VDB
GCVE-110-NCSC-2026-378
GCVE-110-NCSC-2026-378
Advisory PublishedCVSS 8.0/10
Apache Log4j Core's XmlLayout up to version 2.25.3 fails to sanitize forbidden XML 1.0 characters causing malformed XML and potential logging failures, while multiple enterprise products from NetApp, Oracle, IBM, HPE, and SAP are affected by exploitable Log4j vulnerabilities.
Weaknesses (CWE)
CWE-116Improper Encoding or Escaping of Output
Risk Scores
CVSS 3.1
8.0/10
High · CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Oracle | vers:unknown/* | — | — |
Browse GCVE Records
406 records in the GCVE database · Updated September 17, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.