Dependency health Workspace

org.apache.logging.log4j:log4j-coreMaven Central · Java

⚠ Known vulnerability history

These advisories relate to this package’s identity. We have not verified your installed version or deployment. This context is separate from its maintenance score.

CVE-2021-44228 · Log4Shell ↗

Applies to specific log4j-core releases, not log4j-api alone. Check resolved and bundled dependencies against Apache’s affected-version ranges.

How these vulnerabilities relate to package checks →
State history 1
WhenChange
2026-09-05 first verdict: active

Badge

maintenance: active

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/maven/org.apache.logging.log4j:log4j-core.svg)](https://isitdeadyet.dev/maven/org.apache.logging.log4j:log4j-core)

Watch it

Get told when org.apache.logging.log4j:log4j-core changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.