Improper Handling of Exceptional Conditions in Apache log4net for ASP.NET Applications
CVE-2026-105242

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105242?

A vulnerability exists in Apache log4net affecting ASP.NET applications, specifically when using the %aspnet-request layout. This flaw allows a malicious sender to suppress log records by submitting requests with special content, which triggers ASP.NET request validation. As a result, the entire log event may be discarded, leading to potential information loss. It is crucial for users of log4net versions prior to 3.5.0 to upgrade to the latest version to secure their applications against this issue.

Affected Version(s)

Apache log4net 1.2.11 < 3.5.0

Apache log4net 243f1e9f3ee235955bade4b4fe664a903378719a < 145203420c579a703008b4b723b6a080757f4964

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Security
Jan Friedrich
.