Open Source Vulnerability Database

The most comprehensive, accurate and timely database for open source vulnerabilities.

Remote Code Execution (RCE)

Affecting org.apache.logging.log4j:log4j-core package, versions

How to fix?


About Snyk

Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.

Report a new vulnerability
A shield with a tick icon inside, symbolising security