in the following products:

  Red Hat Data Grid 8.6.1

Via RHSA-2026:22619 https://access.redhat.com/errata/RHSA-2026:22619

Comment 3 errata-xmlrpc 2026-07-09 15:29:20 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16

Via RHSA-2026:37390 https://access.redhat.com/errata/RHSA-2026:37390