mediumREV. 01

CVE-2021-45105Log4j — Denial of Service via Self-Referential Lookup

A later Log4j flaw: a self-referential lookup in context data recurses until the thread dies, so an attacker who can shape logged context can stop the application.

YOUR NEXT MOVE

Upgrade Log4j past 2.16.0, and keep attacker-controlled values out of thread context data.

Read the risk

THE VITAL STATS
CVSS score
5.9/ 10
CVSS v3.1
EPSS probability
100%
Likelihood of exploitation
Attack complexity
High
Conditions needed to exploit
Known exploited
Not listed
CVE published
2021-12-18
Exploit published
Not recorded
Confidence
medium
Kill chain
impact
MITRE ATT&CK
T1499
Severity
medium

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attacker needsControl over a value that reaches thread context data

Behind the card

5 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-08-07scrty-crds-pipeline/0.1high
epssapi.first.org2026-08-07scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-08-07claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2021-45105 · CRDS 0.1 · Issued 2026-08-07