Skip to content

[FP]: CVE-2026-34480 log4j-api confused with log4j-core #8457

@adam-siklosi

Description

@adam-siklosi

Package URl

pkg:maven/org.apache.logging.log4j/log4j-api@2.24.2

CPE

cpe:2.3:a:apache:log4j:2.24.2:::::::*

CVE

CVE-2026-34480

ODC Integration

{"label" => "Gradle Plugin"}

ODC Version

12.1.9

Description

This vulnerability is limited to Apache Log4j Core (the org.apache.logging.log4j:log4j-core artifact / log4j-core.jar). It impacts the XmlLayout class in Log4j Core versions 2.21.0 through 2.25.3 (and some 3.0.0 beta versions).

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions