VDB

GCVE-110-NCSC-2026-259

GCVE-110-NCSC-2026-259
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published July 22, 2026
Apache Log4j Core's XmlLayout up to version 2.25.3 fails to sanitize forbidden XML 1.0 characters, causing malformed XML output or exceptions depending on the StAX parser, affecting multiple vendors including NetApp, HPE, Oracle, and IBM.

Weaknesses (CWE)

CWE-116Improper Encoding or Escaping of OutputCWE-131Incorrect Calculation of Buffer Size

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersionsPlatforms
Oraclevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

75,788 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›