Vulnerability GHSA-6hg6-v5c8-fphq

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 months ago
April 10, 2026 at 06:31 PM UTC
Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration
2.14.0 - 2.16.0 and 2.18.0 - 3.0.0
2.14.0 - 2.16.0 and 2.18.0 - 3.0.0

Summary

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

Details

The fix for CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName attribute of the <Ssl> element.

Although the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value.

A network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met:

  • An SMTP, Socket, or Syslog appender is in use.
  • TLS is configured via a nested element.
  • The attacker can present a certificate issued by a CA trusted by the appender's configured trust store, or by the default Java trust store if none is configured.

This issue does not affect users of the HTTP appender, which uses a separate verifyHostname attribute that was not subject to this bug and verifies host names by default.

Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
5 months ago
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
2.1.0 - 2.2.0 and 2.4.0 - 2.5.0 and 2.7.0 and 2.9.0 - 2.10.0 and 2.14.0 - 2.16.0 and 2.18.0 - 3.0.0 GHSA-3pxv-7cmr-fjr4
2.1.0 - 2.2.0 and 2.4.0 - 2.5.0 and 2.7.0 and 2.9.0 - 2.10.0 and 2.14.0 - 2.16.0 and 2.18.0 - 3.0.0 GHSA-3pxv-7cmr-fjr4
Medium Risk
5 months ago
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
2.21.0 - 3.0.0 GHSA-445c-vh5m-36rj
2.21.0 - 3.0.0 GHSA-445c-vh5m-36rj
Medium Risk
9 months ago
Apache Log4j does not verify the TLS hostname in its Socket Appender
2.1.0 - 2.2.0 and 2.4.0 - 2.5.0 and 2.7.0 and 2.9.0 - 2.10.0 and 2.14.0 - 2.16.0 and 2.18.0 - 2.23.1 GHSA-vc5p-v9hr-52mj
2.1.0 - 2.2.0 and 2.4.0 - 2.5.0 and 2.7.0 and 2.9.0 - 2.10.0 and 2.14.0 - 2.16.0 and 2.18.0 - 2.23.1 GHSA-vc5p-v9hr-52mj
High Risk
3 years ago
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
==2.0-alpha1, ==2.0-alpha2, ==2.0-beta1, ==2.0-beta2, ==2.0-beta3, ==2.0-beta4, ==2.0-beta5, ==2.0-beta6, ==2.0-beta7, ==2.0-beta8, ==2.0-beta9, ==2.0-rc1, ==2.0-rc2 GHSA-vp98-w2p3-mv35
==2.0-alpha1, ==2.0-alpha2, ==2.0-beta1, ==2.0-beta2, ==2.0-beta3, ==2.0-beta4, ==2.0-beta5, ==2.0-beta6, ==2.0-beta7, ==2.0-beta8, ==2.0-beta9, ==2.0-rc1, ==2.0-rc2 GHSA-vp98-w2p3-mv35
Medium Risk
4 years ago
Improper Input Validation and Injection in Apache Log4j2
2.1.0 - 2.5.0 and 2.7.0 and 2.9.0 - 2.10.0 and 2.14.0 - 2.17.0 GHSA-8489-44mv-ggj8
2.1.0 - 2.5.0 and 2.7.0 and 2.9.0 - 2.10.0 and 2.14.0 - 2.17.0 GHSA-8489-44mv-ggj8
View all vulnerabilities for these packages

Timeline

Published
5 months ago
April 10, 2026 at 06:31 PM UTC
Fixed (2.25.4)
Unknown
Unknown
Last Modified
22 days ago
September 10, 2026 at 03:50 AM UTC