Back to mods
Log4J2 JNDI Exploit Fix project artwork

CurseForge · Minecraft mod

Log4J2 JNDI Exploit Fix

This mod fixes a critical vulnerability in Log4J2 in conjunction with JNDI.

Choose a version Pick your version below, then grab the matching file.

Quick answer

Which Log4J2 JNDI Exploit Fix release should I use?

Updated 4 years ago
beta file 1.0.0 Forge 1.13.x-1.16.x
Game version 1.16-Snapshot, 1.16.3, 1.13.1
Loader Forge

Log4J2 JNDI Exploit Fix 1.0.0 Forge 1.13.x-1.16.x targets 1.16-Snapshot, 1.16.3, 1.13.1 with Forge. The project page does not say whether this file belongs on the client, dedicated server, or both. No extra mods listed for this file.

Where it goes

Is Log4J2 JNDI Exploit Fix required on the client, server, or both?

The project page does not say whether this file belongs on the client, dedicated server, or both.

Client Source doesn’t say
Dedicated server Source doesn’t say
Loader for this release Forge
Required install it here Optional supported, not mandatory Not supported do not install here Source doesn’t say do not assume

The source does not explicitly classify this release as client-only or server-only.

What else does Log4J2 JNDI Exploit Fix 1.0.0 Forge 1.13.x-1.16.x need?

1.0.0 Forge 1.13.x-1.16.x. Change the file and its required mods may change too.

No extra mods listed for this file

This file does not list any required mods. Do not add a library just because a different file uses it.

This file does not list any required or optional mods.

Before you install it

Add Log4J2 JNDI Exploit Fix without breaking your instance.

Built for Log4J2 JNDI Exploit Fix 1.0.0 Forge 1.13.x-1.16.x. Pick another file and the loader, install side or required mods may change.

  1. 01

    Stick to this file

    Use 1.0.0 Forge 1.13.x-1.16.x. It targets 1.16-Snapshot, 1.16.3, 1.13.1 with Forge; another release may have different loader, side or dependency requirements.

  2. 02

    Bring the mods it needs

    This file does not list any required mods. Do not add a library just because a different file uses it.

  3. 03

    Put it on the correct side

    The project page does not say whether this file belongs on the client, dedicated server, or both.

  4. 04

    Pick the file you checked

    Use the “Get this file” button beside 1.0.0 Forge 1.13.x-1.16.x. It opens that exact file at the source.

About this project

What does Log4J2 JNDI Exploit Fix add?

This is a tiny client and server, Fabric and Forge mod to fix the Log4J2 exploit that surfaced 2021-12-10 and may lead to crashes, stalls or remote code execution in some cases.

Instead of using this mod you should update your mod loader to the following versions, if possible:

  • Fabric Loader 0.12.12+ for all MC versions

  • Forge 1.18.1-39.0.0+ for MC 1.18.1

  • Forge 1.18-38.0.17+ for MC 1.18

  • Forge 1.17.1-37.1.1+ for MC 1.17.1

  • Forge 1.16.5-36.2.20+ for MC 1.16.5

  • Forge 1.15.2-31.2.56+ for MC 1.15.2

  • Forge 1.14.4-28.2.25+ for MC 1.14.4

  • Forge 1.13.2-25.0.222+ for MC 1.13.2

  • Forge 1.12.2-14.23.5.2857+ for MC 1.12.2

If your want to play Minecraft versions between 1.7 and 1.18 that are not in this list or you want to use mods that are incompatible with the updated mod loader versions, the Log4J2 JNDI Exploit Fix mod is a decent option.

This mod works by removing a highly problematic log content remote lookup feature, which is not used otherwise. If unmitigated anyone can draft a malicious chat or disconnect message, use mis-framed packets or other forms of activity that involves generating user controlled log output to exploit the bug. Since both client and server log, they are equally at risk.

Minecraft, CurseForge and Fabric Loader mitigated the problem in their launcher, but servers and some old versions remain vulnerable at the time of writing.

Likely fixed by their platform are currently and thus don't need the mod:

Likely vulnerable are currently and thus need the mod:

  • Unmitigated Vanilla server older than 1.18.1-rc3

  • Outdated Fabric or Forge server

  • Outdated Fabric or Forge client

  • Forge client or server older than 1.12

Incompatible with the mod:

  • Forge 1.17+ due to its module encapsulation - use the Java/JVM argument -Dlog4j2.formatMsgNoLookups=true instead (only works for 1.17+!)

  • Fabric with Loader 0.12.10+ as it comes with a similar fix, use Fabric Loader 0.12.12 instead of this mod

There should be no harm in using the mod even if it is not necessary outside the above incompatibilities. It does a small one time operation at startup to remove the superfluous but exploitable JNDI lookup mechanism.

There is no guarantee that the mod definitely fixes the exploit, but it acts on a fundamental level. It does not prevent exploiting messages from traversing the server to other clients.

Project description from CurseForge.

Pick your setup

Log4J2 JNDI Exploit Fix by Minecraft version and loader

Choose the version and loader you play, then open the matching release.

144 available setups

Showing the newest 12 of 85 game versions. Older files are in the list below.

Check the dependencies, then try the file in a copied instance before changing a world you care about.

Recent files

Log4J2 JNDI Exploit Fix versions and loaders

4 of 4 releases match

Looking for an older file? The official CurseForge project page is in Resources.