# fullhunt/log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Repository: https://github.com/fullhunt/log4j-scan
Canonical: https://ross.abutalabs.com/products/log4j-scan
Language: Python
License: MIT
License Family: permissive
Last push: 2022-11-23T18:23:24+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1724, "days_push": 1379, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3422, forks 725 (observed 2026-08-28T04:08:03.840717+00:00)

## What it is
A Python-based automated scanner for detecting the Log4j RCE vulnerability (CVE-2021-44228, Log4Shell) and related CVEs across lists of URLs. It fuzzes HTTP headers, POST data, and JSON parameters with WAF bypass payloads and built-in DNS out-of-band callback support.

## Use cases
- scan my infrastructure for log4shell vulnerability
- find servers vulnerable to CVE-2021-44228
- test WAF bypass payloads for log4j RCE
- bulk scan a list of URLs for log4j RCE
- detect Apache Commons Text RCE CVE-2022-42889
- check for CVE-2021-45046 patch bypass
- verify log4j vulnerability without setting up a DNS callback server

## When to choose
- you need fast, automated scanning of many URLs for Log4Shell and related CVEs
- you want built-in DNS OOB callbacks and WAF bypass payloads without extra setup
- you need a lightweight Python CLI your security team can run ad hoc

## When to avoid
- you need continuous vulnerability management rather than point-in-time scanning
- you require authenticated or deep application-layer scanning beyond HTTP parameter fuzzing
- the Log4j incident is fully remediated and you use a broader general-purpose scanner

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: penetration-testing, vulnerability-scanning, security, http-client
- domain: security, penetration-testing, developer-tools
- platform: cli, python, windows, cross-platform
- tags: log4j, log4shell, cve-2021-44228, cve-2021-45046, cve-2022-42889, rce-scanner, waf-bypass, dns-callback, security-scanning, linux, macos

## Member repositories
- fullhunt/log4j-scan (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:03.840717+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:38:08.511325+00:00, confidence not recorded.
  - readme: https://github.com/fullhunt/log4j-scan (fetched 2026-08-28T04:08:03.840717+00:00, sha f4daf66ff524)
- Data as of 2026-08-30T08:39:29.467469+00:00.
