Strip CR/LF from SMTP subjects derived from event data - #4258
Open
shaggyinsomniac wants to merge 1 commit into
Open
Strip CR/LF from SMTP subjects derived from event data#4258shaggyinsomniac wants to merge 1 commit into
shaggyinsomniac wants to merge 1 commit into
Conversation
The SmtpAppender subject is produced by a PatternLayout serializer and commonly embeds event data (message, MDC, throwable). CR/LF sequences in that data flow into MimeMessage.setSubject unsanitized, allowing mail header injection when an attacker can influence logged content (for example a 'Bcc' header relayed through the application's SMTP credentials). Strip CR and LF from subjects in MimeMessageBuilder.setSubject and in the SmtpManager multipart send paths of both the javax (log4j-core) and jakarta (log4j-jakarta-smtp) modules. Signed-off-by: Sagar Chanchal <Sagarr2112@gmail.com>
shaggyinsomniac
force-pushed
the
smtp-subject-crlf
branch
from
August 27, 2026 13:11
fb66599 to
70f6220
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The
SmtpAppendersubject is produced by a PatternLayout serializer and commonly embeds event data (message, MDC, throwable). CR/LF sequences in that data currently flow intoMimeMessage.setSubjectunsanitized, allowing mail header injection when an attacker can influence logged content — for example a logged username or error message containing\r\nBcc: attacker@example.comresults in an injectedBccheader relayed through the application's SMTP credentials.This strips CR and LF from the subject in:
MimeMessageBuilder.setSubject(log4j-coreandlog4j-jakarta-smtp)SmtpManagervariantsTesting
MimeMessageBuilderTest(new): asserts a plain subject round-trips unchanged, and a subject containing CRLF has all CR/LF removed (making the remainder inert text within the single subject value). Both pass; no other behavior changes.