Re: [D] Threat model: how should Thread Context (MDC) keys be classified (trusted structural or untrusted content) ? [logging-log4j2]

FreeAndNil (via GitHub) <[email protected]> Sun, 31 May 2026 21:03:21 -0000
Newsgroups gmane.comp.jakarta.log4j.devel
Message-ID <ghd-D_kwDOAKJSSM4AmyP1-56a66ef3-2248-48fc-9775-70fc62771389@gitbox.apache.org>
GitHub user FreeAndNil added a comment to the discussion: Threat model: how should Thread Context (MDC) keys be classified (trusted structural or untrusted content)?

If keys are trusted, the framework may reject a malformed key by throwing rather than sanitizing it, and does not need to escape special characters in keys in structured layouts. Key-based injection would be out of scope, with "do not populate keys from untrusted input" becoming a documented developer responsibility.

GitHub link: https://github.com/apache/logging-log4j2/discussions/4132#discussioncomment-17126244

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]