Log4j End of Life Dates

other

Developers rely on Log4j, a widely-used logging library, to track and manage logs in their applications, and for good reason - it has been a staple in the development community since its creation. The Apache Software Foundation maintains Log4j, ensuring it remains a viable and secure option for logging needs. With a history of providing reliable logging capabilities, Log4j has become an essential tool for many developers, allowing them to focus on their core application development.

The end-of-life landscape for Log4j is relatively straightforward, with a total of 4 versions, 3 of which have already reached their end-of-life. The last version to reach end-of-life was 2.12, which occurred on December 14, 2021. Currently, only 1 version remains active, with the latest stable version being 2.26.0. Notably, there is no next end-of-life date announced, giving developers a sense of stability and consistency with the current version.

From a security perspective, Log4j has a clean slate, with 0 total CVEs tracked and 0 critical CVEs. As a result, there is no most affected version, and the Known Exploited Vulnerabilities catalog does not apply. This spotless security record is a testament to the dedication of the Apache Software Foundation in maintaining a secure logging library. Developers can continue to use Log4j with confidence, knowing that their logging needs are met without introducing potential security risks into their applications. With no immediate action required, developers can focus on their development work, secure in the knowledge that Log4j is a reliable and secure logging solution.

Last updated: Jul 24, 2026

VersionReleasedActive supportEOL dateUntil EOLLatestCVEsStatusAlert me
2.12 Jun 26, 2019Dec 14, 20211683d ago2.12.4EOL
2.3 May 10, 2015Sep 20, 20153960d ago2.3.2EOL
2 Jul 12, 2014No2.26.0Active
1 Jan 8, 2001Oct 15, 20153935d ago1.2.17EOL

Data sourced from endoflife.date · CVE data from NVD

Related technologies

Frequently Asked Questions