{"document":{"aggregate_severity":{"namespace":"https://access.redhat.com/security/updates/classification/","text":"Moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright © Red Hat, Inc. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"legal_disclaimer","text":"This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.","title":"Terms of Use"}],"publisher":{"category":"vendor","contact_details":"https://access.redhat.com/security/team/contact/","issuing_authority":"Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.","name":"Red Hat Product Security","namespace":"https://www.redhat.com"},"references":[{"category":"self","summary":"Canonical URL","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34481.json"}],"title":"org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output","tracking":{"current_release_date":"2026-09-04T16:34:46+00:00","generator":{"date":"2026-09-04T16:34:46+00:00","engine":{"name":"Red Hat SDEngine","version":"5.3.16"}},"id":"CVE-2026-34481","initial_release_date":"2026-04-10T15:43:00.100000+00:00","revision_history":[{"date":"2026-04-10T15:43:00.100000+00:00","number":"1","summary":"Initial version"},{"date":"2026-08-10T11:00:52.758843+00:00","number":"2","summary":"Current version"},{"date":"2026-09-04T16:34:46+00:00","number":"3","summary":"Last generated version"}],"status":"final","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"Red Hat AMQ Broker 7","product":{"name":"Red Hat AMQ Broker 7","product_id":"red_hat_amq_broker_7","product_identification_helper":{"cpe":"cpe:/a:redhat:amq_broker:7"}}}],"category":"product_family","name":"Red Hat AMQ Broker 7"},{"branches":[{"category":"product_name","name":"Red Hat Enterprise Linux 8","product":{"name":"Red Hat Enterprise Linux 8","product_id":"red_hat_enterprise_linux_8","product_identification_helper":{"cpe":"cpe:/o:redhat:enterprise_linux:8"}}}],"category":"product_family","name":"Red Hat Enterprise Linux 8"},{"branches":[{"category":"product_name","name":"Red Hat Enterprise Linux 9","product":{"name":"Red Hat Enterprise Linux 9","product_id":"red_hat_enterprise_linux_9","product_identification_helper":{"cpe":"cpe:/o:redhat:enterprise_linux:9"}}}],"category":"product_family","name":"Red Hat Enterprise Linux 9"},{"branches":[{"category":"product_name","name":"Red Hat JBoss Enterprise Application Platform 7","product":{"name":"Red Hat JBoss Enterprise Application Platform 7","product_id":"red_hat_jboss_enterprise_application_platform_7","product_identification_helper":{"cpe":"cpe:/a:redhat:jboss_enterprise_application_platform:7"}}}],"category":"product_family","name":"Red Hat JBoss Enterprise Application Platform 7"},{"branches":[{"category":"product_name","name":"Red Hat JBoss Enterprise Application Platform 8","product":{"name":"Red Hat JBoss Enterprise Application Platform 8","product_id":"red_hat_jboss_enterprise_application_platform_8","product_identification_helper":{"cpe":"cpe:/a:redhat:jboss_enterprise_application_platform:8"}}}],"category":"product_family","name":"Red Hat JBoss Enterprise Application Platform 8"},{"branches":[{"category":"product_name","name":"Red Hat JBoss Enterprise Application Platform Expansion Pack","product":{"name":"Red Hat JBoss Enterprise Application Platform Expansion Pack","product_id":"red_hat_jboss_enterprise_application_platform_expansion_pack","product_identification_helper":{"cpe":"cpe:/a:redhat:jbosseapxp"}}}],"category":"product_family","name":"Red Hat JBoss Enterprise Application Platform Expansion Pack"},{"branches":[{"category":"product_name","name":"Streams for Apache Kafka 3.2.1","product":{"name":"Streams for Apache Kafka 3.2.1","product_id":"Streams for Apache Kafka 3.2.1","product_identification_helper":{"cpe":"cpe:/a:redhat:amq_streams:3.2::el9"}}}],"category":"product_family","name":"Red Hat OpenShift Enterprise"},{"branches":[{"category":"product_name","name":"Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16","product":{"name":"Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16","product_id":"Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16","product_identification_helper":{"cpe":"cpe:/a:redhat:apache_camel_spring_boot:4.18"}}}],"category":"product_family","name":"Red Hat Build of Apache Camel"},{"branches":[{"category":"product_name","name":"Red Hat Data Grid 8.6.1","product":{"name":"Red Hat Data Grid 8.6.1","product_id":"Red Hat Data Grid 8.6.1","product_identification_helper":{"cpe":"cpe:/a:redhat:jboss_data_grid:8"}}}],"category":"product_family","name":"Red Hat JBoss Data Grid"},{"branches":[{"category":"product_name","name":"Red Hat Offline Knowledge Portal 1.2.6","product":{"name":"Red Hat Offline Knowledge Portal 1.2.6","product_id":"Red Hat Offline Knowledge Portal 1.2.6","product_identification_helper":{"cpe":"cpe:/a:redhat:offline_knowledge_portal:1.2::el9"}}}],"category":"product_family","name":"Red Hat Offline Knowledge Portal"},{"category":"product_version","name":"log4j-layout-template-json","product":{"name":"log4j-layout-template-json","product_id":"log4j-layout-template-json","product_identification_helper":{"purl":"pkg:maven/org.apache.logging.log4j/log4j-layout-template-json"}}},{"category":"product_version","name":"log4j-web","product":{"name":"log4j-web","product_id":"log4j-web","product_identification_helper":{"purl":"pkg:rpm/redhat/log4j-web?rpmmod=log4j:2"}}},{"category":"product_version","name":"log4j-slf4j","product":{"name":"log4j-slf4j","product_id":"log4j-slf4j","product_identification_helper":{"purl":"pkg:rpm/redhat/log4j-slf4j?rpmmod=log4j:2"}}},{"category":"product_version","name":"log4j","product":{"name":"log4j","product_id":"log4j","product_identification_helper":{"purl":"pkg:rpm/redhat/log4j?rpmmod=log4j:2"}}},{"category":"product_version","name":"log4j-jcl","product":{"name":"log4j-jcl","product_id":"log4j-jcl","product_identification_helper":{"purl":"pkg:rpm/redhat/log4j-jcl?rpmmod=log4j:2"}}},{"category":"product_version","name":"log4j.src","product":{"name":"log4j.src","product_id":"log4j.src","product_identification_helper":{"purl":"pkg:rpm/redhat/log4j?arch=src"}}},{"branches":[{"category":"product_version","name":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64","product":{"name":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64","product_id":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64","product_identification_helper":{"purl":"pkg:oci/rhokp-rhel9@sha256%3Aec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36?arch=amd64&repository_url=registry.redhat.io/offline-knowledge-portal/rhokp-rhel9&tag=1779996999"}}}],"category":"architecture","name":"amd64"},{"branches":[{"category":"product_version","name":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64","product":{"name":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64","product_id":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64","product_identification_helper":{"purl":"pkg:oci/rhokp-rhel9@sha256%3Ab26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e?arch=arm64&repository_url=registry.redhat.io/offline-knowledge-portal/rhokp-rhel9&tag=1779996999"}}}],"category":"architecture","name":"arm64"}],"category":"vendor","name":"Red Hat"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64 as a component of Red Hat Offline Knowledge Portal 1.2.6","product_id":"Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64"},"product_reference":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64","relates_to_product_reference":"Red Hat Offline Knowledge Portal 1.2.6"},{"category":"default_component_of","full_product_name":{"name":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64 as a component of Red Hat Offline Knowledge Portal 1.2.6","product_id":"Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64"},"product_reference":"registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64","relates_to_product_reference":"Red Hat Offline Knowledge Portal 1.2.6"},{"category":"default_component_of","full_product_name":{"name":"log4j-layout-template-json as a component of Red Hat AMQ Broker 7","product_id":"red_hat_amq_broker_7:log4j-layout-template-json"},"product_reference":"log4j-layout-template-json","relates_to_product_reference":"red_hat_amq_broker_7"},{"category":"default_component_of","full_product_name":{"name":"log4j as a component of Red Hat Enterprise Linux 8","product_id":"red_hat_enterprise_linux_8:log4j"},"product_reference":"log4j","relates_to_product_reference":"red_hat_enterprise_linux_8"},{"category":"default_component_of","full_product_name":{"name":"log4j-jcl as a component of Red Hat Enterprise Linux 8","product_id":"red_hat_enterprise_linux_8:log4j-jcl"},"product_reference":"log4j-jcl","relates_to_product_reference":"red_hat_enterprise_linux_8"},{"category":"default_component_of","full_product_name":{"name":"log4j-slf4j as a component of Red Hat Enterprise Linux 8","product_id":"red_hat_enterprise_linux_8:log4j-slf4j"},"product_reference":"log4j-slf4j","relates_to_product_reference":"red_hat_enterprise_linux_8"},{"category":"default_component_of","full_product_name":{"name":"log4j-web as a component of Red Hat Enterprise Linux 8","product_id":"red_hat_enterprise_linux_8:log4j-web"},"product_reference":"log4j-web","relates_to_product_reference":"red_hat_enterprise_linux_8"},{"category":"default_component_of","full_product_name":{"name":"log4j-jcl as a component of Red Hat Enterprise Linux 9","product_id":"red_hat_enterprise_linux_9:log4j-jcl"},"product_reference":"log4j-jcl","relates_to_product_reference":"red_hat_enterprise_linux_9"},{"category":"default_component_of","full_product_name":{"name":"log4j-slf4j as a component of Red Hat Enterprise Linux 9","product_id":"red_hat_enterprise_linux_9:log4j-slf4j"},"product_reference":"log4j-slf4j","relates_to_product_reference":"red_hat_enterprise_linux_9"},{"category":"default_component_of","full_product_name":{"name":"log4j.src as a component of Red Hat Enterprise Linux 9","product_id":"red_hat_enterprise_linux_9:log4j.src"},"product_reference":"log4j.src","relates_to_product_reference":"red_hat_enterprise_linux_9"},{"category":"default_component_of","full_product_name":{"name":"log4j-layout-template-json as a component of Red Hat JBoss Enterprise Application Platform 7","product_id":"red_hat_jboss_enterprise_application_platform_7:log4j-layout-template-json"},"product_reference":"log4j-layout-template-json","relates_to_product_reference":"red_hat_jboss_enterprise_application_platform_7"},{"category":"default_component_of","full_product_name":{"name":"log4j-layout-template-json as a component of Red Hat JBoss Enterprise Application Platform 8","product_id":"red_hat_jboss_enterprise_application_platform_8:log4j-layout-template-json"},"product_reference":"log4j-layout-template-json","relates_to_product_reference":"red_hat_jboss_enterprise_application_platform_8"},{"category":"default_component_of","full_product_name":{"name":"log4j-layout-template-json as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack","product_id":"red_hat_jboss_enterprise_application_platform_expansion_pack:log4j-layout-template-json"},"product_reference":"log4j-layout-template-json","relates_to_product_reference":"red_hat_jboss_enterprise_application_platform_expansion_pack"}]},"vulnerabilities":[{"cve":"CVE-2026-34481","cwe":{"id":"CWE-241","name":"Improper Handling of Unexpected Data Type"},"discovery_date":"2026-04-10T16:01:44.581898+00:00","flags":[{"label":"vulnerable_code_not_present","product_ids":["red_hat_enterprise_linux_8:log4j","red_hat_enterprise_linux_8:log4j-jcl","red_hat_enterprise_linux_8:log4j-slf4j","red_hat_enterprise_linux_8:log4j-web","red_hat_jboss_enterprise_application_platform_8:log4j-layout-template-json","red_hat_jboss_enterprise_application_platform_expansion_pack:log4j-layout-template-json"]}],"ids":[{"system_name":"Red Hat Bugzilla ID","text":"2457321"}],"notes":[{"category":"description","text":"A flaw was found in Apache Log4j's JsonTemplateLayout. This vulnerability allows a remote attacker to disrupt log processing systems. By sending log events that include specific non-numeric floating-point values, the attacker can cause the JsonTemplateLayout to generate invalid JSON output. This invalid output can then lead to downstream systems rejecting or failing to index these logs, effectively causing a denial of service for log analysis.","title":"Vulnerability description"},{"category":"summary","text":"org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output","title":"Vulnerability summary"},{"category":"other","text":"Exploitation of this flaw requires an application to be configured with JsonTemplateLayout and to log attacker-controlled non-finite floating-point values within a MapMessage, which is not a default or common configuration in Red Hat products.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["Red Hat Data Grid 8.6.1","Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64","Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64","Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16","Streams for Apache Kafka 3.2.1"],"known_affected":["red_hat_amq_broker_7:log4j-layout-template-json","red_hat_enterprise_linux_9:log4j-jcl","red_hat_enterprise_linux_9:log4j-slf4j","red_hat_enterprise_linux_9:log4j.src","red_hat_jboss_enterprise_application_platform_7:log4j-layout-template-json"],"known_not_affected":["red_hat_enterprise_linux_8:log4j","red_hat_enterprise_linux_8:log4j-jcl","red_hat_enterprise_linux_8:log4j-slf4j","red_hat_enterprise_linux_8:log4j-web","red_hat_jboss_enterprise_application_platform_8:log4j-layout-template-json","red_hat_jboss_enterprise_application_platform_expansion_pack:log4j-layout-template-json"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-34481"},{"category":"external","summary":"RHBZ#2457321","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2457321"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-34481","url":"https://www.cve.org/CVERecord?id=CVE-2026-34481"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-34481","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34481"},{"category":"external","summary":"https://github.com/apache/logging-log4j2/pull/4080","url":"https://github.com/apache/logging-log4j2/pull/4080"},{"category