Debian Package Tracker
Register | Log in
Subscribe

apache-log4j2

Apache Log4j - Logging Framework for Java

Choose email to subscribe with

general
  • source: apache-log4j2 (main)
  • version: 2.19.0-2
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: Emmanuel Bourg [DMD]
  • arch: all
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.17.1-1~deb11u1
  • o-o-sec: 2.17.1-1~deb11u2
  • oldstable: 2.19.0-2
  • stable: 2.19.0-2
  • testing: 2.19.0-2
  • unstable: 2.19.0-2
versioned links
  • 2.17.1-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.17.1-1~deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.19.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • liblog4j2-java
action needed
A new upstream version is available: 2.26.1 high
A new upstream version 2.26.1 is available, you should consider packaging it.
Created: 2025-11-26 Last update: 2026-10-02 15:02
5 security issues in sid high

There are 5 open security issues in sid.

5 important issues:
  • CVE-2025-68161: The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true. This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions: * The attacker is able to intercept or redirect network traffic between the client and the log receiver. * The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured). Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue. As an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.
  • CVE-2026-34479: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records. Two groups of users are affected: * Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file. * Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class. Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue. Note: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.
  • CVE-2026-34480: Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.
  • CVE-2026-34481: Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records. An attacker can exploit this issue only if both of the following conditions are met: * The application uses JsonTemplateLayout. * The application logs a MapMessage, or logs an object directly (e.g., via Logger.info(Object), which wraps it in an ObjectMessage), where the message contains an attacker-controlled floating-point value. Users are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue. Note: The fix released in version 2.25.4 did not cover all affected code paths. CVE-2026-49844 was assigned to the remaining issue, which concerns the MapMessage.asJson() serialization in Apache Log4j API and is fixed in versions 2.25.5 and 2.26.1.
  • CVE-2026-49844: Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.
Created: 2025-12-19 Last update: 2026-09-01 22:00
5 security issues in forky high

There are 5 open security issues in forky.

5 important issues:
  • CVE-2025-68161: The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true. This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions: * The attacker is able to intercept or redirect network traffic between the client and the log receiver. * The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured). Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue. As an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.
  • CVE-2026-34479: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records. Two groups of users are affected: * Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file. * Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class. Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue. Note: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.
  • CVE-2026-34480: Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.
  • CVE-2026-34481: Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records. An attacker can exploit this issue only if both of the following conditions are met: * The application uses JsonTemplateLayout. * The application logs a MapMessage, or logs an object directly (e.g., via Logger.info(Object), which wraps it in an ObjectMessage), where the message contains an attacker-controlled floating-point value. Users are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue. Note: The fix released in version 2.25.4 did not cover all affected code paths. CVE-2026-49844 was assigned to the remaining issue, which concerns the MapMessage.asJson() serialization in Apache Log4j API and is fixed in versions 2.25.5 and 2.26.1.
  • CVE-2026-49844: Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.
Created: 2025-12-19 Last update: 2026-09-01 22:00
4 security issues in bullseye high

There are 4 open security issues in bullseye.

3 important issues:
  • CVE-2026-34479: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records. Two groups of users are affected: * Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file. * Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class. Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue. Note: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.
  • CVE-2026-34481: Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records. An attacker can exploit this issue only if both of the following conditions are met: * The application uses JsonTemplateLayout. * The application logs a MapMessage, or logs an object directly (e.g., via Logger.info(Object), which wraps it in an ObjectMessage), where the message contains an attacker-controlled floating-point value. Users are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue. Note: The fix released in version 2.25.4 did not cover all affected code paths. CVE-2026-49844 was assigned to the remaining issue, which concerns the MapMessage.asJson() serialization in Apache Log4j API and is fixed in versions 2.25.5 and 2.26.1.
  • CVE-2026-49844: Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.
1 issue postponed or untriaged:
  • CVE-2026-34480: (postponed; to be fixed through a stable update) Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.
Created: 2026-04-12 Last update: 2026-08-31 08:32
lintian reports 9 warnings high
Lintian reports 9 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2020-07-29 Last update: 2022-12-16 15:48
3 open merge requests in Salsa normal
There are 3 open merge requests for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-10-01 Last update: 2026-10-01 17:01
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 2.26.1-1, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 0c2ed345d3af2564cb11c46e8dcdb18d9ff7029c
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 22:38:56 2026 -0700

    interim changelog

commit 5b531ea55d848b1541222c08b1bf480619b53bae
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 21:58:02 2026 -0700

    Bump Standards-Version to 4.7.4

commit b105fbc687b65a4d143cf96e07daf71e76fadd2f
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 21:44:41 2026 -0700

