Disclosure summary
# Impact The fix to address [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a remote code execution (RCE) attack. ## Affected packages Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apache.logging.log4j:log4j-core` package to ensure compatability if in use. # Mitigation Log4j 2.16.0 fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default. This issue can be mitigated in prior releases (< 2.16.0) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). Log4j 2.15.0 restricts JNDI LDAP lookups
CISA remediation guidance
Apply updates per vendor instructions.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-7rjr-3q55-vv33
Open original source · Updated Oct 02, 2026
Incomplete fix for Apache Log4j vulnerability
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| maven | org.apache.logging.log4j:log4j-core | >= 2.13.0, < 2.16.0 | 2.16.0 |
| maven | org.ops4j.pax.logging:pax-logging-log4j2 | >= 1.8.0, < 1.9.2 | 1.9.2 |
| maven | org.ops4j.pax.logging:pax-logging-log4j2 | >= 1.10.0, < 1.10.8 | 1.10.8 |
| maven | org.ops4j.pax.logging:pax-logging-log4j2 | >= 1.11.0, < 1.11.11 | 1.11.11 |
| maven | org.ops4j.pax.logging:pax-logging-log4j2 | >= 2.0.0, < 2.0.12 | 2.0.12 |
| maven | org.apache.logging.log4j:log4j-core | >= 2.4.0, < 2.12.2 | 2.12.2 |
| maven | org.apache.logging.log4j:log4j-core | < 2.3.1 | 2.3.1 |
Original records & references
- NIST NVD record
- CVE Program record
- CISA KEV catalog entry
- github.com — Reviewed advisory
PUBLISHED 2021-12-14T13:01:28-05:00
MODIFIED 2026-10-02T16:21:54-04:00
INGESTED 2026-10-06T11:45:17-04:00