CVE-2025-68161
Apache Log4j does not verify the TLS hostname in its Socket Appender
What Should I Do?
Address in Next Maintenance Window
Low exploitation probability (0.28%). Schedule for your next planned update.
Summary
Remediation
Upgrade to the fixed version using your package manager.
<!-- Update pom.xml dependency version to 2.25.3 for org.apache.logging.log4j:log4j-core -->
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (1)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| org.apache.logging.log4j:log4j-core | Maven | 2.0, 2.0-beta9, 2.0-rc1, 2.0-rc2 (+55 more) | 2.25.3 |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-297
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 4.0 score means for each attack dimension.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-68161ADVISORY
- https://github.com/apache/logging-log4j2/pull/4002WEB
- https://github.com/apache/logging-log4j2/commit/3b93748497e1adbbd027fda8a5e7268ec5d0d578WEB
- https://github.com/apache/logging-log4j2WEB
- https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvxWEB
- https://logging.apache.org/cyclonedx/vdr.xmlWEB
- https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostNameWEB
- https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostNameWEB
- https://logging.apache.org/security.html#CVE-2025-68161WEB
- https://www.openwall.com/lists/oss-security/2025/12/18/1WEB
Frequently Asked Questions
- What is CVE-2025-68161?
- Apache Log4j does not verify the TLS hostname in its Socket Appender This vulnerability has been assigned a severity rating of MEDIUM (CVSS score: 4.0/10).
- How do I check if my project is affected by CVE-2025-68161?
- CVE-2025-68161 affects org.apache.logging.log4j:log4j-core. It has a 0.3% probability of exploitation within 30 days (EPSS score). Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-68161 and 200,000+ other known vulnerabilities.
Severity & Exploitability
Exploitation requires specific conditions or has limited impact. Remediate within weeks.
Also Known As
Related CVEs
- CVE-2021-45046CRITICAL
Incomplete fix for Apache Log4j vulnerability
- CVE-2021-44228CRITICAL
Remote code injection in Log4j
- CVE-2021-45105HIGH
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
- CVE-2021-44832MEDIUM
Improper Input Validation and Injection in Apache Log4j2
- CVE-2026-62909MEDIUM
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
- CVE-2026-62902MEDIUM
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
- CVE-2026-61807MEDIUM
Snipe-IT: Stored DOM XSS via table selected-count IDs
- CVE-2026-62899MEDIUM
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies