CVE-2023-26464

CVSS 7.5 · HIGH
EPSS p77
Higher than 77% of all CVEs — moderate exploitation risk.
No patch reference
No patch/mitigation in references

Published 3/10/2023 · updated 6/17/2026 · CWE-502

Share
Get asset-aware triage

Summary

** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging component is in use) to be processed could exhaust the available memory in the virtual machine and achieve Denial of Service when the object is deserialized. This issue affects Apache Log4j before 2. Affected users are recommended to update to Log4j 2.x. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS 7.5HIGH

7.5 / 10
  • AV: Network
  • AC: Low complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope unchanged
  • C: Confidentiality: None
  • I: Integrity: None
  • A: Availability: High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS exploitation probability

1.9%

Percentile p77 Higher than 77% of all CVEs — moderate exploitation risk.

Affected products

1 vendor/product entries
  • Apache Log4j≥ 1.0.4 and < 2.0
Do you run any of these? Sign in to match this CVE against your SBOM and asset inventory automatically.

Timeline

  1. Mar 10, 2023 · Disclosed / published in NVD
  2. Jun 17, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 42 days ago
  • CVE.org· no data
  • FIRST EPSS· 42 days ago
  • CISA KEV· no data
  • OSV· 42 days ago

References

Unlock the full report

See how CVE-2023-26464 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.