CVE-2019-17571: exploitation status and patch state

CVE-2019-17571 · CVSS 9.8 CRITICAL · EPSS 69%

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

Is CVE-2019-17571 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2019-17571

PlainSec has not published a story about this CVE.

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.