Why removing the class breaks old servers
In December 2021 the Log4Shell vulnerability, CVE-2021-44228, affected Java Edition servers. One mitigation Apache documents for log4j versions that cannot be upgraded is to delete JndiLookup.class from the log4j-core jar with a zip command.
Minecraft 1.7 to 1.11.2 ships log4j 2.0-beta9. In that version, log4j creates the JndiLookup class directly when logging starts, with no guard, so a missing class throws at the first log line and the server exits. Log4j 2.8.1, which Minecraft 1.12 to 1.16.5 ships, loads the class inside a guard and only prints a warning.
| Minecraft version | log4j-core | With JndiLookup.class removed |
|---|---|---|
| 1.7 to 1.11.2 | 2.0-beta9 | The server crashes at start-up. |
| 1.12 to 1.16.5 | 2.8.1 | A warning, JNDI lookup class is not available, and the server keeps running. |
The class lives in the log4j-core jar under libraries/ on a Forge install, and also inside the vanilla server jar itself, so either can be the one that was changed.
How to fix it
- Check the Minecraft version. On 1.7 to 1.11.2 this needs fixing; on 1.12 to 1.16.5 the JNDI lookup class is not available warning can be ignored.
- Find what removed the class: a host panel's Log4j tool, a security scanner, a startup script, or someone running the zip command. Turn it off first, or it will remove the class again.
- Restore the original jar. Download the vanilla server jar for your version from Mojang again, and on Forge run the Forge installer again or restore the log4j-core jar from a clean install.
- Apply Mojang's own mitigation for these versions instead: put log4j2_17-111.xml in the server folder and add -Dlog4j.configurationFile=log4j2_17-111.xml to the start command (1.12 to 1.16.5 use log4j2_112-116.xml). Get the file from Mojang's announcement, not a mirror.
- Restart and confirm the server reaches Done.
Warning
The -Dlog4j2.formatMsgNoLookups=true flag is not a mitigation on these versions. Apache documents it for log4j 2.10 and later, and Minecraft 1.7 to 1.16.5 ships older log4j.
Old Minecraft versions need an old Java as well. Check which one your version expects.
Look up the Java versionWhat MineXHost's launcher does with this crash
Before every start, MineXEngine, our launcher, checks the log4j jars on the server, including the vanilla server jar, and replaces JndiLookup.class with a small inert version instead of removing it. That keeps 1.7 to 1.11.2 servers starting while the JNDI lookup behind Log4Shell does nothing. If it finds a jar where the class is already missing, it puts the inert version back.
If the crash appears anyway, the engine runs that repair once more rather than blaming a mod. It does not upgrade log4j or change your Minecraft or Forge version, and this protection covers CVE-2021-44228, not every log4j advisory.
MineXHost runs Forge and vanilla servers on MineXEngine. Our launcher detects the modpack, picks the right Minecraft loader and Java version, tunes the JVM for your RAM, and auto-recovers from the crashes that normally end a modded server's evening. Pick your RAM, paste the pack, and play.
See hosting plansFrequently asked questions
Why does my old Minecraft server crash with NoClassDefFoundError JndiLookup?
An old Minecraft server crashes with NoClassDefFoundError JndiLookup because Minecraft 1.7 to 1.11.2 ships log4j 2.0-beta9, which creates the JndiLookup class directly when logging starts, so if a Log4Shell fix removed that class from the jar the server dies at its first log line. Restore the jar and use Mojang's configuration-file mitigation.
Is it safe to remove JndiLookup.class to fix Log4Shell?
Removing JndiLookup.class is Apache's documented mitigation for log4j versions that cannot be upgraded, but on Minecraft 1.7 to 1.11.2 it stops the server from starting because log4j 2.0-beta9 cannot run without the class, while on 1.12 to 1.16.5 it only produces a warning. Old servers should use Mojang's published configuration file instead.
I see “JNDI lookup class is not available” on 1.16.5. Is my server broken?
A Minecraft 1.12 to 1.16.5 server that logs JNDI lookup class is not available is not broken: the line is a warning from log4j 2.8.1 saying it could not load the JndiLookup class and is continuing without JNDI lookups, which is the effect a Log4Shell fix wants. The server keeps running normally.
Does -Dlog4j2.formatMsgNoLookups=true protect old servers?
The -Dlog4j2.formatMsgNoLookups=true flag does not protect Minecraft 1.7 to 1.16.5 servers, because Apache documents that setting as a mitigation for log4j 2.10 and later and those Minecraft versions ship log4j 2.0-beta9 or 2.8.1, so on them the flag does nothing. Mojang's instructions for those versions use a configuration file.
