
Tungsten Automation Knowledge
Log4J Vulnerability CVE-2026-49844 reported.
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.
Full details NVD-CVE-2026-49844
The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token.
Full details NVD-CVE-2026-49844
| Product | Version | Build | Environment | Hardware |
|---|---|---|---|---|
https://aio-eus-uat-cae-aif-app14-local.redglacier-35d7ee4f.eastus.azurecontainerapps.io/article/45921 | Article 000045921 | Printed Sep 30, 2026