CVE-2026-40023 - Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters
CVE ID :CVE-2026-40023
Published : April 10, 2026, 3:45 p.m. | 20 minutes ago
Description :Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayo...
Related Vulnerabilities
- CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects MEDIUM
- CVE-2026-34486: Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-2914 MEDIUM
- CVE-2026-29145: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v MEDIUM
- CVE-2026-34478: Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424L MEDIUM
- CVE-2026-34487: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clusterin MEDIUM
Related Coverage
Threat Actors
- 蔓灵花 (International)
- Lazarus (North Korea)
- 艾叶豹 (International)
- 盲眼鹰 (International)