CVE-2026-34477: Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
Overview
- Severity
- N/A
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2026-Apr
- Released
- 2026-04-13
- Last Updated
- 2026-04-13
- EPSS Score
- 0.11% (percentile: 29.1%)
Affected Products (1)
Other
Revision History
- 2026-04-13: Information published.
- 2026-04-13: Information published.