SUSE-SU-2026:1843-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261843-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1843-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:1843-1
Upstream
CVE (4)
Related
Published
2026-05-13T15:24:57Z
Modified
2026-05-14T08:15:06Z
Summary
Security update for log4j
Details

This update for log4j fixes the following issues:

  • CVE-2026-34477: TLS connections vulnerable to interception due to incomplete hostname verification configuration checks (bsc#1262050).
  • CVE-2026-34479: silent log event loss due to improper XML escaping in Log4j1XmlLayout (bsc#1262091).
  • CVE-2026-34480: silent log event loss due to improper XML escaping in XmlLayout (bsc#1262092).
  • CVE-2026-34481: silent log event loss due to improper serialization of non-finite floating-point values in JsonTemplateLayout (bsc#1262093).
References

Affected packages