":"external","summary":"https://lists.apache.org/thread/n34zdv00gbkdbzt2rx9rf5mqz6lhopcv","url":"https://lists.apache.org/thread/n34zdv00gbkdbzt2rx9rf5mqz6lhopcv"},{"category":"external","summary":"https://logging.apache.org/cyclonedx/vdr.xml","url":"https://logging.apache.org/cyclonedx/vdr.xml"},{"category":"external","summary":"https://logging.apache.org/log4j/2.x/manual/json-template-layout.html","url":"https://logging.apache.org/log4j/2.x/manual/json-template-layout.html"},{"category":"external","summary":"https://logging.apache.org/security.html#CVE-2026-34481","url":"https://logging.apache.org/security.html#CVE-2026-34481"}],"release_date":"2026-04-10T15:43:00.100000+00:00","remediations":[{"category":"vendor_fix","date":"2026-06-02T17:41:02+00:00","details":"Before applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to: https://access.redhat.com/articles/11258","product_ids":["Red Hat Data Grid 8.6.1"],"url":"https://access.redhat.com/errata/RHSA-2026:22619"},{"category":"vendor_fix","date":"2026-05-28T22:46:23+00:00","details":"The container image provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the \"podman pull\" command.","product_ids":["Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64","Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64"],"url":"https://access.redhat.com/errata/RHSA-2026:21773"},{"category":"vendor_fix","date":"2026-07-09T15:29:15+00:00","details":"Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16"],"url":"https://access.redhat.com/errata/RHSA-2026:37390"},{"category":"vendor_fix","date":"2026-08-12T19:35:14+00:00","details":"Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["Streams for Apache Kafka 3.2.1"],"url":"https://access.redhat.com/errata/RHSA-2026:54435"},{"category":"workaround","details":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.","product_ids":["Red Hat Data Grid 8.6.1","Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64","Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64","Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16","Streams for Apache Kafka 3.2.1","red_hat_amq_broker_7:log4j-layout-template-json","red_hat_enterprise_linux_9:log4j-jcl","red_hat_enterprise_linux_9:log4j-slf4j","red_hat_enterprise_linux_9:log4j.src","red_hat_jboss_enterprise_application_platform_7:log4j-layout-template-json"]},{"category":"no_fix_planned","details":"Will not fix","product_ids":["red_hat_enterprise_linux_9:log4j-jcl","red_hat_enterprise_linux_9:log4j-slf4j","red_hat_enterprise_linux_9:log4j.src","red_hat_jboss_enterprise_application_platform_7:log4j-layout-template-json"]},{"category":"none_available","details":"Affected","product_ids":["red_hat_amq_broker_7:log4j-layout-template-json"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","version":"3.1"},"products":["Red Hat Data Grid 8.6.1","Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64","Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64","Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16","Streams for Apache Kafka 3.2.1","red_hat_amq_broker_7:log4j-layout-template-json","red_hat_enterprise_linux_8:log4j","red_hat_enterprise_linux_8:log4j-jcl","red_hat_enterprise_linux_8:log4j-slf4j","red_hat_enterprise_linux_8:log4j-web","red_hat_enterprise_linux_9:log4j-jcl","red_hat_enterprise_linux_9:log4j-slf4j","red_hat_enterprise_linux_9:log4j.src","red_hat_jboss_enterprise_application_platform_7:log4j-layout-template-json","red_hat_jboss_enterprise_application_platform_8:log4j-layout-template-json","red_hat_jboss_enterprise_application_platform_expansion_pack:log4j-layout-template-json"]}],"threats":[{"category":"impact","details":"Moderate","product_ids":["Red Hat Data Grid 8.6.1","Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:b26253f0a6c6b9e8c8458ecb07e79e9f87ff313491fffc31e342e32bce0a2b3e_arm64","Red Hat Offline Knowledge Portal 1.2.6:registry.redhat.io/offline-knowledge-portal/rhokp-rhel9@sha256:ec8b14b7a170b689a19cee7820888e81ddc3affc2faada6cc6139644f328bd36_amd64","Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16","Streams for Apache Kafka 3.2.1","red_hat_amq_broker_7:log4j-layout-template-json","red_hat_enterprise_linux_8:log4j","red_hat_enterprise_linux_8:log4j-jcl","red_hat_enterprise_linux_8:log4j-slf4j","red_hat_enterprise_linux_8:log4j-web","red_hat_enterprise_linux_9:log4j-jcl","red_hat_enterprise_linux_9:log4j-slf4j","red_hat_enterprise_linux_9:log4j.src","red_hat_jboss_enterprise_application_platform_7:log4j-layout-template-json","red_hat_jboss_enterprise_application_platform_8:log4j-layout-template-json","red_hat_jboss_enterprise_application_platform_expansion_pack:log4j-layout-template-json"]}],"title":"org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output"}]}