GHSA-p6xc-xr62-6r2g · Severity: high · Ecosystem: maven — Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Conclusion & alert: CVE-2021-45105 is rated Moderate Risk (57.7/100): CVSS Medium severity, with high exploitation likelihood (EPSS 74.02%, 99th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-01 | 74.54% | 74.02% | -0.52% |
| 2 | 2026-05-11 | 70.43% | 74.54% | +4.11% |
| 3 | 2026-04-09 | — | 70.43% | — |
Full EPSS history (94 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-p6xc-xr62-6r2g · Severity: high · Ecosystem: maven — Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2021-45105 not yet assigned priority: Debian including 1 source packages (apache-log4j2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-45105 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-45105 |
suse
|
high | CVE-2021-45105 severity important: SUSE including 25 source package names (5.0.0-beta1.2.122:log4j-2.17.0-4.13.1, 5.0.0-beta1.2.122:log4j-jcl-2.17.0-4.13.1, …), 134 product×package rows across 66 product lines (Container suse/manager/5.0/x86_64/server, Container suse/manager/5.0/x86_64/server-attestation, … (66 product lines)): Fixed 73, Known Not Affected 61. | https://www.suse.com/security/cve/CVE-2021-45105/ |
ubuntu
|
medium | CVE-2021-45105 medium priority: Ubuntu including 1 source packages (apache-log4j2), 14 status rows across 14 suites (bionic, focal, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, upstream, xenial): not-affected 8, released 5, needed 1. | https://ubuntu.com/security/CVE-2021-45105 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | log4j | >= 2.0, < 2.3.1 | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* |
| apache | log4j | >= 2.4, < 2.12.3 | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* |
| apache | log4j | >= 2.13.0, <= 2.16.0 | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* |
| netapp | cloud_manager | — | cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
| sonicwall | email_security | <= 10.0.12 | cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:* |
| sonicwall | network_security_manager | >= 2.0, < 3.0 | cpe:2.3:a:sonicwall:network_security_manager:*:*:*:*:on-premises:*:*:* |
| sonicwall | network_security_manager | >= 2.0, < 3.0 | cpe:2.3:a:sonicwall:network_security_manager:*:*:*:*:saas:*:*:* |
| sonicwall | web_application_firewall | >= 3.0.0, < 3.1.0 | cpe:2.3:a:sonicwall:web_application_firewall:*:*:*:*:*:*:*:* |
| sonicwall | 6bk1602-0aa12-0tp0_firmware | < 2.7.0 | cpe:2.3:o:sonicwall:6bk1602-0aa12-0tp0_firmware:*:*:*:*:*:*:*:* |
| sonicwall | 6bk1602-0aa22-0tp0_firmware | < 2.7.0 | cpe:2.3:o:sonicwall:6bk1602-0aa22-0tp0_firmware:*:*:*:*:*:*:*:* |
| sonicwall | 6bk1602-0aa32-0tp0_firmware | < 2.7.0 | cpe:2.3:o:sonicwall:6bk1602-0aa32-0tp0_firmware:*:*:*:*:*:*:*:* |
| sonicwall | 6bk1602-0aa42-0tp0_firmware | < 2.7.0 | cpe:2.3:o:sonicwall:6bk1602-0aa42-0tp0_firmware:*:*:*:*:*:*:*:* |
| sonicwall | 6bk1602-0aa52-0tp0_firmware | < 2.7.0 | cpe:2.3:o:sonicwall:6bk1602-0aa52-0tp0_firmware:*:*:*:*:*:*:*:* |
| oracle | agile_engineering_data_management | 6.2.1.0 | cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* |
| oracle | agile_plm | 9.3.6 | cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* |
| oracle | agile_plm_mcad_connector | 3.6 | cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:* |
| oracle | autovue_for_agile_product_lifecycle_management | 21.0.2 | cpe:2.3:a:oracle:autovue_for_agile_product_lifecycle_management:21.0.2:*:*:*:*:*:*:* |
| oracle | banking_deposits_and_lines_of_credit_servicing | 2.12.0 | cpe:2.3:a:oracle:banking_deposits_and_lines_of_credit_servicing:2.12.0:*:*:*:*:*:*:* |
| oracle | banking_enterprise_default_management | 2.7.1 | cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.1:*:*:*:*:*:*:* |
| oracle | banking_enterprise_default_management | 2.12.0 | cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0:*:*:*:*:*:*:* |
| oracle | banking_loans_servicing | 2.12.0 | cpe:2.3:a:oracle:banking_loans_servicing:2.12.0:*:*:*:*:*:*:* |
| oracle | banking_party_management | 2.7.0 | cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*:* |
| oracle | banking_payments | 14.5 | cpe:2.3:a:oracle:banking_payments:14.5:*:*:*:*:*:*:* |
| oracle | banking_platform | 2.6.2 | cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:* |
| oracle | banking_platform | 2.7.1 | cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:* |
| oracle | banking_platform | 2.12.0 | cpe:2.3:a:oracle:banking_platform:2.12.0:*:*:*:*:*:*:* |
| oracle | banking_trade_finance | 14.5 | cpe:2.3:a:oracle:banking_trade_finance:14.5:*:*:*:*:*:*:* |
| oracle | banking_treasury_management | 14.5 | cpe:2.3:a:oracle:banking_treasury_management:14.5:*:*:*:*:*:*:* |
| oracle | business_intelligence | 5.5.0.0.0 | cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise:*:*:* |
| oracle | communications_asap | 7.3 | cpe:2.3:a:oracle:communications_asap:7.3:*:*:*:*:*:*:* |
| oracle | communications_billing_and_revenue_management | 12.0.0.4 | cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.4:*:*:*:*:*:*:* |
