Improper Output Encoding in Apache log4net RemoteSyslogAppender
CVE-2026-105244
5.3MEDIUM
What is CVE-2026-105244?
The Apache log4net RemoteSyslogAppender contains a vulnerability that results in improper encoding of output. Specifically, characters outside visible ASCII and space are stripped from log records instead of being properly escaped. This issue leads to the potential for distinct values to appear identical in logged messages, creating a risk of data misrepresentation. Users are urged to upgrade to version 3.5.0 or later to mitigate this issue and ensure accurate logging.
Affected Version(s)
Apache log4net 1.2.12 < 3.5.0
Apache log4net 56a2e146e21ff4737e1ff3ec308810e667873947 < 77717061b20d4346b6c0ce6b54643d85fb348bc7
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The Apache Software Foundation
Claude Security
Jan Friedrich