Ross ROSS = Recommend OSS · open-source software intelligence for agents

fullhunt/log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228 observed · 2026-08-28

github.com/fullhunt/log4j-scan · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1724
  • days_rel: n/a
  • days_push: 1379
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

3422 stars · 725 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A Python-based automated scanner for detecting the Log4j RCE vulnerability (CVE-2021-44228, Log4Shell) and related CVEs across lists of URLs. It fuzzes HTTP headers, POST data, and JSON parameters with WAF bypass payloads and built-in DNS out-of-band callback support.

Use cases

  • scan my infrastructure for log4shell vulnerability
  • find servers vulnerable to CVE-2021-44228
  • test WAF bypass payloads for log4j RCE
  • bulk scan a list of URLs for log4j RCE
  • detect Apache Commons Text RCE CVE-2022-42889
  • check for CVE-2021-45046 patch bypass
  • verify log4j vulnerability without setting up a DNS callback server

When to choose

  • you need fast, automated scanning of many URLs for Log4Shell and related CVEs
  • you want built-in DNS OOB callbacks and WAF bypass payloads without extra setup
  • you need a lightweight Python CLI your security team can run ad hoc

When to avoid

  • you need continuous vulnerability management rather than point-in-time scanning
  • you require authenticated or deep application-layer scanning beyond HTTP parameter fuzzing
  • the Log4j incident is fully remediated and you use a broader general-purpose scanner

Facets

cli-tool · maturity maintenance

penetration-testing vulnerability-scanning security http-client security penetration-testing developer-tools cli python windows cross-platform log4j log4shell cve-2021-44228 cve-2021-45046 cve-2022-42889 rce-scanner waf-bypass dns-callback security-scanning linux macos

1 source

Member repositories

RepositoryRoleHealth v2
fullhunt/log4j-scanmain23

For agents

markdown · JSON · MCP: product_card(name="fullhunt/log4j-scan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem