#Log4j2
New Apache Log4j2 Flaw Lets Attackers Bypass Security Checks and Execute Remote Code
New Apache Log4j2 Flaw Lets Attackers Bypass Security Checks and Execute Remote Code
A newly disclosed Apache Log4j2 issue could allow attackers to bypass a deserialization allowlist and execute code remotely in narrowly defined deployments. The issue, tracked as Log4j2 #4255, affects applications that accept serialized Log4j events through a network-accessible Java deserialization path. The reported weakness involves Log4j’s FilteredObjectInputStream, a utility designed to restrict which Java classes can be loaded while reading serialized log events. Its allowlist includes Java.rmi MarshalledObject, a Java container that can store another serialized object as an opaque byte array. Researchers found that this outer object can pass the Log4j allowlist while concealing a malicious inner object. When Log4j later calls MarshalledObject.get(), Java deserializes the embedded payload using a fresh, unfiltered ObjectInputStream. This means the original allowlist does not inspect the hidden object graph. New Apache Log4j2 Vulnerability The vulnerable flow is linked to Log4jLogEvent$LogEventProxy, the serialized representation of a Log4j event. The proxy places the event message inside a MarshalledObject and retrieves it automatically during deserialization. An attacker could craft a malicious serialized Log4j event, send it to a vulnerable receiver, and cause a gadget chain available on the target classpath to execute. Dinosn reports Log4j2 #4255 on GitHub , where a public reproduction lab demonstrated the issue in Log4j 2.26.1 running on JDK 17. In the test environment, a malicious payload embedded in a MarshalledObject triggered code execution when processed by an unauthenticated TCP receiver using FilteredObjectInputStream. The lab also showed that a Commons Collections 3.2.1 gadget chain could execute without requiring an attacker-supplied class on the victim system. However, the issue is not comparable to the widespread Log4Shell vulnerability . It cannot be triggered simply by placing a malicious string into an application log message. Exploitation requires a specific and uncommon setup: an application must expose a receiver that accepts attacker-controlled serialized Log4j events, processes them using FilteredObjectInputStream, and includes a usable chain of Java deserialization gadgets. Apache’s security guidance stresses that current Log4j Core production code does not normally deserialize data received from sockets, queues, or other external sources. The project describes FilteredObjectInputStream as a defense-in-depth utility rather than a complete security boundary. It warns that applications should not deserialize untrusted log event streams. Organizations should identify legacy serialized Log4j event receivers, especially unauthenticated network services based on old socket bridge patterns. A temporary mitigation is to configure the JVM serialization filter to reject Java.rmi.MarshalledObject, although this may also block legitimate serialized Log4j events. More durable defenses include removing Java serialization from log transport, upgrading or removing vulnerable gadget dependencies, using mutually authenticated endpoints, and migrating to JSON or RFC 5424 logging over TLS. Apache specifically recommends structured formats and TLS rather than Java-serialized log transport. At the time of reporting, Log4j2 issue #4255 remained open and had no assigned CVE. The flaw is best understood as a dangerous deserialization bypass in legacy or custom Log4j event receivers, not a universal remote code execution flaw affecting ordinary Log4j deployments. Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:  Integrate TI Lookup in your SOC The post New Apache Log4j2 Flaw Lets Attackers Bypass Security Checks and Execute Remote Code appeared first on Cyber Security News .
cybersecuritynews.com
August 27, 2026 at 9:09 AM
#OpenRewrite v8.62.4 is out! ⭐

🔒 GitHub Actions security insights
🔧 JEP 512 Instance main methods
⚡ Kafka 4.0/4.1 migration recipes
🔎 ElasticSearch 9 type migrations
📑 Extended JSP parser support
✨ Inline Guava & Log4j2 methods
📦 Quarkus aggregated update recipes

github.com/openrewrite/...
Release 3.15.0 · openrewrite/rewrite-recipe-bom
What's Changed Incorporates the latest versions of OpenRewrite (v8.62.4), the rewrite-gradle-plugin (v7.17.0), and the rewrite-maven-plugin (v6.19.0) to improve code parsing accuracy and recipe ex...
github.com
September 24, 2025 at 5:44 PM
fastlogging - Fast logging module written in Rust

Integrates with python, C, C++, Go, Java & C#. I have not really understood the benchmarks against log4j/log4j2, so I am not sure it's really faster.

github.com/brmmm3/fastl...
GitHub - brmmm3/fastlogging-rs: Fast logging module written in Rust
Fast logging module written in Rust. Contribute to brmmm3/fastlogging-rs development by creating an account on GitHub.
github.com
September 30, 2026 at 12:56 PM
In-Depth Technical Analysis: The New Log4j2 FilteredObjectInputStream Bypass Vulnerability

