Apache / Log4j
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-49844 | Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson() | MEDIUM | 6.3 | Jul 10, 2026 |
| CVE-2026-34481 | Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout | MEDIUM | 6.3 | Apr 10, 2026 |
| CVE-2026-34480 | Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters | MEDIUM | 6.9 | Apr 10, 2026 |
| CVE-2026-34479 | Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters | MEDIUM | 6.9 | Apr 10, 2026 |
| CVE-2026-34478 | Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility | MEDIUM | 6.9 | Apr 10, 2026 |
| CVE-2026-34477 | Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass | MEDIUM | 6.3 | Apr 10, 2026 |
| CVE-2025-68161 | Apache Log4j Core: Missing TLS hostname verification in Socket appender | MEDIUM | 6.3 | Dec 18, 2025 |
| CVE-2023-26464 | Apache Log4j 1.x (EOL) allows DoS in Chainsaw and SocketAppender | HIGH | 7.5 | Mar 10, 2023 |
| CVE-2022-23307 | A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution. | CRITICAL | 9.8 | Jan 18, 2022 |
| CVE-2022-23305 | SQL injection in JDBC Appender in Apache Log4j V1 | CRITICAL | 9.8 | Jan 18, 2022 |
| CVE-2022-23302 | Deserialization of untrusted data in JMSSink in Apache Log4j 1.x | HIGH | 8.8 | Jan 18, 2022 |
| CVE-2021-44832 | Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration | MEDIUM | 6.6 | Dec 28, 2021 |
| CVE-2021-45105 | Apache Log4j2 does not always protect from infinite recursion in lookup evaluation | HIGH | 8.6 | Dec 18, 2021 |
| CVE-2021-45046 KEV | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack | CRITICAL | 9.0 | Dec 14, 2021 |
| CVE-2021-4104 | Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2 | HIGH | 7.5 | Dec 14, 2021 |
| CVE-2021-44228 KEV | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | CRITICAL | 10.0 | Dec 10, 2021 |
| CVE-2020-9493 | Java deserialization in Chainsaw | CRITICAL | 9.8 | Jun 16, 2021 |
| CVE-2020-9488 | log4j: improper validation of certificate with host mismatch in SMTP appender | LOW | 3.7 | Apr 27, 2020 |
| CVE-2019-17571 | log4j: deserialization of untrusted data in SocketServer | CRITICAL | 9.8 | Dec 20, 2019 |
| CVE-2017-5645 | log4j: Socket receiver deserialization vulnerability | CRITICAL | 9.8 | Apr 17, 2017 |
Showing 1 to 20 of 20 CVEs