What CVE identifier was assigned to the 2021 Log4Shell vulnerability in Apache Log4j?

The story behind the answer

The 2021 Log4Shell vulnerability in Apache Log4j was assigned the identifier CVE-2021-44228.

Log4j is a widely used Java-based logging library maintained by the Apache Software Foundation. Log4Shell allowed specially crafted text to trigger remote code execution through Log4j's Java Naming and Directory Interface features. Because Log4j appeared inside many applications and services, the flaw affected organizations far beyond those that had installed the library directly.

The vulnerability was publicly disclosed in December 2021, although it had reportedly been discovered earlier by security researchers. It was especially serious because attackers could often exploit vulnerable systems with a single request. Log4Shell is not the same as Shellshock, which affected Bash, or Heartbleed, which affected OpenSSL. The CVE identifier is the precise reference used by security teams, software vendors, and vulnerability databases when tracking the flaw and its fixes.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: