Skip to content

[FP]: CVE-2026-34480 log4j-api confused with log4j-core #8457

@adam-siklosi

Description

@adam-siklosi

Package URl

pkg:maven/org.apache.logging.log4j/[email protected]

CPE

cpe:2.3:a:apache:log4j:2.24.2:::::::*

CVE

CVE-2026-34480

ODC Integration

{"label" => "Gradle Plugin"}

ODC Version

12.1.9

Description

This vulnerability is limited to Apache Log4j Core (the org.apache.logging.log4j:log4j-core artifact / log4j-core.jar). It impacts the XmlLayout class in Log4j Core versions 2.21.0 through 2.25.3 (and some 3.0.0 beta versions).

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions