Insufficient Logging Vulnerability in Apache Log4net on Windows Platforms
CVE-2026-105243

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105243?

An insufficient logging vulnerability exists in Apache Log4net's EventLogAppender, particularly affecting Windows applications. When log messages exceed a certain length, they can truncate, resulting in the entire log record not being stored or reported. This means that if an attacker manipulates the logging process with long data, they can effectively suppress visibility of certain log entries, potentially obscuring malicious actions. To mitigate this issue, users should upgrade to version 3.5.0 where this vulnerability has been addressed.

Affected Version(s)

Apache log4net 1.2.9 < 3.5.0

Apache log4net 02e1e115435888485f2e28b414d267e39e799e07 < 28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Security
Jan Friedrich
.