PT-2026-107179 · Apache · Log4Net

·

CVE-2026-105239

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache log4net versions 1.2.9 through 3.4.x
Description Improper neutralization of null bytes or NUL characters in the EventLogAppender allows a NUL character in logged content to truncate the Windows Event Log record. This results in all subsequent data rendered by the layout, such as exception text and trailing fields, being silently omitted. An attacker capable of injecting data into a log message could use this to hide the remainder of the record. This issue specifically affects applications running on Windows that utilize the EventLogAppender.
Recommendations Upgrade to version 3.5.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105239

Affected Products

Log4Net