CVE-2026-105243
Apache log4net: Oversize EventLogAppender record silently discarded
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
| CWE | CWE-778 |
| Vendor | apache software foundation |
| Product | apache log4net |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache log4net
Be the first to know when new medium vulnerabilities affecting apache software foundation apache log4net are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
Apache Software Foundation / Apache log4net
1.2.9 < 3.5.0
Apache Software Foundation / Apache log4net
02e1e115435888485f2e28b414d267e39e799e07 < 28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed
References
Credits
The Apache Software Foundation Claude Security Jan Friedrich