CVE-2021-45105Medium· 5.9▾ Midnight0dayPoC availableApache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 32.5 · likelihood 20 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
100%
7 GitHub repos
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
log4j >= 2.0, < 2.3.1log4j >= 2.4, < 2.12.3log4j >= 2.13.0, <= 2.16.0cloud_managerdebian_linux = 10.0debian_linux = 11.0email_security <= 10.0.12network_security_manager >= 2.0, < 3.0web_application_firewall >= 3.0.0, < 3.1.06bk1602-0aa12-0tp0_firmware < 2.7.06bk1602-0aa22-0tp0_firmware < 2.7.06bk1602-0aa32-0tp0_firmware < 2.7.06bk1602-0aa42-0tp0_firmware < 2.7.06bk1602-0aa52-0tp0_firmware < 2.7.0agile_engineering_data_management = 6.2.1.0agile_plm_mcad_connector = 3.6agile_product_lifecycle_management = 9.3.6autovue_for_agile_product_lifecycle_management = 21.0.2banking_deposits_and_lines_of_credit_servicing = 2.12.0banking_enterprise_default_management = 2.7.1banking_enterprise_default_management = 2.12.0banking_loans_servicing = 2.12.0banking_party_management = 2.7.0banking_payments = 14.5banking_platform = 2.6.2banking_platform = 2.7.1banking_platform = 2.12.0banking_trade_finance = 14.5banking_treasury_management = 14.5business_intelligence = 5.5.0.0.0communications_asap = 7.3communications_billing_and_revenue_management = 12.0.0.4communications_billing_and_revenue_management = 12.0.0.5communications_cloud_native_core_console = 1.9.0communications_cloud_native_core_network_function_cloud_native_environment = 1.10.0communications_cloud_native_core_network_repository_function = 1.15.0communications_cloud_native_core_network_repository_function = 1.15.1communications_cloud_native_core_network_slice_selection_function = 1.8.0communications_cloud_native_core_policy = 1.15.0communications_cloud_native_core_security_edge_protection_proxy = 1.7.0communications_cloud_native_core_service_communication_proxy = 1.15.0communications_cloud_native_core_unified_data_repository = 1.15.0communications_convergence = 3.0.2.2.0communications_convergence = 3.0.3.0communications_convergent_charging_controller >= 12.0.1.0.0, <= 12.0.4.0.0communications_convergent_charging_controller = 6.0.1.0.0communications_diameter_signaling_router >= 8.3.0.0, <= 8.5.1.0communications_eagle_element_management_system = 46.6communications_eagle_ftp_table_base_retrieval = 4.5communications_element_manager < 9.0communications_evolved_communications_application_server = 7.1communications_interactive_session_recorder = 6.3communications_interactive_session_recorder = 6.4communications_ip_service_activator = 7.4.0communications_messaging_server = 8.1communications_network_charging_and_control >= 12.0.1.0.0, <= 12.0.4.0.0communications_network_charging_and_control = 6.0.1.0.0communications_network_integrity = 7.3.6communications_performance_intelligence_center = 10.4.0.3communications_pricing_design_center = 12.0.0.4communications_pricing_design_center = 12.0.0.5communications_service_broker = 6.2communications_services_gatekeeper = 7.0communications_session_report_manager < 9.0communications_session_route_manager < 9.0communications_unified_inventory_management = 7.3.5communications_unified_inventory_management = 7.4.1communications_unified_inventory_management = 7.4.2communications_user_data_repository = 12.4communications_webrtc_session_controller = 7.2.0.0communications_webrtc_session_controller = 7.2.1data_integrator = 12.2.1.3.0data_integrator = 12.2.1.4.0e-business_suite = 12.2enterprise_manager_base_platform = 13.4.0.0enterprise_manager_base_platform = 13.5.0.0enterprise_manager_for_peoplesoft = 13.4.1.1enterprise_manager_for_peoplesoft = 13.5.1.1enterprise_manager_ops_center = 12.4.0.0financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1financial_services_model_management_and_governance = 8.0.8.0.0financial_services_model_management_and_governance = 8.1.0.0.0financial_services_model_management_and_governance = 8.1.1.0.0flexcube_universal_banking >= 12.1.0, <= 12.4flexcube_universal_banking >= 14.0.0, <= 14.3.0flexcube_universal_banking = 11.83.3flexcube_universal_banking = 14.5health_sciences_empirica_signal = 9.1.0.6health_sciences_empirica_signal = 9.2.0.0health_sciences_inform = 6.2.1.1health_sciences_inform = 6.3.2.1health_sciences_inform = 7.0.0.0health_sciences_information_manager >= 3.0.1, <= 3.0.4healthcare_data_repository = 8.1.1healthcare_foundation >= 7.3.0.1, <= 7.3.0.4healthcare_master_person_index = 5.0.1healthcare_translational_research = 4.1.0healthcare_translational_research = 4.1.1hospitality_suite8 = 8.13.0hospitality_suite8 = 8.14.0Upgrade past the affected range:
log4j 2.12.3network_security_manager 3.0web_application_firewall 3.1.06bk1602-0aa12-0tp0_firmware 2.7.06bk1602-0aa22-0tp0_firmware 2.7.06bk1602-0aa32-0tp0_firmware 2.7.06bk1602-0aa42-0tp0_firmware 2.7.06bk1602-0aa52-0tp0_firmware 2.7.0communications_element_manager 9.0communications_session_report_manager 9.0communications_session_route_manager 9.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29425Medium· 4.8In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…
CVE-2021-3572Medium· 5.7A flaw was found in python-pip in the way it handled Unicode separators in git references
CVE-2026-74761High· 7.5Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affec…
CVE-2026-61483High· 7.5** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue
CVE-2026-66274High· 7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35…
CVE-2026-50633High· 8.1A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …