CVE-2021-45105
Log4j Uncontrolled Recursion DoS: stopped at runtime
Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.
Published December 18, 2021 · Updated March 4, 2026
The vulnerability
Denial of service via self-referential lookup
Log4j2 did not guard against uncontrolled recursion from self-referential lookups. An attacker who controls Thread Context Map data can craft a string that triggers infinite recursion, crashing the application - a follow-on issue from the original Log4Shell disclosure.
Running an affected version? We can help.
Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.
How Waratek RASP stops it
Blocked at runtime by Waratek RASP
Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.
Runtime, not perimeter
Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.
No code changes
Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.
Zero false positives
Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.
| Mod | Rules | Enable |
|---|---|---|
| Log4j Uncontrolled Recursion DoS protectionCVE-2021-45105 · Uncontrolled recursion / improper input handling | 1 | |
| SQL Injection protectionQuery manipulation | 4 | |
| Path Traversal protectionUnsafe file access | 3 |
Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.
Common questions
Log4j Uncontrolled Recursion DoS FAQ
Is Log4j Uncontrolled Recursion DoS (CVE-2021-45105) exploitable?
CVE-2021-45105 carries a CVSS 5.9/10 (MEDIUM) rating and affects Apache Log4j 2 (log4j-core) 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1). Log4j2 did not guard against uncontrolled recursion from self-referential lookups. An attacker who controls Thread Context Map data can craft a string that triggers infinite recursion, crashing the application - a follow-on issue from the original Log4Shell disclosure.
How does Waratek mitigate Log4j Uncontrolled Recursion DoS (CVE-2021-45105)?
Waratek RASP blocks exploitation of Log4j Uncontrolled Recursion DoS (CVE-2021-45105) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.
How quickly was Log4j Uncontrolled Recursion DoS (CVE-2021-45105) exploited after disclosure?
A working exploit for CVE-2021-45105 was published within hours of its NVD disclosure, on December 18, 2021.
Protect your apps in production
Get protected against Log4j Uncontrolled Recursion DoS - without code changes or redeploying
Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2021-45105 and attacks like it, and get you covered in production.