Canva home
Help

Log4j2 Vulnerability Update


On 10th December, 2021 AEDT, we were made aware of a remote code execution vulnerability (CVE-2021-44228) related to Apache Log4j2, a popular Java logging library.

We undertook a thorough investigation to confirm that Canva desktop and mobile applications are not impacted by this vulnerability, and implemented layered mitigations to protect Canva systems and services. We are also working with our service providers to make sure they are taking appropriate action.

At this time, there is no action required from Canva customers. We are actively monitoring the issue and will provide status updates upon significant change.

People also viewed