end-of-life.org

Apache Log4j 2.12 End of Life

Support dates and upgrade guidance — rebuilt from live data.

End of Life

Apache Log4j 2.12 reached end of life on 14 Dec 2021. It no longer receives security fixes.

1,699 days without security patches
Recommended action: upgrade to Apache Log4j 2.

Support timeline

Official dates from the Apache Log4j release process.

MilestoneDateStatus
Initial release26 Jun 2019
End of life 14 Dec 2021 4.7 years ago
Latest release2.12.4 · 28 Dec 2021 final

Where to go from 2.12

Recommended target: Apache Log4j 2.

The newest actively supported branch is Apache Log4j 2 (latest release 2.26.1).

Frequently asked questions

Is Apache Log4j 2.12 still safe to use?

Apache Log4j 2.12 reached end of life on 14 Dec 2021, 1,699 days ago, and is no longer covered by standard support. Running it means no guaranteed security fixes.

Can I still download Apache Log4j 2.12?

Yes — the final release (2.12.4) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.

What should I upgrade Apache Log4j 2.12 to?

Upgrade to Apache Log4j 2, the newest actively supported branch.

All Apache Log4j versions