VendorsApachelog4jall versions
Vulnerabilities

Apache Software Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2017-5645
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Published 2017-04-17 · Modified
9.8EPSS 0.898
CVE-2019-17571
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
Published 2019-12-20 · Modified
9.8EPSS 0.691
CVE-2022-23305
SQL injection in JDBC Appender in Apache Log4j V1
Published 2022-01-18 · Modified
9.8EPSS 0.665
CVE-2020-9493
Java deserialization in Chainsaw
Published 2021-06-16 · Modified
9.8EPSS 0.046
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Published 2021-12-14 · Analyzed
9.0KEVEPSS 1.000
CVE-2022-23307
A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.
Published 2022-01-18 · Modified
9.0EPSS 0.544
CVE-2022-23302
Deserialization of untrusted data in JMSSink in Apache Log4j 1.x
Published 2022-01-18 · Modified
8.8EPSS 0.636
CVE-2021-44832
Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration
Published 2021-12-28 · Modified
8.5EPSS 0.979
CVE-2021-4104
Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2
Published 2021-12-14 · Modified
7.5EPSS 0.806
CVE-2023-26464
Apache Log4j 1.x (EOL) allows DoS in Chainsaw and SocketAppender
Published 2023-03-10 · Modified
7.5EPSS 0.019
CVE-2026-34478
Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
Published 2026-04-10 · Analyzed
7.5EPSS 0.012
CVE-2026-34480
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Published 2026-04-10 · Analyzed
7.5EPSS 0.012
CVE-2026-34479
Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
Published 2026-04-10 · Analyzed
7.5EPSS 0.009
CVE-2026-34481
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
Published 2026-04-10 · Modified
7.5EPSS 0.009
CVE-2026-49844
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Published 2026-07-10 · Analyzed
6.3EPSS 0.008
CVE-2025-68161
Apache Log4j Core: Missing TLS hostname verification in Socket appender
Published 2025-12-18 · Modified
6.3EPSS 0.008
CVE-2026-34477
Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
Published 2026-04-10 · Analyzed
6.3EPSS 0.005
CVE-2021-45105
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Published 2021-12-18 · Modified
5.9EPSS 1.000
CVE-2020-9488
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Published 2020-04-27 · Modified
4.3EPSS 0.081