Codicrest Blog

Log4Shell still bites.

Three years after the original disclosure, the Log4Shell class of vulnerability is still the shape AppSec teams run into — same root cause, same blast radius, new names. Here’s the pattern, and what we do about it.

Published

When Log4Shell landed in December 2021, the immediate fire was the JNDI lookup inside Log4j — and we all shipped the upgrade. Three years on, the same class of bug keeps showing up: a logging library that interpolates untrusted strings, a templating engine that reaches too eagerly into a runtime. Reachability hasn’t moved forward as fast as the patches have.

Codicrest’s angle isn’t to keep listing CVEs. It’s to ask, on every shipped dependency, does the vulnerable code path actually execute in this repo? If it doesn’t, your team should not be paged for it.