Database Management
Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-34480
This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-34480.
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-34480.
Product section
Cause
CVE-2026-34480 is due to Apache Log4j Core’s XmlLayout failing to sanitize characters forbidden by XML 1.0 specification, producing an invalid XML output whenever a log message or MDC value contains such characters. The impact of this vulnerability will depend on the StAX implementation.
Resolution
While the component’s presence is flagged by dependency scanning tools, our analysis shows there is no associated security risk.
SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-34480 because the attack vector, Log4j XmlLayout, does not exist in DPA’s deployment.