{"api_version":"v1","generated_at":"2026-10-06T22:50:00+00:00","product":{"cve_count":4,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-log4j-core-774c8e073318","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Log4j Core","next_cursor":null,"observations":[{"affected":"2.0-alpha1 < 2.25.4; 3.0.0-alpha1 \u2264 3.0.0-beta3","affected_versions_present":true,"cve_id":"CVE-2026-34480","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34480","fixed":"Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update).","last_modified":"2026-04-10T17:45:07.434Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-34480","primary_source":"","published":"2026-04-10T15:42:03.843Z"},{"affected":"2.21.0 < 2.25.4; 3.0.0-beta1 \u2264 3.0.0-beta3","affected_versions_present":true,"cve_id":"CVE-2026-34478","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34478","fixed":"Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update).","last_modified":"2026-04-10T17:50:12.484Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-34478","primary_source":"","published":"2026-04-10T15:40:17.713Z"},{"affected":"2.12.0 < 2.25.4; 3.0.0-alpha1 \u2264 3.0.0-beta3","affected_versions_present":true,"cve_id":"CVE-2026-34477","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34477","fixed":"The container image provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the \"podman pull\" command.","last_modified":"2026-04-10T17:38:57.154Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-34477","primary_source":"","published":"2026-04-10T15:36:19.740Z"},{"affected":"2.0-beta9 < 2.25.3; 3.0.0-alpha1 \u2264 3.0.0-beta3","affected_versions_present":true,"cve_id":"CVE-2025-68161","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68161","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-10T16:18:50.424Z","patch_url":"https://github.com/apache/logging-log4j2/pull/4002","primary_source":"","published":"2025-12-18T20:47:49.123Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
