Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 23 SEP 2026

Apache · AUTOMATIC DISCOVERY

Apache Log4j Lifecycle policy

Apache Log4j is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 82. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

This discovery does not establish a product-specific support or retirement date. A missing date does not mean support continues.

Product overview

Apache Log4j is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductApache Log4j
ReleaseLifecycle policy
Start or releaseNot extracted
Lifecycle boundaryContinuous or not dated in the source
Date precisionUnknown

Known exploited vulnerabilities

Catalogue updated 2 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2021-45046Added 1 May 2023

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

Apache · Log4j2Ransomware use: Known

CISA entry
CVE-2021-44228Added 10 Dec 2021

Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Apache · Log4j2Ransomware use: Known

CISA entry

Package vulnerability advisories

Checked 1 Oct 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2021-45046Critical severity

Incomplete fix for Apache Log4j vulnerability

pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.16.0, 2.12.2

OSV record
CVE-2021-45105High severity

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.12.3, 2.17.0, 2.3.1

OSV record
CVE-2026-34477Medium severity

Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration

pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.25.4

OSV record
CVE-2026-34478Medium severity

Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility

pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.25.4

OSV record
CVE-2026-34480Medium severity

Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters

pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.25.4

OSV record
CVE-2025-68161Medium severity

Apache Log4j does not verify the TLS hostname in its Socket Appender

pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.25.3

OSV record
CVE-2021-44832Medium severity

Improper Input Validation and Injection in Apache Log4j2

pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.3.2, 2.12.4, 2.17.1

OSV record
CVE-2020-9488Low severity

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.13.2, 2.12.3, 2.3.2

OSV record

Source evidence

PRIMARYManual

Apache Log4j official lifecycle source

Log4cxx, Log4j and Log4net must prevent log injection in structured layouts, such as the XML, JSON, RFC 5424, and HTML layouts, when they are consumed by a passive sink; see Passive and active sinks . | Apache Logging Services projects do check the quality of our dependencies. | Apache Logging Services projects do check the quality of our dependencies. | Deprecated components such as the Cassandra , Kafka and CouchDB appenders are provided for backward compatibility purposes only. While we actively check for vulnerabilities in those components, they are de facto unmaintained, and we discourage their usage in production. | Deprecated components such as the Cassandra , Kafka and CouchDB appenders are provided for backward compatibility purposes only. While we actively check for vulnerabilities in those components, they are de facto unmaintained, and we discourage their usage in production. | All Apache Logging Services are signed with one of the keys in the Logging Services PMC KEYS file . We do not support artifacts that do not have a valid signature, and we encourage users to always check the integrity of the downloaded components. Additional information on how to verify releases signatures is available on the Download page | All Apache Logging Services are signed with one of the keys in the Logging Services PMC KEYS file . We do not support artifacts that do not have a valid signature, and we encourage users to always check the integrity of the downloaded components. Additional information on how to verify releases signatures is available on the Download page

Publisher identity used by product-specific official-source collectors.

First collected 12 Sep 2026 · Last collected 23 Sep 2026 · Review state accepted

Open official vendor source