Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49844— Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()

Quick assessment

Affected
Apache Software Foundation Apache Log4j API
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Log4j API是美国Apache基金会开源的一款基于Java的日志记录组件。 Apache Log4j API存在输出处理不当漏洞,该漏洞源于MapMessage JSON序列化过程中对非有限浮点值的编码不当,导致输出无效JSON,可能破坏日志记录或中断下游日志解析。以下版本受到影响:2.13.1版本至2.25.4版本和2.26.0版本。

CVSS 6.3 · Medium EPSS 0.81% · P55

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

VendorProduct Version RangeStatus
Apache Software Foundation Apache Log4j API 2.13.1< 2.25.5 affected
2.26.0< 2.26.1 affected
3.0.0-alpha1≤ 3.0.0-beta2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-49844

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Source: CVE Program / CVE List V5
Vulnerability Description
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对输出编码和转义不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Log4j API 输出处理不当漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Log4j API是美国Apache基金会开源的一款基于Java的日志记录组件。 Apache Log4j API存在输出处理不当漏洞,该漏洞源于MapMessage JSON序列化过程中对非有限浮点值的编码不当,导致输出无效JSON,可能破坏日志记录或中断下游日志解析。以下版本受到影响:2.13.1版本至2.25.4版本和2.26.0版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Log4j API 2.13.1 ~ 2.25.5 cpe:2.3:a:apache:log4j_api:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-49844

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49844

登录查看更多情报信息。

Patches & Fixes for CVE-2026-49844 (1)

Same Patch Batch · Apache Software Foundation · 2026-07-10 · 9 CVEs total

CVE-2026-40454 Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash clie
CVE-2026-40452 Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to un
CVE-2026-40009 Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themse
CVE-2026-40008 Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
CVE-2026-40007 Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language pr
CVE-2026-40006 Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap
CVE-2026-40005 Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
CVE-2026-28564 Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials

IV. Related Vulnerabilities

V. Comments for CVE-2026-49844

No comments yet


Leave a comment