Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <d44696e2-320b-8cf3-5cc5-a1c774b06556@apache.org>
Date: Tue, 06 Oct 2026 19:43:24 +0000
From: Jan Friedrich <freeandnil@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2026-105243: Apache log4net: Oversize EventLogAppender record
 silently discarded 

Severity: moderate 
    CVSS 3.1: 5.3 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected versions:

- Apache log4net 1.2.9 before 3.5.0
- Apache log4net 02e1e115435888485f2e28b414d267e39e799e07 before 28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed

Description:

Insufficient Logging vulnerability in the EventLogAppender of Apache log4net.

Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected.

This issue affects Apache log4net: from 1.2.9 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Credit:

The Apache Software Foundation (finder)
Claude Security (tool)
Jan Friedrich (remediation developer)

References:

https://github.com/apache/logging-log4net/pull/315
https://github.com/apache/logging-log4net/commit/28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed
https://logging.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-105243

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.