<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Log4j (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/log4j.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/log4j-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Log4j (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:57 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-34481 – Apache Log4j's  JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34481</guid>
    <pubDate>Fri, 10 Apr 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34481</strong></p>
  <p>Apache Log4j's  JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records.  An att…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34480 – Apache Log4j Core's  XmlLayout https://logging.apache.org/log4j/2.x/manual/layou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34480</guid>
    <pubDate>Fri, 10 Apr 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34480</strong></p>
  <p>Apache Log4j Core's  XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the  XML 1.0 specification https://www.w3.org/TR/xml/#charsets  producing invalid XML output whenever a log message or MDC value contains such characters.  The impact depends on the StAX implementation in use:    *  J…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34479 – The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape ch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34479</guid>
    <pubDate>Fri, 10 Apr 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34479</strong></p>
  <p>The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.  Two groups of users are affected:    *  Those…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34478 – Apache Log4j Core's  Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34478</guid>
    <pubDate>Fri, 10 Apr 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34478</strong></p>
  <p>Apache Log4j Core's  Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.  Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:    *  The newLineEscape att…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23049 – An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23049</guid>
    <pubDate>Mon, 05 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23049</strong></p>
  <p>An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26464 – ** UNSUPPORTED WHEN ASSIGNED **

When using the Chainsaw or SocketAppender compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26464</guid>
    <pubDate>Fri, 10 Mar 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26464</strong></p>
  <p>** UNSUPPORTED WHEN ASSIGNED **  When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested)  hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service w…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4125 – It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4125</guid>
    <pubDate>Wed, 24 Aug 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4125</strong></p>
  <p>It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-33915 – Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33915</guid>
    <pubDate>Fri, 17 Jun 2022 13:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-33915</strong></p>
  <p>Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation. This Hotpatch package is not a replacement for updating to a log4j version that mitigates CVE-2021-44228 or CVE-2021-45046; it provides a temporary mitigation to CVE-2021-44228 by hotpatching the local Java virtual ma…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0070 – Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0070</guid>
    <pubDate>Tue, 19 Apr 2022 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0070</strong></p>
  <p>Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3100 – The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3100</guid>
    <pubDate>Tue, 19 Apr 2022 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3100</strong></p>
  <p>The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24818 – GeoTools is an open source Java library that provides tools for geospatial data...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24818</guid>
    <pubDate>Wed, 13 Apr 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24818</strong></p>
  <p>GeoTools is an open source Java library that provides tools for geospatial data. The GeoTools library has a number of data sources that can perform unchecked JNDI lookups, which in turn can be used to perform class deserialization and result in arbitrary code execution. Similar to the Log4J case, the vulnerability can be triggered if the JNDI names are user-provided, but requires admin-level logi…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23848 – In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23848</guid>
    <pubDate>Sun, 20 Feb 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23848</strong></p>
  <p>In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23307 – CVE-2020-9493 identified a deserialization issue that was present in Apache Chai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23307</guid>
    <pubDate>Tue, 18 Jan 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23307</strong></p>
  <p>CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23305 – By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23305</guid>
    <pubDate>Tue, 18 Jan 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23305</strong></p>
  <p>By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be ex…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23302 – JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrust...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23302</guid>
    <pubDate>Tue, 18 Jan 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23302</strong></p>
  <p>JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fash…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-44530 – An injection vulnerability exists in a third-party library used in UniFi Network...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44530</guid>
    <pubDate>Fri, 14 Jan 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-44530</strong></p>
  <p>An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45046 – It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45046</guid>
    <pubDate>Tue, 14 Dec 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45046</strong></p>
  <p>It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft ma…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4104 – JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4104</guid>
    <pubDate>Tue, 14 Dec 2021 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4104</strong></p>
  <p>JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-44228 – Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44228</guid>
    <pubDate>Fri, 10 Dec 2021 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-44228</strong></p>
  <p>Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is e…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-17571 – Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserializat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17571</guid>
    <pubDate>Fri, 20 Dec 2019 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-17571</strong></p>
  <p>Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-17531 – A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17531</guid>
    <pubDate>Sat, 12 Oct 2019 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-17531</strong></p>
  <p>A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-5645 – In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5645</guid>
    <pubDate>Mon, 17 Apr 2017 21:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-5645</strong></p>
  <p>In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5645">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
