Insufficient Logging Vulnerability in Apache Log4net on Windows Platforms
CVE-2026-105243
5.3MEDIUM
What is CVE-2026-105243?
An insufficient logging vulnerability exists in Apache Log4net's EventLogAppender, particularly affecting Windows applications. When log messages exceed a certain length, they can truncate, resulting in the entire log record not being stored or reported. This means that if an attacker manipulates the logging process with long data, they can effectively suppress visibility of certain log entries, potentially obscuring malicious actions. To mitigate this issue, users should upgrade to version 3.5.0 where this vulnerability has been addressed.
Affected Version(s)
Apache log4net 1.2.9 < 3.5.0
Apache log4net 02e1e115435888485f2e28b414d267e39e799e07 < 28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The Apache Software Foundation
Claude Security
Jan Friedrich