Improper Handling of Unicode Encoding in Apache log4net SmtpPickupDirAppender
CVE-2026-105241

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105241?

The SmtpPickupDirAppender component of Apache log4net is susceptible to an issue where improper handling of Unicode encoding, such as unpaired UTF-16 surrogates, can lead to disruptions in mail file writing processes. When this occurs, it results in the loss of buffered events, potentially leaving truncated mail files in the pickup directory. Consequently, this poses a risk of data suppression, where a third party can prevent the records of other log events from being captured. Applications that utilize the SmtpPickupDirAppender are specifically impacted, and it is strongly recommended that users upgrade to version 3.5.0 to rectify this issue.

Affected Version(s)

Apache log4net 1.2.9 < 3.5.0

Apache log4net 02e1e115435888485f2e28b414d267e39e799e07 < 4d2e10f0908199604b4326f9df6d0b43b871e333

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Security
Jan Friedrich
.