Improper Handling of Unicode Encoding in Apache log4net SmtpPickupDirAppender
CVE-2026-105241
What is CVE-2026-105241?
The SmtpPickupDirAppender component of Apache log4net is susceptible to an issue where improper handling of Unicode encoding, such as unpaired UTF-16 surrogates, can lead to disruptions in mail file writing processes. When this occurs, it results in the loss of buffered events, potentially leaving truncated mail files in the pickup directory. Consequently, this poses a risk of data suppression, where a third party can prevent the records of other log events from being captured. Applications that utilize the SmtpPickupDirAppender are specifically impacted, and it is strongly recommended that users upgrade to version 3.5.0 to rectify this issue.
Affected Version(s)
Apache log4net 1.2.9 < 3.5.0
Apache log4net 02e1e115435888485f2e28b414d267e39e799e07 < 4d2e10f0908199604b4326f9df6d0b43b871e333
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved