CVE-2026-40023 - Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters
CVE ID :CVE-2026-40023
Published : April 10, 2026, 3:45 p.m. | 20 minutes ago
Description :Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayo...
Related Vulnerabilities
- CVE-2026-34486: Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-2914 MEDIUM
- CVE-2026-24880: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap MEDIUM
- CVE-2026-34477: The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: i MEDIUM
- CVE-2026-22750: When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl. HIGH
- CVE-2026-34487: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clusterin MEDIUM
Related Coverage
Threat Actors