    Drop Build-Depends on groovy (Closes: #1109751)

commit 2cad5f0f90233391eb6058f3a17cd66510978a6e
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:22:49 2026 -0700

    Update Debian poms to align with upstream 2.26.1

commit 3c7520fe5fb623393d1862368a6b7c859e2f0415
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:20:58 2026 -0700

    Update d/maven.rules and ignoreRules for new upstream release

commit fd0d6ae126326e246d57fb6f98de5b586c858124
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:18:49 2026 -0700

    Update debian/rules to set POM revision property to upstream package version

commit 0e2ff6e25c9ebe13637089e92b783a4af447149d
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:18:05 2026 -0700

    Add libjspecify to Build-Depends

commit 38078ee02943ad66a3b87d75ffc5f06664ecaaef
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:16:46 2026 -0700

    Add patch to ignore log4j-docgen

commit 456aa1624c4a5e71a65391ea35b19bc79e5f11e3
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:15:33 2026 -0700

    Add patch to ignore bnd baseline check

commit e98758344c8b3e6e8df103b82f94a64fa93ce0f0
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:14:27 2026 -0700

    Add patch for commons-lang3 dependency

commit 100dee0bad6efce6dff8afe254c0408bbe818b2f
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:13:08 2026 -0700

    Add patch to drop dummy resources from main POM

commit d66d2a3631bb0a8d949a6987c35402937c973dac
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:10:51 2026 -0700

    Add patch to set default compiler version

commit 24f40545fcec30205d46f33406da9715091223a5
Author: tony mancill <tmancill@debian.org>
Date:   Sun Sep 27 19:09:51 2026 -0700

    Update 01-disable-kafka-appender.patch

commit fe8866f8e79062d85db981c214b190f3b7641063
Merge: 7e08ee6 09efcd0
Author: tony mancill <tmancill@debian.org>
Date:   Fri Sep 25 16:29:39 2026 -0700

    Update upstream source from tag 'upstream/2.26.1'
    
    Update to upstream version '2.26.1'
    with Debian dir b5dbe540646f7664292f6755957c0cdb09f3c596

commit 09efcd016276ee37d791b89c4cec857fe3cdec61
Author: tony mancill <tmancill@debian.org>
Date:   Fri Sep 25 16:29:32 2026 -0700

    New upstream version 2.26.1

commit 7e08ee694d977a4dcf2cd49f5e985d1701da4a3f
Author: tony mancill <tmancill@debian.org>
Date:   Sat Dec 20 18:09:13 2025 -0800

    Remove log4j-kubernetes/pom.xml from liblog4j-java.poms

commit f540c05b6260b5a1a61f57da4b2fa281c170f889
Author: tony mancill <tmancill@debian.org>
Date:   Sat Dec 20 18:03:12 2025 -0800

    interim changelog entry

commit cd801dd6307e2df44a6450cd4a40c0afdb9e6790
Author: tony mancill <tmancill@debian.org>
Date:   Sat Dec 20 18:02:26 2025 -0800

    Interim patch updates

commit 0943a145c0cdebc04fb0c8066715b42fecd11cd4
Merge: 5be9780 5dc2634
Author: tony mancill <tmancill@debian.org>
Date:   Sat Dec 20 17:29:21 2025 -0800

    Update upstream source from tag 'upstream/2.25.3'
    
    Update to upstream version '2.25.3'
    with Debian dir b54522a7c9d3291cb8dd8e82eb7b95d51b622ee8

commit 5dc2634bccfd5d408c0a2b4f2705dc819b5ea5ae
Author: tony mancill <tmancill@debian.org>
Date:   Sat Dec 20 17:29:15 2025 -0800

    New upstream version 2.25.3

commit 5be9780dd34fb9079e727aec07fb2359c6d0a70b
Author: tony mancill <tmancill@debian.org>
Date:   Sun Jun 30 15:09:39 2024 -0700

    interim changelog entry

commit 7a19adfd6a25a9a6fd211ce4855657c2ccd71f62
Merge: 569e84c f6f54fe
Author: tony mancill <tmancill@debian.org>
Date:   Sun Jun 30 14:53:32 2024 -0700

    Update upstream source from tag 'upstream/2.23.1'
    
    Update to upstream version '2.23.1'
    with Debian dir b795cd475f6f11cfe6761c2232de36b2ad89041b

commit f6f54fef2709fe3870cce5ff869edb761fbcd9b7
Author: tony mancill <tmancill@debian.org>
Date:   Sun Jun 30 14:53:26 2024 -0700

    New upstream version 2.23.1
Created: 2026-10-01 Last update: 2026-10-01 17:01
5 low-priority security issues in trixie low

There are 5 open security issues in trixie.