A newly reported Log4j2 flaw can bypass deserialization protections through Java…

https://thecybersecguru.com/news/in-depth-technical-analysis-the-new-log4j2-filteredobjectinputstream-bypass-vulnerability/
August 26, 2026 at 2:25 PM
Log4j2のLoggerのAppender設定がおかしいと言い出す銀行員
April 16, 2026 at 2:29 AM
I recently read and shared You’re Wasting Time in #Java Without These 10 Libraries. I commented on it a bit in my newsletter, but given the amount and intensity of reactions, I think a full-blown post is in order.

#Lombok #JUnit #Jackson #SpringFramework #Liquibase #Flyway #SLF4J #Log4J2
Are you really wasting your time in Java without these 10 libraries?
I recently read and shared You’re Wasting Time in Java Without These 10 Libraries. I commented on it a bit in my newsletter, but given the amount and intensity of reactions, I think a full-blown post ...
blog.frankel.ch
November 16, 2025 at 6:28 PM
Critical Apache Log4j2 flaw still threatens global finance
Critical Apache Log4j2 flaw still threatens global finance - Security Affairs
The flaw CVE-2021-44832 is Apache Log4j2 library is still a serious problem for multiple industries, experts warn it threatens global Finance.
securityaffairs.com
June 1, 2024 at 4:17 PM
How To Do Logging In Java
How To Do Logging In Java
You can use this guide to discover, understand and use the right Java logging library for your applications, like Log4j2, Logback, or java.util.logging.
www.marcobehler.com
January 8, 2025 at 8:37 AM
Struts JQuery Plugin ver 6.0.0 is out with full support for Struts 7.0.0 and Java 17!

#java #struts #jquery #plugin #release

github.com/struts-commu...
Release 6.0.0 · struts-community-plugins/struts2-jquery
What's Changed Upgrades to Struts 7 by @lukaszlenart in #597 Dependencies Update log4j2 monorepo to v2.24.3 by @renovate in #588 Update dependency org.junit.jupiter:junit-jupiter to v5.11.4 by @...
github.com
January 9, 2025 at 8:39 AM
Vamo resolver esse negócio, man.

Acho que umas horas lendo sobre o assunto (pra entender as melhores práticas e o que deu certo) seriam suficientes pra criar a base que precisamos pra fazer uma v1 e apresentar a ideia pra engenharia.

Logback com MDC é um bom caminho.
Java Logging with Mapped Diagnostic Context (MDC) | Baeldung
Learn how to use MDC with Log4j, Log4j2 and Logback.
www.baeldung.com
December 20, 2025 at 2:08 PM
We have some breaking news. A potential RCE in Apache #Log4J 2 (yes, really) appears to have proofs-of-concept. We have the details, the initial bug report, and mitigation recommendations. We are verifying the PoCs currently.

discourse.ifin.netwo...

#ThreatIntel #ThreatIntel #IFIN
Log4j2 Allowlist Bypass Could Allow for RCE
Last Updated: 2026-08-26T17:05:28Z (UTC) What’s Happening A currently unconfirmed vulnerability in Apache Log4j could allow remote code execution (RCE) by bypassing the allowlist enforced by FilteredObjectInputStream (FOIS) during Java deserialization. Exploitation requires an uncommon configuration in which an application or logging service accepts serialized Log4j LogEvent objects through an FOIS-based receiver, as well as a suitable deserialization gadget on the target classpath. Unlik...
discourse.ifin.network
August 26, 2026 at 5:33 PM
The #OpenTelemetry Java Instrumentation agent and SDK now offer an easy solution to convert #logs from frameworks like SLF4J/Logback or Log4j2 into OTel-compliant #JSON logs on stdout with all resource and log attributes.

