๐Ÿ” CVE Alert

CVE-2026-105244

MEDIUM 5.3

Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected. This issue affects Apache log4net: from 1.2.12 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

CWE CWE-116
Vendor apache software foundation
Product apache log4net
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache log4net

Be the first to know when new medium vulnerabilities affecting apache software foundation apache log4net are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Apache Software Foundation / Apache log4net
1.2.12 < 3.5.0
Apache Software Foundation / Apache log4net
56a2e146e21ff4737e1ff3ec308810e667873947 < 77717061b20d4346b6c0ce6b54643d85fb348bc7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/logging-log4net/pull/315 github.com: https://github.com/apache/logging-log4net/commit/77717061b20d4346b6c0ce6b54643d85fb348bc7 lists.apache.org: https://lists.apache.org/thread.html/q7649hhdodthoqw8jsjgtnb4m8qfy6d6

Credits

The Apache Software Foundation Claude Security Jan Friedrich