Network Management

SolarWinds Products and Apache Log4j Vulnerabilities

This article addresses vulnerabilities in Apache Log4j as described in CVE-2026-34481, CVE-2026-34480, CVE-2026-34479, CVE-2026-34478, CVE-2026-34477. SolarWinds Observability Self-Hosted is not impacted by these vulnerabilities.

First published date

5/4/2026 3:53 PM

Last published date

5/4/2026 3:53 PM

Overview

In 2026, the following security bulletins were released to address vulnerabilities in Apache Log4j:

Apache Log4j’s JsonTemplateLayout (≤2.25.3) can emit invalid JSON when logging non-finite float values (NaN/Infinity), potentially breaking downstream processing if attacker-controlled MapMessage data is logged.

Apache Log4j Core’s XmlLayout (≤2.25.3) may generate invalid XML or drop log events due to unsanitized forbidden characters—potentially causing parser failures or logging exceptions.

The Log4j1XmlLayout in the Log4j 1-to-Log4j 2 bridge produces malformed XML by not escaping forbidden characters—risking dropped or unindexed logs.

Apache Log4j Core’s Rfc5424Layout (2.21.0–2.25.3) can allow CRLF log injection due to silently renamed security attributes that disable newline escaping and alter framing behavior.

Apache Log4j Core (≤2.25.3) fails to enforce TLS hostname verification when configured via the <Ssl verifyHostName> attribute—leaving certain appenders vulnerable to MITM attacks.

Product section

Orion Platform

Cause

CVE-2026-34481, CVE-2026-34480, CVE-2026-34479, CVE-2026-34478, CVE-2026-34477.

Resolution

SolarWinds Observability Self-Hosted isnot impacted by these vulnerabilities. 

XML logging is not used in our product.

Follow up on the previous CVE-2025-68161 issue. We do not use this type of architecture in our product.