5.3

CVE-2026-105244

Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content

Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net.

Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected.

This issue affects Apache log4net: from 1.2.12 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt Apache log4net
Default Statusunaffected
Version 1.2.12
Version < 3.5.0
Status affected
HerstellerApache Software Foundation
≫
Produkt Apache log4net
Default Statusunaffected
Version 56a2e146e21ff4737e1ff3ec308810e667873947
Version < 77717061b20d4346b6c0ce6b54643d85fb348bc7
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.251
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Apache 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-116 Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

https://github.com/apache/logging-log4net/pull/315
https://github.com/apache/logging-log4net/commit/77717061b20d4346b6c0ce6b54643d85fb348bc7
https://lists.apache.org/thread.html/q7649hhdodthoqw8jsjgtnb4m8qfy6d6
http://www.openwall.com/lists/oss-security/2026/10/07/19