org.apache.logging.log4j:log4j-core
Maven3.6k GitHub starsv3.0.0-beta3 · Nov 2024 · Apache-2.0 (top-level declared license)
- 3 known CVEs (0 in v3.0.0-beta3)
- 239 known dependents
- ★ 3.6k
- 78 versions
Description
Apache Log4j is a versatile, feature-rich, efficient logging API and backend for Java.
License exposure
This package's dependency tree includes LGPL-2.1-only, which may require you to publish changes to that component when you distribute.
This view is derived from declared package metadata, and a full FOSSA scan detects licenses that declared metadata misses. Scan free.
License and vulnerability information on this page is derived from public package metadata and public advisory databases. It is not legal advice, and it reflects the top-level declared license only. Verify the license and terms of any software for your own needs.
Need org.apache.logging.log4j:log4j-core approved? Get the full license and vulnerability report for your codebase. Scan free.
Scan freeVulnerabilities
| Affected range | CVE | CWE | CVSS | EPSS |
|---|---|---|---|---|
| >=2.0-alpha1 <2.25.4 | CVE-2026-34480 | CWE-116 | 0.00972 | |
| >=2.21.0 <2.25.4 | CVE-2026-34478 | CWE-117, CWE-684 | 0.00972 | |
| >=2.12.0 <2.25.4 | CVE-2026-34477 | CWE-297 | 0.00410 |
Remediation
| CVE | Issue | Impacted | Fixed in |
|---|---|---|---|
| CVE-2026-34480 | Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters | >=2.0-alpha1 <2.25.4 | 2.25.4 |
| CVE-2026-34478 | Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility | >=2.21.0 <2.25.4 | 2.25.4 |
| CVE-2026-34477 | Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration | >=2.12.0 <2.25.4 | 2.25.4 |
Find and fix org.apache.logging.log4j:log4j-core issues across your dependencies.
Scan freeVersion history
| Version | Published | License |
|---|---|---|
| 2.25.5 | Jul 2026 | |
| 2.26.1 | Jun 2026 | |
| 2.26.0 | May 2026 | |
| 2.25.4 | Mar 2026 | |
| 2.25.3 | Dec 2025 | |
| 2.25.2 | Sep 2025 | |
| 2.25.1 | Jul 2025 | |
| 2.25.0 | Jun 2025 | |
| 2.24.3 | Dec 2024 | |
| 2.24.2 | Nov 2024 | |
| 3.0.0-beta3 | Nov 2024 | |
| 2.24.1 | Sep 2024 | |
| 2.24.0 | Sep 2024 | |
| 2.23.1 | Mar 2024 | |
| 3.0.0-beta2 | Feb 2024 | |
| 2.23.0 | Feb 2024 | |
| 2.22.1 | Dec 2023 | |
| 3.0.0-beta1 | Dec 2023 | |
| 2.22.0 | Nov 2023 | |
| 2.21.1 | Oct 2023 |
Dependencies
- biz.aQute.bnd:biz.aQute.bnd.annotation
- com.github.spotbugs:spotbugs-annotations
- com.google.errorprone:error_prone_annotations
- org.apache.logging.log4j:log4j-api
- org.apache.logging.log4j:log4j-kit
- org.apache.logging.log4j:log4j-plugins
- org.jspecify:jspecify
- org.osgi:org.osgi.annotation.bundle
- org.osgi:org.osgi.framework
- org.osgi:osgi.annotation
Dependents
- org.springframework.boot:spring-boot-starter-log4j2
- com.alibaba:druid
- org.apache.logging.log4j:log4j-slf4j-impl
- org.elasticsearch:elasticsearch
- org.apache.logging.log4j:log4j-web
These edges are declared in package metadata. FOSSA’s build-replication scan can resolve a different graph.
Popularity
- 239 known dependents in this corpus
- 3.6k GitHub stars
- OpenSSF score 9
FAQ
- What is the latest version of org.apache.logging.log4j:log4j-core?
- The latest version of org.apache.logging.log4j:log4j-core is 3.0.0-beta3, published November 2024.
- What license is org.apache.logging.log4j:log4j-core under?
- org.apache.logging.log4j:log4j-core declares Apache-2.0 as its top-level declared license. Its dependency tree spans 3 distinct licenses.
- Does org.apache.logging.log4j:log4j-core have known vulnerabilities?
- org.apache.logging.log4j:log4j-core has 3 known CVE-linked advisories across its published versions; 0 affect the latest version, v3.0.0-beta3.
- How do I install org.apache.logging.log4j:log4j-core?
- Add org.apache.logging.log4j:log4j-core to your pom.xml as a dependency on org.apache.logging.log4j:log4j-core:3.0.0-beta3.
- How do I generate an SBOM that includes org.apache.logging.log4j:log4j-core?
- FOSSA's SBOM generator produces SPDX or CycloneDX output for a codebase that includes org.apache.logging.log4j:log4j-core. Generate an SPDX or CycloneDX SBOM free.