TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries.
A Reported Log4j RCE Is More Complicated Than It Looks
calendar_today
August 27, 2026
person
research@sonatype.com (Sonatype Research Team)
domain
sonatype