CVE-2021-45105

CVE-2021-45105: Apache Log4j2 does not always protect from infinite recursion in lookup evaluation

Vendor Apache Software Foundation
Product Apache Log4j2
Weakness CWE-20 · Input validation
Published December 18, 2021
Last update May 29, 2026

CVSS base score

What the vulnerability does

01Description

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

Key dates

02Disclosure timeline

December 18, 2021 CVE published
May 29, 2026 Record updated

Related vulnerabilities

04Related CVE