Improper Output Encoding in Apache log4net RemoteSyslogAppender
CVE-2026-105244

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105244?

The Apache log4net RemoteSyslogAppender contains a vulnerability that results in improper encoding of output. Specifically, characters outside visible ASCII and space are stripped from log records instead of being properly escaped. This issue leads to the potential for distinct values to appear identical in logged messages, creating a risk of data misrepresentation. Users are urged to upgrade to version 3.5.0 or later to mitigate this issue and ensure accurate logging.

Affected Version(s)

Apache log4net 1.2.12 < 3.5.0

Apache log4net 56a2e146e21ff4737e1ff3ec308810e667873947 < 77717061b20d4346b6c0ce6b54643d85fb348bc7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Security
Jan Friedrich
.