Skip to content

[GHSA-qv9r-c865-cp47] Improper encoding of non-finite floating-point values...#8754

Open
ashwani945 wants to merge 1 commit into
ashwani945/advisory-improvement-8754from
ashwani945-GHSA-qv9r-c865-cp47
Open

[GHSA-qv9r-c865-cp47] Improper encoding of non-finite floating-point values...#8754
ashwani945 wants to merge 1 commit into
ashwani945/advisory-improvement-8754from
ashwani945-GHSA-qv9r-c865-cp47

Conversation

@ashwani945

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v4
  • Summary

Comments
CVE-2026-49844 affects org.apache.logging.log4j:log4j-api. The current advisory
does not have complete version range information for the 2.25.x and 2.26.x branches.

What's changing:

Branch Affected Versions Patched Version
2.25.x >= 2.25.0, < 2.25.5 2.25.5
2.26.x >= 2.26.0, < 2.26.1 2.26.1
Affected Products:
  • Ecosystem: Maven
  • Package: org.apache.logging.log4j:log4j-api
  • Vulnerable version ranges:
  • = 2.25.0, < 2.25.5

  • = 2.26.0, < 2.26.1

  • Patched versions:
  • 2.25.5
  • 2.26.1

Evidence:

  1. The vulnerability was fixed in Log4j API version 2.25.5
  2. The fix was backported to version 2.26.1 for the 2.26.x branch
  3. Verified by reviewing the official Apache Log4j repository and release notes

Impact of change:

  • Users on version 2.25.5 and 2.26.1 will no longer receive false positive alerts
  • Security scanning tools (Dependabot, OWASP, etc.) will accurately identify
    vulnerable versions
  • Organizations can safely upgrade to these patched versions without
    being incorrectly flagged

References:
https://nvd.nist.gov/vuln/detail/CVE-2026-49844
apache/logging-log4j2#4163
https://logging.apache.org/cyclonedx/vdr.xml
https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message
https://logging.apache.org/security.html#CVE-2026-49844

Note to Reviewers:
This advisory is currently marked as "Unreviewed". I have verified these version
ranges against the official Apache Log4j repository. Please review and update the
advisory database accordingly.

@github-actions
github-actions Bot changed the base branch from main to ashwani945/advisory-improvement-8754 July 22, 2026 08:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant