CVE-2026-40023 - Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters
CVE ID :CVE-2026-40023
Published : April 10, 2026, 3:45 p.m. | 20 minutes ago
Description :Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayo...
Related Vulnerabilities
- CVE-2026-5525: A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handl MEDIUM
- CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects MEDIUM
- CVE-2026-25854: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th MEDIUM
- CVE-2026-22750: When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl. HIGH
- CVE-2026-40023: Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayou MEDIUM
Related Coverage
Threat Actors