{"id":"GHSA-6hg6-v5c8-fphq","summary":"Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration","details":"The fix for  CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the  [`log4j2.sslVerifyHostName`](https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName) system property, but not when configured through the [`verifyHostName`](https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName) attribute of the `\u003cSsl\u003e` element.\n\nAlthough the `verifyHostName` configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value.\n\nA network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met:\n\n  *  An SMTP, Socket, or Syslog appender is in use.\n  *  TLS is configured via a nested \u003cSsl\u003e element.\n  *  The attacker can present a certificate issued by a CA trusted by the appender's configured trust store, or by the default Java trust store if none is configured.\n\nThis issue does not affect users of the HTTP appender, which uses a separate [`verifyHostname`](https://logging.apache.org/log4j/2.x/manual/appenders/network.html#HttpAppender-attr-verifyHostName) attribute that was not subject to this bug and verifies host names by default.\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.","aliases":["CVE-2026-34477"],"modified":"2026-09-10T03:50:43.570169134Z","published":"2026-04-10T18:31:17Z","database_specific":{"github_reviewed_at":"2026-04-14T00:11:55Z","nvd_published_at":"2026-04-10T16:16:30Z","cwe_ids":["CWE-297"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34477"},{"type":"WEB","url":"https://github.com/apache/logging-log4j2/pull/4075"},{"type":"PACKAGE","url":"https://github.com/apache/logging-log4j2"},{"type":"WEB","url":"https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4"},{"type":"WEB","url":"https://logging.apache.org/cyclonedx/vdr.xml"},{"type":"WEB","url":"https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName"},{"type":"WEB","url":"https://logging.apache.org/security.html#CVE-2026-34477"}],"affected":[{"package":{"name":"org.apache.logging.log4j:log4j-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.logging.log4j/log4j-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.12.0"},{"fixed":"2.25.4"}]}],"versions":["2.12.0","2.12.1","2.12.2","2.12.3","2.12.4","2.13.0","2.13.1","2.13.2","2.13.3","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0","2.17.1","2.17.2","2.18.0","2.19.0","2.20.0","2.21.0","2.21.1","2.22.0","2.22.1","2.23.0","2.23.1","2.24.0","2.24.1","2.24.2","2.24.3","2.25.0","2.25.1","2.25.2","2.25.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-6hg6-v5c8-fphq/GHSA-6hg6-v5c8-fphq.json"}},{"package":{"name":"org.apache.logging.log4j:log4j-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.logging.log4j/log4j-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0-alpha1"},{"last_affected":"3.0.0-beta3"}]}],"versions":["3.0.0-alpha1","3.0.0-beta1","3.0.0-beta2","3.0.0-beta3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-6hg6-v5c8-fphq/GHSA-6hg6-v5c8-fphq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N"}]}