org.apache.logging.log4j:log4j-core
Maven11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.logging.log4j:log4j-corepage 1 of 1
- CVE-2017-5645CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.8.22017-04-17
vulnerable: 2.0 ... 2.8.1 (17 versions)
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrar…
- CVE-2020-9488LOWCVSS 3.7EG 3.7✓ Fixed in 2.3.22020-04-27
vulnerable: 2.0 ... 2.3.1 (20 versions)
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed i…
- CVE-2021-44228CRITICALCVSS 10.0EG 10.0⚠ KEV✓ Fixed in 2.12.22021-12-10
vulnerable: 2.10.0 ... 2.9.1 (18 versions)
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoin…
- CVE-2021-44832MEDIUMCVSS 6.6EG 6.6✓ Fixed in 2.17.12021-12-28
vulnerable: 2.13.0 ... 2.17.0 (9 versions)
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an at…
- CVE-2021-45046CRITICALCVSS 9.0EG 9.0⚠ KEV✓ Fixed in 2.12.22021-12-14
vulnerable: 2.0 ... 2.9.1 (39 versions)
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configurati…
- CVE-2021-45105MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2.3.12021-12-18
vulnerable: 2.0 ... 2.3 (19 versions)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of…
- CVE-2023-26464HIGHCVSS 7.5EG 7.5✓ Fixed in 2.02023-03-10
vulnerable: 2.0-alpha1 ... 2.0-rc2 (13 versions)
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hash…
- CVE-2025-68161MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2.25.32025-12-18
vulnerable: 2.0 ... 2.9.1 (59 versions)
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html…
- CVE-2026-34477MEDIUMCVSS 5.9EG 5.92026-04-10
vulnerable: 3.0.0-alpha1, 3.0.0-beta1, 3.0.0-beta2, 3.0.0-beta3
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemp…
- CVE-2026-34478HIGHCVSS 7.5EG 7.52026-04-10
vulnerable: 3.0.0-beta1, 3.0.0-beta2, 3.0.0-beta3
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-releva…
- CVE-2026-34480HIGHCVSS 7.5EG 7.52026-04-10
vulnerable: 3.0.0-alpha1, 3.0.0-beta1, 3.0.0-beta2, 3.0.0-beta3
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#cha…
Check whether org.apache.logging.log4j:log4j-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.logging.log4j:log4j-core CVEs against the assets you own.
Start Free Scan →