Skip to main content
FOSSA Logo
Skip to package details

org.apache.logging.log4j:log4j-core

Maven3.6k GitHub stars

v3.0.0-beta3 · Nov 2024 · Apache-2.0 (top-level declared license)

Install format
<dependency>
  <groupId>org.apache.logging.log4j</groupId>
  <artifactId>log4j-core</artifactId>
  <version>3.0.0-beta3</version>
</dependency>
implementation("org.apache.logging.log4j:log4j-core:3.0.0-beta3")
  • 3 known CVEs (0 in v3.0.0-beta3)
  • 239 known dependents
  • 3.6k
  • 78 versions

Description

Apache Log4j is a versatile, feature-rich, efficient logging API and backend for Java.

License exposure

This package's dependency tree includes LGPL-2.1-only, which may require you to publish changes to that component when you distribute.

This view is derived from declared package metadata, and a full FOSSA scan detects licenses that declared metadata misses. Scan free.

License and vulnerability information on this page is derived from public package metadata and public advisory databases. It is not legal advice, and it reflects the top-level declared license only. Verify the license and terms of any software for your own needs.

Need org.apache.logging.log4j:log4j-core approved? Get the full license and vulnerability report for your codebase. Scan free.

Scan free

Vulnerabilities

CVE-linked advisories
Affected rangeCVECWECVSSEPSS
>=2.0-alpha1 <2.25.4CVE-2026-34480CWE-1160.00972
>=2.21.0 <2.25.4CVE-2026-34478CWE-117, CWE-6840.00972
>=2.12.0 <2.25.4CVE-2026-34477CWE-2970.00410

Remediation

Fix versions
CVEIssueImpactedFixed in
CVE-2026-34480Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters>=2.0-alpha1 <2.25.42.25.4
CVE-2026-34478Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility>=2.21.0 <2.25.42.25.4
CVE-2026-34477Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration>=2.12.0 <2.25.42.25.4

Find and fix org.apache.logging.log4j:log4j-core issues across your dependencies.

Scan free

Version history

Published versions
VersionPublishedLicense
2.25.5Jul 2026
2.26.1Jun 2026
2.26.0May 2026
2.25.4Mar 2026
2.25.3Dec 2025
2.25.2Sep 2025
2.25.1Jul 2025
2.25.0Jun 2025
2.24.3Dec 2024
2.24.2Nov 2024
3.0.0-beta3Nov 2024
2.24.1Sep 2024
2.24.0Sep 2024
2.23.1Mar 2024
3.0.0-beta2Feb 2024
2.23.0Feb 2024
2.22.1Dec 2023
3.0.0-beta1Dec 2023
2.22.0Nov 2023
2.21.1Oct 2023

Dependencies

  • biz.aQute.bnd:biz.aQute.bnd.annotation
  • com.github.spotbugs:spotbugs-annotations
  • com.google.errorprone:error_prone_annotations
  • org.apache.logging.log4j:log4j-api
  • org.apache.logging.log4j:log4j-kit
  • org.apache.logging.log4j:log4j-plugins
  • org.jspecify:jspecify
  • org.osgi:org.osgi.annotation.bundle
  • org.osgi:org.osgi.framework
  • org.osgi:osgi.annotation

Dependents

  • org.springframework.boot:spring-boot-starter-log4j2
  • com.alibaba:druid
  • org.apache.logging.log4j:log4j-slf4j-impl
  • org.elasticsearch:elasticsearch
  • org.apache.logging.log4j:log4j-web

These edges are declared in package metadata. FOSSA’s build-replication scan can resolve a different graph.

Popularity

  • 239 known dependents in this corpus
  • 3.6k GitHub stars
  • OpenSSF score 9

FAQ

What is the latest version of org.apache.logging.log4j:log4j-core?
The latest version of org.apache.logging.log4j:log4j-core is 3.0.0-beta3, published November 2024.
What license is org.apache.logging.log4j:log4j-core under?
org.apache.logging.log4j:log4j-core declares Apache-2.0 as its top-level declared license. Its dependency tree spans 3 distinct licenses.
Does org.apache.logging.log4j:log4j-core have known vulnerabilities?
org.apache.logging.log4j:log4j-core has 3 known CVE-linked advisories across its published versions; 0 affect the latest version, v3.0.0-beta3.
How do I install org.apache.logging.log4j:log4j-core?
Add org.apache.logging.log4j:log4j-core to your pom.xml as a dependency on org.apache.logging.log4j:log4j-core:3.0.0-beta3.
How do I generate an SBOM that includes org.apache.logging.log4j:log4j-core?
FOSSA's SBOM generator produces SPDX or CycloneDX output for a codebase that includes org.apache.logging.log4j:log4j-core. Generate an SPDX or CycloneDX SBOM free.

Dependency graph and package metadata from deps.dev (Google Open Source Insights), used under CC BY 4.0.

Vulnerability data from the Open Source Vulnerability (OSV) database, including the GitHub Advisory Database and the PyPI Advisory Database, used under CC BY 4.0. Only CVE-linked advisories are shown.

EPSS scores from the Exploit Prediction Scoring System, maintained by the EPSS Special Interest Group at FIRST.

Repository stars from the GitHub API.

OpenSSF Scorecard results from deps.dev.

License and vulnerability information on this page is derived from public package metadata and public advisory databases. It is not legal advice, and it reflects the top-level declared license only. Verify the license and terms of any software for your own needs.