Apache log4net 的 EventLogAppender 中存在“对空字节(NUL 字符)的处理不当”漏洞。 当日志内容中包含 NUL 字符时,Windows 事件日志记录会在该位置被截断,导致布局渲染器在此之后生成的所有内容(包括异常文本和尾部字段)均被静默丢弃、未存储。攻击者若能将数据注入到日志消息中,即可隐藏该记录后续的部分内容。此漏洞仅影响在 Windows 平台上使用 EventLogAppender 的应用程序。 受影响版本为 Apache log4net 1.2.9 至 3.5.0(不含 3
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache log4net | 1.2.9< 3.5.0 |
affected |
02e1e115435888485f2e28b414d267e39e799e07< dc5855a0720c91590fd7a81d729ea01fdd69e000 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache log4net | 1.2.9 ~ 3.5.0 | - |
|
| Apache Software Foundation | Apache log4net | 02e1e115435888485f2e28b414d267e39e799e07 ~ dc5855a0720c91590fd7a81d729ea01fdd69e000 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94114 | 5.9 MEDIUM | Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in |
| CVE-2026-105244 | 5.3 MEDIUM | Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content |
| CVE-2026-105243 | 5.3 MEDIUM | Apache log4net: Oversize EventLogAppender record silently discarded |
| CVE-2026-105242 | 5.3 MEDIUM | Apache log4net: Request validation failure drops the event in the aspnet-request converter |
| CVE-2026-105241 | 5.3 MEDIUM | Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch |
| CVE-2026-105240 | 5.3 MEDIUM | Apache log4net: NUL character truncates OutputDebugStringAppender records |
| CVE-2026-105111 | 4.7 MEDIUM | Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS |
No comments yet