Improper Neutralization Vulnerability in Apache log4net Affects Windows Event Logging
CVE-2026-105239

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105239?

An improper neutralization vulnerability in the EventLogAppender of Apache log4net allows NUL characters to truncate logged content. This means that any data entered before a NUL character will be stored in the Windows Event Log, but any subsequent details are lost. This exposes a risk for Windows applications that utilize EventLogAppender, as malicious users could exploit this to conceal critical information from the logs. Users are advised to upgrade to log4net version 3.5.0 or later to mitigate this issue.

Affected Version(s)

Apache log4net 1.2.9 < 3.5.0

Apache log4net 02e1e115435888485f2e28b414d267e39e799e07

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Security
Jan Friedrich
.