org.apache.logging.log4j:log4j-coreMaven Central · Java
- latest 2.26.1
- licence Apache-2.0
- checked today
- registry ↗
⚠ Known vulnerability history
These advisories relate to this package’s identity. We have not verified your installed version or deployment. This context is separate from its maintenance score.
CVE-2021-44228 · Log4Shell ↗
Applies to specific log4j-core releases, not log4j-api alone. Check resolved and bundled dependencies against Apache’s affected-version ranges.
How these vulnerabilities relate to package checks →Maintenance trends
Loading historical repository activity…
Signals · last 1 check
The first observation is recorded. Trend lines appear once at least two checks have data for the same signal.
State history 1
| When | Change |
|---|---|
| 2026-09-05 | first verdict: active |
Badge
Drop this in your README. It re-renders itself as the verdict changes.
[](https://isitdeadyet.dev/maven/org.apache.logging.log4j:log4j-core)
Watch it
Get told when org.apache.logging.log4j:log4j-core changes state, changes licence, or is deprecated — instead of finding out during an incident.
Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.