Network Management
SolarWinds Products and Apache Log4j Vulnerabilities
This article addresses vulnerabilities in Apache Log4j as described in CVE-2026-34481, CVE-2026-34480, CVE-2026-34479, CVE-2026-34478, CVE-2026-34477. SolarWinds Observability Self-Hosted is not impacted by these vulnerabilities.
First published date
Last published date
Overview
In 2026, the following security bulletins were released to address vulnerabilities in Apache Log4j:
Apache Log4j’s JsonTemplateLayout (≤2.25.3) can emit invalid JSON when logging non-finite float values (NaN/Infinity), potentially breaking downstream processing if attacker-controlled MapMessage data is logged.
Apache Log4j Core’s XmlLayout (≤2.25.3) may generate invalid XML or drop log events due to unsanitized forbidden characters—potentially causing parser failures or logging exceptions.
The Log4j1XmlLayout in the Log4j 1-to-Log4j 2 bridge produces malformed XML by not escaping forbidden characters—risking dropped or unindexed logs.
Apache Log4j Core’s Rfc5424Layout (2.21.0–2.25.3) can allow CRLF log injection due to silently renamed security attributes that disable newline escaping and alter framing behavior.
Apache Log4j Core (≤2.25.3) fails to enforce TLS hostname verification when configured via the <Ssl verifyHostName> attribute—leaving certain appenders vulnerable to MITM attacks.
Product section
Cause
CVE-2026-34481, CVE-2026-34480, CVE-2026-34479, CVE-2026-34478, CVE-2026-34477.
Resolution
SolarWinds Observability Self-Hosted is not impacted by these vulnerabilities.
XML logging is not used in our product.
Follow up on the previous CVE-2025-68161 issue. We do not use this type of architecture in our product.