CVE-2023-26464
published 2023-03-10CVE-2023-26464: ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a…
PriorityP275high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.91%
77.4th percentile
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized. This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | >= 1.0.4 < 2.0 | 2.0 |
| apache_software_foundation | apache_log4j | >= 1.0.4 < 2 | 2 |
| debian | apache-log4j1.2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable components are Chainsaw and SocketAppender in Log4j 1.x; detection should focus on use of these components with JRE < 1.7 processing deserialized objects ↗
- →Attack vector is network/HTTP; monitor for unexpected large or deeply nested serialized hashmap/hashtable objects sent to Log4j 1.x SocketAppender listener ports ↗
- →Red Hat identifies the vulnerable package as log4j1-socketappender; inventory and alert on deployments of log4j (version 1.x) where SocketAppender or Chainsaw is enabled ↗
- ·Vulnerability only affects Log4j 1.x (before version 2) running on JRE less than 1.7; Log4j 2.x is not affected ↗
- ·Red Hat Enterprise Linux 8 and 9 are rated Low severity because they do not enable the vulnerable JDK by default ↗
- ·This is an unsupported/EOL product; the maintainer will not issue a patch for Log4j 1.x ↗
- ·No mitigation meeting Red Hat's criteria is currently available for affected products ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_oracle6.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-26464: ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1
osv·2023-03-10·CVSS 7.5
CVE-2023-26464 [HIGH] CVE-2023-26464: ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized. This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
OSV
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
osv·2023-03-10
CVE-2023-26464 [HIGH] Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie deeply nested) hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized. This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
GHSA
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
ghsa·2023-03-10
CVE-2023-26464 [HIGH] CWE-400 Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie deeply nested) hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized. This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
VulnCheck
Apache log4j Deserialization of Untrusted Data
vulncheck·2023·CVSS 7.5
CVE-2023-26464 [HIGH] Apache log4j Deserialization of Untrusted Data
Apache log4j Deserialization of Untrusted Data
** UNSUPPORTED WHEN ASSIGNED **
When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested)
hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized.
This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected: Apache log4j
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the pr
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Installation (Apache Log4j) — CVE-2023-26464
vendor_oracle·2025-04-15·CVSS 6.5
CVE-2023-26464 [HIGH] Oracle Oracle Food and Beverage Applications Risk Matrix: Installation (Apache Log4j) — CVE-2023-26464
Oracle Oracle Food and Beverage Applications Risk Matrix: Installation (Apache Log4j) vulnerability
CVE: CVE-2023-26464
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Red Hat
log4j1-socketappender: DoS via hashmap logging
vendor_redhat·2023-03-15·CVSS 7.5
CVE-2023-26464 [HIGH] CWE-400 log4j1-socketappender: DoS via hashmap logging
log4j1-socketappender: DoS via hashmap logging
** UNSUPPORTED WHEN ASSIGNED **
When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested)
hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized.
This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
A flaw was found in Chainsaw and SocketAppender components with Log4j 1.x on JRE, less than 1.7. This issue may allow an attacker
Debian
CVE-2023-26464: apache-log4j1.2 - ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender compo...
vendor_debian·2023·CVSS 7.5
CVE-2023-26464 [HIGH] CVE-2023-26464: apache-log4j1.2 - ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender compo...
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized. This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-10
Published
Exploited in the wild