5 issues left for the package maintainer to handle:
  • CVE-2025-68161: (needs triaging) The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true. This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions: * The attacker is able to intercept or redirect network traffic between the client and the log receiver. * The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured). Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue. As an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.
  • CVE-2026-34479: (needs triaging) The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records. Two groups of users are affected: * Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file. * Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class. Users are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue. Note: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.
  • CVE-2026-34480: (needs triaging) Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.
  • CVE-2026-34481: (needs triaging) Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records. An attacker can exploit this issue only if both of the following conditions are met: * The application uses JsonTemplateLayout. * The application logs a MapMessage, or logs an object directly (e.g., via Logger.info(Object), which wraps it in an ObjectMessage), where the message contains an attacker-controlled floating-point value. Users are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue. Note: The fix released in version 2.25.4 did not cover all affected code paths. CVE-2026-49844 was assigned to the remaining issue, which concerns the MapMessage.asJson() serialization in Apache Log4j API and is fixed in versions 2.25.5 and 2.26.1.
  • CVE-2026-49844: (needs triaging) Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-12-19 Last update: 2026-09-01 22:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.1).
Created: 2022-12-17 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2026-01-19] Accepted apache-log4j2 2.17.1-1~deb11u2 (source) into oldoldstable-security (Markus Koschany)
  • [2022-12-28] apache-log4j2 2.19.0-2 MIGRATED to testing (Debian testing watch)
  • [2022-12-22] Accepted apache-log4j2 2.19.0-2 (source) into unstable (tony mancill)
  • [2022-12-20] apache-log4j2 2.19.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-15] Accepted apache-log4j2 2.19.0-1 (source) into unstable (Emmanuel Bourg)
  • [2022-05-10] apache-log4j2 2.17.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-05-05] Accepted apache-log4j2 2.17.2-1 (source) into unstable (Markus Koschany)
  • [2022-02-13] Accepted apache-log4j2 2.17.1-1~deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2022-02-13] Accepted apache-log4j2 2.17.1-1~deb10u1 (source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-31] apache-log4j2 2.17.1-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-29] Accepted apache-log4j2 2.12.4-0+deb9u1 (source) into oldoldstable (Markus Koschany)
  • [2021-12-29] Accepted apache-log4j2 2.17.1-1 (source) into unstable (Markus Koschany)
  • [2021-12-26] Accepted apache-log4j2 2.12.3-0+deb9u1 (source) into oldoldstable (Markus Koschany)
  • [2021-12-24] Accepted apache-log4j2 2.17.0-1~deb10u1 (source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-24] Accepted apache-log4j2 2.17.0-1~deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-24] Accepted apache-log4j2 2.15.0-1~deb10u1 (source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-24] Accepted apache-log4j2 2.16.0-1~deb10u1 (source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-21] apache-log4j2 2.17.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-18] Accepted apache-log4j2 2.17.0-1~deb11u1 (source) into stable-security->embargoed, stable-security (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-18] Accepted apache-log4j2 2.17.0-1~deb10u1 (source) into oldstable->embargoed, oldstable (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-18] Accepted apache-log4j2 2.17.0-1 (source) into unstable (Markus Koschany)
  • [2021-12-17] apache-log4j2 2.16.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-16] Accepted apache-log4j2 2.16.0-1~deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-16] Accepted apache-log4j2 2.16.0-1~deb11u1 (source) into stable-security->embargoed, stable-security (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-16] Accepted apache-log4j2 2.16.0-1~deb10u1 (source) into oldstable->embargoed, oldstable (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-15] Accepted apache-log4j2 2.16.0-1 (source) into unstable (Markus Koschany)
  • [2021-12-14] apache-log4j2 2.15.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-12] Accepted apache-log4j2 2.7-2+deb9u1 (source) into oldoldstable (Markus Koschany)
  • [2021-12-12] Accepted apache-log4j2 2.15.0-1~deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2021-12-11] Accepted apache-log4j2 2.15.0-1~deb10u1 (source) into oldstable->embargoed, oldstable (Debian FTP Masters) (signed by: Markus Koschany)
  • 1
  • 2
bugs [bug history graph]
  • all: 6
  • RC: 0
  • I&N: 5
  • M&W: 0
  • F&P: 1
  • patch: 0
links
  • homepage
  • lintian (0, 9)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.19.0-2build1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing