Homepage
  1. Snyk Vulnerability Database
  2. Linux
  3. centos
  4. centos:9
  5. log4j

log4j

Report a new vulnerability Found a mistake?

Direct Vulnerabilities

Known vulnerabilities in the log4j package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Directory Traversal

*
  • L
Misinterpretation of Input

*
  • M
Improper Input Validation

*
  • M
XML External Entity (XXE) Injection

*
  • M
Improper Validation of Certificate with Host Mismatch

*
  • H
Directory Traversal

*
  • M
Improper Resource Shutdown or Release

*
  • M
Cross-site Request Forgery (CSRF)

*
  • M
Improper Input Validation

*
  • M
Directory Traversal

*
  • M
Session Fixation

*
  • L
Uncontrolled Recursion

*
  • L
Authentication Bypass

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
HTTP Response Splitting

*
  • M
Information Exposure

*
  • M
Improper Authentication

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Validation of Specified Index, Position, or Offset in Input

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Resource Exhaustion

*
  • M
Uncontrolled Recursion

*
  • M
Improper Input Validation

*
  • L
Out-of-bounds Write

*
                                  
Product
  • Partners
  • Developers & Devops Features
  • Enterprise Features
  • Pricing
  • Test with GitHub
  • Test with CLI
  • API status
Resources
  • Vulnerability DB
  • Blog
  • Documentation
  • FAQs
Company
  • About
  • Jobs
  • Contact
  • Legal terms
  • Privacy
  • Press kit
  • Events
Contact us
  • Support
  • Report a new vuln

Find us online

Track our development

DevSecOps Community Podcast

© 2026 Snyk Ltd.