VYPR

Maven package

org.apache.logging.log4j/log4j-core

pkg:maven/org.apache.logging.log4j/log4j-core

Vulnerabilities (11)

  • CVE-2026-34480HigApr 10, 2026
    affected >= 2.0-alpha1, < 2.25.4fixed 2.25.4

    Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whene

  • CVE-2026-34478HigApr 10, 2026
    affected >= 2.21.0, < 2.25.4fixed 2.25.4

    Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes. Two distinc

  • CVE-2026-34477MedApr 10, 2026
    affected >= 2.12.0, < 2.25.4fixed 2.25.4

    The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName

  • CVE-2025-68161Dec 18, 2025
    affected >= 2.0-beta9, < 2.25.3fixed 2.25.3

    The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName co

  • CVE-2023-26464Mar 10, 2023
    affected >= 1.0.4, < 2.0fixed 2.0

    ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging compone

  • CVE-2021-44832Dec 28, 2021
    affected >= 2.0-beta7, < 2.3.2fixed 2.3.2

    Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP ser

  • CVE-2021-45105Dec 18, 2021
    affected >= 2.4.0, < 2.12.3fixed 2.12.3

    Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpr

  • CVE-2021-45046KEVDec 14, 2021
    affected >= 2.13.0, < 2.16.0fixed 2.16.0

    It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with

  • CVE-2021-44228KEVDec 10, 2021
    affected >= 2.13.0, < 2.15.0fixed 2.15.0

    Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messa

  • CVE-2020-9488Apr 27, 2020
    affected >= 2.13.0, < 2.13.2fixed 2.13.2

    Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

  • CVE-2017-5645CriApr 17, 2017
    affected >= 2.0, < 2.8.2fixed 2.8.2

    In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.