Improper Neutralization Vulnerability in Apache log4net Affects Windows Event Logging
CVE-2026-105239
5.3MEDIUM
What is CVE-2026-105239?
An improper neutralization vulnerability in the EventLogAppender of Apache log4net allows NUL characters to truncate logged content. This means that any data entered before a NUL character will be stored in the Windows Event Log, but any subsequent details are lost. This exposes a risk for Windows applications that utilize EventLogAppender, as malicious users could exploit this to conceal critical information from the logs. Users are advised to upgrade to log4net version 3.5.0 or later to mitigate this issue.
Affected Version(s)
Apache log4net 1.2.9 < 3.5.0
Apache log4net 02e1e115435888485f2e28b414d267e39e799e07
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The Apache Software Foundation
Claude Security
Jan Friedrich