CVE-2026-105244
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Summary
Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net.
Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected.
This issue affects Apache log4net: from 1.2.12 before 3.5.0.
Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache log4net | 1.2.12 < 3.5.0 | affected |
| Apache Software Foundation | Apache log4net | 56a2e146e21ff4737e1ff3ec308810e667873947 < 77717061b20d4346b6c0ce6b54643d85fb348bc7 | affected |
Weaknesses
- CWE-116: CWE-116 Improper Encoding or Escaping of Output
References
- https://github.com/apache/logging-log4net/pull/315
- https://github.com/apache/logging-log4net/commit/77717061b20d4346b6c0ce6b54643d85fb348bc7
- https://lists.apache.org/thread.html/q7649hhdodthoqw8jsjgtnb4m8qfy6d6
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.