๐Ÿ” CVE Alert

CVE-2026-105242

MEDIUM 5.3

Apache log4net: Request validation failure drops the event in the aspnet-request converter

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

CWE CWE-755
Vendor apache software foundation
Product apache log4net
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache log4net

Be the first to know when new medium vulnerabilities affecting apache software foundation apache log4net are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Apache Software Foundation / Apache log4net
1.2.11 < 3.5.0
Apache Software Foundation / Apache log4net
243f1e9f3ee235955bade4b4fe664a903378719a < 145203420c579a703008b4b723b6a080757f4964

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/logging-log4net/pull/316 github.com: https://github.com/apache/logging-log4net/commit/145203420c579a703008b4b723b6a080757f4964 lists.apache.org: https://lists.apache.org/thread.html/zg6dbqm4ztm7j3c21nfsqj0yxm5yrpdx

Credits

The Apache Software Foundation Claude Security Jan Friedrich