๐Ÿ” CVE Alert

CVE-2026-105243

MEDIUM 5.3

Apache log4net: Oversize EventLogAppender record silently discarded

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

CWE CWE-778
Vendor apache software foundation
Product apache log4net
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache log4net

Be the first to know when new medium vulnerabilities affecting apache software foundation apache log4net are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Apache Software Foundation / Apache log4net
1.2.9 < 3.5.0
Apache Software Foundation / Apache log4net
02e1e115435888485f2e28b414d267e39e799e07 < 28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/logging-log4net/pull/315 github.com: https://github.com/apache/logging-log4net/commit/28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed lists.apache.org: https://lists.apache.org/thread.html/jr6fj5skv1vnjbc9jmt8bp151p8ow1rp

Credits

The Apache Software Foundation Claude Security Jan Friedrich