org.apache.logging.log4j Vulnerabilities
CVE security advisories and vulnerability history for org.apache.logging.log4j.
Overview
org.apache.logging.log4j has 13 published CVE records since 2017, of which 2 are in CISA's Known Exploited Vulnerabilities catalog and 2 have a known public exploit. The average CVSS base score across scored CVEs is 6.9.
This page aggregates every publicly disclosed vulnerability (CVE) affecting org.apache.logging.log4j products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.