Product overview
Apache Log4j is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Application development components
- Versioned runtime or build interfaces
- Security and compatibility maintenance
Typical use
Used by software teams to build, run or maintain applications.
Deployment
Included in source projects, application dependencies, build systems or managed runtimes.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page ↗.
Collected lifecycle data
| Product | Apache Log4j |
|---|
| Release | Lifecycle policy |
|---|
| Start or release | Not extracted |
|---|
| Lifecycle boundary | Continuous or not dated in the source |
|---|
| Date precision | Unknown |
|---|
Known exploited vulnerabilities
Catalogue updated 2 Oct 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Apache · Log4j2Ransomware use: Known
CISA entry ↗Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
Apache · Log4j2Ransomware use: Known
CISA entry ↗
Package vulnerability advisories
Checked 1 Oct 2026OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
Incomplete fix for Apache Log4j vulnerability
pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.16.0, 2.12.2
OSV record ↗Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.12.3, 2.17.0, 2.3.1
OSV record ↗Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration
pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.25.4
OSV record ↗Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.25.4
OSV record ↗Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.25.4
OSV record ↗Apache Log4j does not verify the TLS hostname in its Socket Appender
pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.25.3
OSV record ↗Improper Input Validation and Injection in Apache Log4j2
pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.3.2, 2.12.4, 2.17.1
OSV record ↗Improper validation of certificate with host mismatch in Apache Log4j SMTP appender
pkg:maven/org.apache.logging.log4j/log4j-coreFixed: 2.13.2, 2.12.3, 2.3.2
OSV record ↗
Source evidence
PRIMARYManual
Apache Log4j official lifecycle source
Log4cxx, Log4j and Log4net must prevent log injection in structured layouts, such as the XML, JSON, RFC 5424, and HTML layouts, when they are consumed by a passive sink; see Passive and active sinks . | Apache Logging Services projects do check the quality of our dependencies. | Apache Logging Services projects do check the quality of our dependencies. | Deprecated components such as the Cassandra , Kafka and CouchDB appenders are provided for backward compatibility purposes only. While we actively check for vulnerabilities in those components, they are de facto unmaintained, and we discourage their usage in production. | Deprecated components such as the Cassandra , Kafka and CouchDB appenders are provided for backward compatibility purposes only. While we actively check for vulnerabilities in those components, they are de facto unmaintained, and we discourage their usage in production. | All Apache Logging Services are signed with one of the keys in the Logging Services PMC KEYS file . We do not support artifacts that do not have a valid signature, and we encourage users to always check the integrity of the downloaded components. Additional information on how to verify releases signatures is available on the Download page | All Apache Logging Services are signed with one of the keys in the Logging Services PMC KEYS file . We do not support artifacts that do not have a valid signature, and we encourage users to always check the integrity of the downloaded components. Additional information on how to verify releases signatures is available on the Download page
Publisher identity used by product-specific official-source collectors.
First collected 12 Sep 2026 · Last collected 23 Sep 2026 · Review state accepted
Open official vendor source ↗