fullhunt/log4j-scan
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228 observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1724
- days_rel: n/a
- days_push: 1379
- n_releases_24m: 0
Adoption not part of the score
3422 stars · 725 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
A Python-based automated scanner for detecting the Log4j RCE vulnerability (CVE-2021-44228, Log4Shell) and related CVEs across lists of URLs. It fuzzes HTTP headers, POST data, and JSON parameters with WAF bypass payloads and built-in DNS out-of-band callback support.
Use cases
- scan my infrastructure for log4shell vulnerability
- find servers vulnerable to CVE-2021-44228
- test WAF bypass payloads for log4j RCE
- bulk scan a list of URLs for log4j RCE
- detect Apache Commons Text RCE CVE-2022-42889
- check for CVE-2021-45046 patch bypass
- verify log4j vulnerability without setting up a DNS callback server
When to choose
- you need fast, automated scanning of many URLs for Log4Shell and related CVEs
- you want built-in DNS OOB callbacks and WAF bypass payloads without extra setup
- you need a lightweight Python CLI your security team can run ad hoc
When to avoid
- you need continuous vulnerability management rather than point-in-time scanning
- you require authenticated or deep application-layer scanning beyond HTTP parameter fuzzing
- the Log4j incident is fully remediated and you use a broader general-purpose scanner
Facets
cli-tool · maturity maintenance
penetration-testing vulnerability-scanning security http-client security penetration-testing developer-tools cli python windows cross-platform log4j log4shell cve-2021-44228 cve-2021-45046 cve-2022-42889 rce-scanner waf-bypass dns-callback security-scanning linux macos
1 source
- readme: https://github.com/fullhunt/log4j-scan · fetched 2026-08-28 · f4daf66ff524
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| fullhunt/log4j-scan | main | 23 |
For agents
markdown · JSON · MCP: product_card(name="fullhunt/log4j-scan")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem