{"id":"openSUSE-SU-2026:20705-1","summary":"Security update for log4cxx","details":"This update for log4cxx fixes the following issues:\n\nChanges in log4cxx:\n\n- update to 1.7.0 (bsc#1261994, CVE-2026-40023):\n  * Non-ascii characters incorrectly encoded in JSON output [#615]\n  * XML output could contain characters not allowed by the XML 1.0\n    specification\n  * An XML configuration file with recursive references caused\n    program termination [#605]\n  * Possible undefined behavior during a configuration change\n  * Message loss when the calculation of a logged value also logs\n  * ODBCAppender prepared statement value buffers had incorrect\n    lifetimes [#581]\n\n- update to 1.6.0:\n  * Configuration ${varname} values can be set programatically prior\n    to loading a configuration file (see com/foo/config4.cpp) [#520]\n  * The current executable's file name and its components are available\n    for use in a configuration file and the LOG4CXX_CONFIGURATION\n    environment variable (see log4cxx::spi::Configurator::properties).\n    [#520]\n  * Console output (Log4cxx internal logging and BasicConfigurator)\n    use a color per message level by default [#529]\n  * New logging macros that defer binary-to-text conversion until\n    used in AsyncAppender's background thread\n  * A simplified way to attach an AsyncAppender to a logger using\n    a configuration file [#550]\n","modified":"2026-05-09T18:25:07.041035Z","published":"2026-05-07T10:19:52Z","related":["CVE-2026-40023"],"upstream":["CVE-2026-40023"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261994"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40023"}],"schema_version":"1.7.5"}