| oracle | communications_billing_and_revenue_management | 12.0.0.5 | cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.5:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_console | 1.9.0 | cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.10.0 | cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_network_repository_function | 1.15.0 | cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_network_repository_function | 1.15.1 | cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.1:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_network_slice_selection_function | 1.8.0 | cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_policy | 1.15.0 | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.7.0 | cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_service_communication_proxy | 1.15.0 | cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.15.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_unified_data_repository | 1.15.0 | cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:* |
| oracle | communications_convergence | 3.0.2.2.0 | cpe:2.3:a:oracle:communications_convergence:3.0.2.2.0:*:*:*:*:*:*:* |
| oracle | communications_convergence | 3.0.3.0 | cpe:2.3:a:oracle:communications_convergence:3.0.3.0:*:*:*:*:*:*:* |
| oracle | communications_convergent_charging_controller | >= 12.0.1.0.0, <= 12.0.4.0.0 | cpe:2.3:a:oracle:communications_convergent_charging_controller:*:*:*:*:*:*:*:* |
| oracle | communications_convergent_charging_controller | 6.0.1.0.0 | cpe:2.3:a:oracle:communications_convergent_charging_controller:6.0.1.0.0:*:*:*:*:*:*:* |
| oracle | communications_diameter_signaling_router | >= 8.3.0.0, <= 8.5.1.0 | cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:* |
| oracle | communications_eagle_element_management_system | 46.6 | cpe:2.3:a:oracle:communications_eagle_element_management_system:46.6:*:*:*:*:*:*:* |
| oracle | communications_eagle_ftp_table_base_retrieval | 4.5 | cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:* |
| oracle | communications_element_manager | < 9.0 | cpe:2.3:a:oracle:communications_element_manager:*:*:*:*:*:*:*:* |
| oracle | communications_evolved_communications_application_server | 7.1 | cpe:2.3:a:oracle:communications_evolved_communications_application_server:7.1:*:*:*:*:*:*:* |
| oracle | communications_interactive_session_recorder | 6.3 | cpe:2.3:a:oracle:communications_interactive_session_recorder:6.3:*:*:*:*:*:*:* |
| oracle | communications_interactive_session_recorder | 6.4 | cpe:2.3:a:oracle:communications_interactive_session_recorder:6.4:*:*:*:*:*:*:* |
| oracle | communications_ip_service_activator | 7.4.0 | cpe:2.3:a:oracle:communications_ip_service_activator:7.4.0:*:*:*:*:*:*:* |
| oracle | communications_messaging_server | 8.1 | cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* |
| oracle | communications_network_charging_and_control | >= 12.0.1.0.0, <= 12.0.4.0.0 | cpe:2.3:a:oracle:communications_network_charging_and_control:*:*:*:*:*:*:*:* |
| oracle | communications_network_charging_and_control | 6.0.1.0.0 | cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1.0.0:*:*:*:*:*:*:* |
| oracle | communications_network_integrity | 7.3.6 | cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:* |
| oracle | communications_performance_intelligence_center | 10.4.0.3 | cpe:2.3:a:oracle:communications_performance_intelligence_center:10.4.0.3:*:*:*:*:*:*:* |
| oracle | communications_pricing_design_center | 12.0.0.4 | cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.4:*:*:*:*:*:*:* |
| oracle | communications_pricing_design_center | 12.0.0.5 | cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.5:*:*:*:*:*:*:* |
| oracle | communications_service_broker | 6.2 | cpe:2.3:a:oracle:communications_service_broker:6.2:*:*:*:*:*:*:* |
| oracle | communications_services_gatekeeper | 7.0 | cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:* |
| oracle | communications_session_report_manager | < 9.0 | cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:* |
| oracle | communications_session_route_manager | < 9.0 | cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.3.5 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.5:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.4.1 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.4.2 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:* |
| oracle | communications_user_data_repository | 12.4 | cpe:2.3:a:oracle:communications_user_data_repository:12.4:*:*:*:*:*:*:* |
| oracle | communications_webrtc_session_controller | 7.2.0.0 | cpe:2.3:a:oracle:communications_webrtc_session_controller:7.2.0.0:*:*:*:*:*:*:* |
| oracle | communications_webrtc_session_controller | 7.2.1 | cpe:2.3:a:oracle:communications_webrtc_session_controller:7.2.1:*:*:*:*:*:*:* |
| oracle | data_integrator | 12.2.1.3.0 | cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | data_integrator | 12.2.1.4.0 | cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | e-business_suite | 12.2 | cpe:2.3:a:oracle:e-business_suite:12.2:*:*:*:*:*:*:* |
| oracle | enterprise_manager_base_platform | 13.4.0.0 | cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:* |
| oracle | enterprise_manager_base_platform | 13.5.0.0 | cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:* |
| oracle | enterprise_manager_for_peoplesoft | 13.4.1.1 | cpe:2.3:a:oracle:enterprise_manager_for_peoplesoft:13.4.1.1:*:*:*:*:*:*:* |
| oracle | enterprise_manager_for_peoplesoft | 13.5.1.1 | cpe:2.3:a:oracle:enterprise_manager_for_peoplesoft:13.5.1.1:*:*:*:*:*:*:* |
| oracle | enterprise_manager_ops_center | 12.4.0.0 | cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:* |