Junglewise Threat Intelligence

CVE-2025-68161: Apache Log4j does not verify the TLS hostname in its Socket Appender

CVE-2025-68161 · Severity: medium · CVSS 4 · Published 2025-12-18

Technologies: org.apache.logging.log4j:log4j-core (Maven). Vendors: Maven.

Executive brief

Apache Log4j does not verify the TLS hostname in its Socket Appender

Affected products

  • Maven org.apache.logging.log4j:log4j-core

Related threats