Read the blog post from @cyrilleleclerc.bsky.social and Gregor Zeitlinger.
Collecting OpenTelemetry-compliant Java logs from files
If you want to get logs from your Java application ingested into an OpenTelemetry-compatible logs backend, the easiest and recommended way is using an OpenTelemetry protocol (OTLP) exporter. However,…
opentelemetry.io
December 14, 2024 at 9:30 AM
Critical RCE Vulnerability in Apache Log4j2 (Log4Shell) – Exploitation and Mitigation + Video

Introduction: In December 2021, the cybersecurity community was rocked by the disclosure of CVE-2021-44228, a remote code execution (RCE) vulnerability in Apache Log4j2, a ubiquitous Java logging library.…
Critical RCE Vulnerability in Apache Log4j2 (Log4Shell) – Exploitation and Mitigation + Video
Introduction: In December 2021, the cybersecurity community was rocked by the disclosure of CVE-2021-44228, a remote code execution (RCE) vulnerability in Apache Log4j2, a ubiquitous Java logging library. Dubbed Log4Shell, this flaw allowed unauthenticated attackers to execute arbitrary code on millions of servers, cloud services, and enterprise applications, making it one of the most severe vulnerabilities in recent history. This article dissects the exploit mechanics, provides hands‑on steps for detection and mitigation across Linux and Windows environments, and outlines long‑term strategies to defend against similar supply chain attacks.
undercodetesting.com
March 15, 2026 at 8:23 AM
Oh wow, that log4j2 RCE is giving me flashbacks to all the CallManager servers I had to patch last time this happened. Glad that’s not my problem anymore! 😎
August 26, 2026 at 8:37 PM
How To Do Logging In Java
How To Do Logging In Java
You can use this guide to discover, understand and use the right Java logging library for your applications, like Log4j2, Logback, or java.util.logging.
www.marcobehler.com
March 6, 2025 at 8:32 PM

Struts Bootstrap plugin ver 6.0.0 is out, with support for Struts 7.0.0 and Java 17! Enjoy!

#struts #bootstrap #plugin #release #java

github.com/struts-commu...
Release 6.0.0 · struts-community-plugins/struts2-bootstrap
What's Changed Upgrades to Struts 7 by @lukaszlenart in #353 Reconfigures renovate to keep 6.0.x branch up to date by @lukaszlenart in #357 Update log4j2 monorepo to v2.24.3 (release/5.0.x) by @re...
github.com
January 9, 2025 at 5:26 PM
It's the holiday season again which means we turn to the Log4j github page for what new major bugs & security issues Security Response Santa 🎅 will bring us this year. github.com/apache/loggi...
Broken logger initialization in 2.24.1 · Issue #3143 · apache/logging-log4j2
Description LoggerContext / LoggerRegistry don't play well together in using weak references, which can result in a null logger if the GC kicks in at a bad timing. Configuration Version: 2.24.1 Ope...
github.com
December 17, 2024 at 5:51 PM
Exploiting and Mitigating the Log4Shell Vulnerability: A Hands-On Guide + Video

Introduction: The Log4Shell vulnerability (CVE-2021-44228) in the popular Apache Log4j2 logging library sent shockwaves through the cybersecurity community due to its ease of exploitation and widespread impact. This…
Exploiting and Mitigating the Log4Shell Vulnerability: A Hands-On Guide + Video
Introduction: The Log4Shell vulnerability (CVE-2021-44228) in the popular Apache Log4j2 logging library sent shockwaves through the cybersecurity community due to its ease of exploitation and widespread impact. This critical remote code execution (RCE) flaw allows unauthenticated attackers to take full control of affected systems by simply sending a specially crafted string to a logged service. Understanding how this attack works and how to defend against it is essential for any IT professional responsible for Java-based applications and infrastructure.
undercodetesting.com
February 17, 2026 at 8:42 PM
🚀 Great work, Tatu!

We’ve just upgraded Log4j 3 to use Jackson 3 🎉
👉 github.com/apache/loggi...

Next up: gearing up for a GA release by the end of the year.

Fun fact: Log4j 3 is one year “younger”, branched in 2018, so we are next in line for graduation.
Upgrade Jackson from 2.x to 3.0.0-rc8 by kurtostfeld · Pull Request #3701 · apache/logging-log4j2
Upgrade Jackson from 2.x to 3.0.0-rc5
github.com
October 7, 2025 at 9:04 AM
Svariati progetti open-source stanno avendo problemi perché subissati di bug report generati con le AI, i quali richiedono di essere analizzati per poi, nella maggior parte dei casi, venire scartati in quanto inutili.

github.com/apache/loggi...
Addressing AI-slop in security reports · apache logging-log4j2 · Discussion #4052
You may have noticed that activity on the public Log4cxx, Log4j, and Log4net repositories has slowed since December 2025. I want to reassure you that the projects are still being actively monitored...
github.com
February 26, 2026 at 2:07 PM
August 27, 2026 at 11:32 AM
log4j2-rce: Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2
log4j2-rce: Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2
github.com
August 27, 2026 at 5:54 AM
Log4j2にRCEを可能にし得る新たな脆弱性 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47384/
August 27, 2026 at 7:53 AM