CVE-2026-105244

Summary

Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net.

Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected.

This issue affects Apache log4net: from 1.2.12 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache log4net1.2.12 < 3.5.0affected
Apache Software FoundationApache log4net56a2e146e21ff4737e1ff3ec308810e667873947 < 77717061b20d4346b6c0ce6b54643d85fb348bc7affected

Weaknesses

  • CWE-116: CWE-116 Improper Encoding or Escaping of Output

References