Improper Encoding or Escaping of Output Affecting kayenta-fips-2025.4 package, versions <2025.4.6-r6


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.57% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-KAYENTAFIPS20254-18800635
  • published15 Aug 2026
  • disclosed10 Jul 2026

Introduced: 10 Jul 2026

CVE-2026-49844  (opens in a new tab)
CWE-116  (opens in a new tab)

How to fix?

Upgrade Chainguard kayenta-fips-2025.4 to version 2025.4.6-r6 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kayenta-fips-2025.4 package and not the kayenta-fips-2025.4 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.

The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.

The defect is reachable only when both of the following conditions hold:

An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.

Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.

CVSS Base Scores

version 3.1