CVE-2026-105243

Summary

Insufficient Logging vulnerability in the EventLogAppender of Apache log4net.

Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected.

This issue affects Apache log4net: from 1.2.9 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache log4net1.2.9 < 3.5.0affected
Apache Software FoundationApache log4net02e1e115435888485f2e28b414d267e39e799e07 < 28fbfb25678c48a8cc5bc9b94ead0dddfc39ffedaffected

Weaknesses

  • CWE-778: CWE-778 Insufficient Logging

References