---
id: CVE-2026-105241
title: >-
  Improper Handling of Unicode Encoding vulnerability in the
  SmtpPickupDirAppender of Apache log4net.


  Content that the mail file writer cannot encode, such as an unpaired UTF-16
  surrogate, made the write throw
summary: >-
  Improper Handling of Unicode Encoding vulnerability in the
  SmtpPickupDirAppender of Apache log4net.


  Content that the mail file writer cannot encode, such as an unpaired UTF-16
  surrogate, made the write throw. Every buffered event in the…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-176
vendor: Apache Software Foundation
product: log4net
affected:
  - log4net >= 1.2.9 < 3.5.0
  - >-
    log4net >= 02e1e115435888485f2e28b414d267e39e799e07 <
    4d2e10f0908199604b4326f9df6d0b43b871e333
published: '2026-10-06'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T15:17:06.543'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105241'
references:
  - url: >-
      https://github.com/apache/logging-log4net/commit/4d2e10f0908199604b4326f9df6d0b43b871e333
    label: security@apache.org
  - url: 'https://github.com/apache/logging-log4net/pull/315'
    label: security@apache.org
  - url: 'https://lists.apache.org/thread.html/hg8dgh3oy8bp3dhb8nsygk9kw2o401ws'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/10/07/15'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-07T14:44:42.702949Z'
ingestedAt: '2026-10-06T20:16:42.478Z'
---

## Overview

Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net.

Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected.

This issue affects Apache log4net: from 1.2.9 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
