Log4Shell Downloaded 40 Million Times in 2025
ID: 761b697b-b5b8-5f7a-8f33-ab400497eab6
STIX ID: report--761b697b-b5b8-5f7a-8f33-ab400497eab6
Feed Name: Infosecurity Magazine (News)
Sonatype analysis of Maven Central downloads found roughly 40 million of 300 million Log4j downloads in 2025 still contained the Log4Shell CVSS 10.0 vulnerability, highlighting persistent supply-chain and dependency-management risks across global developer populations; the report attributes continued exposure to stale/transitive dependencies and poor library selection, and urges use of SCA, artifact-repository guardrails, automated safe-upgrade mechanisms and new risk metrics to reduce avoidable vulnerable usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
