VulnSea

log4net vulnerabilities

CVEs whose affected-version data names the log4net package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-105240Medium· 5.3
yesterday

Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NUL character in logged content ended the debug output record at that point, so everything the layout rendered aft…

Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NUL character in logged content ended the debug output record at that point, so everything the layout rendered aft…

▾ SunlitApache Software Foundation · log4netvia NVD
CVE-2026-105241Medium· 5.3
yesterday

Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw

Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the…

▾ SunlitApache Software Foundation · log4netvia NVD
CVE-2026-105242Medium· 5.3
yesterday

Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the l…

Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the l…

▾ SunlitApache Software Foundation · log4netvia NVD
CVE-2026-105243Medium· 5.3
yesterday

Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then…

Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then…

▾ SunlitApache Software Foundation · log4netvia NVD
CVE-2026-105244Medium· 5.3
yesterday

Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control cha…

Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control cha…

▾ SunlitApache Software Foundation · log4netvia NVD
CVE-2026-105239Medium· 5.3
yesterday

Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after i…

Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after i…

▾ SunlitApache Software Foundation · log4netvia NVD
log4net vulnerabilities (CVEs) · VulnSea