Executive brief
Apache Log4j does not verify the TLS hostname in its Socket Appender
Affected products
- Maven org.apache.logging.log4j:log4j-core
Junglewise Threat Intelligence
CVE-2025-68161 · Severity: medium · CVSS 4 · Published 2025-12-18
Technologies: org.apache.logging.log4j:log4j-core (Maven). Vendors: Maven.
Apache Log4j does not verify the TLS hostname in its Socket Appender