Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105240— Apache log4net: NUL character truncates OutputDebugStringAppender records

Quick assessment

Affected
Apache Software Foundation Apache log4net
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache log4net 的 OutputDebugStringAppender 中存在空字节(NUL 字符)处理不当的漏洞。 当被记录的日志内容中包含 NUL 字符时,调试输出记录会在该位置终止,导致布局后续渲染的所有内容(包括异常文本和尾部字段)被静默丢弃。如果攻击者能够控制进入日志消息的数据,则可能隐藏记录中剩余的部分。仅在使用 OutputDebugStringAppender 的 Windows 平台上运行的应用程序会受到此问题影响。 该漏洞影响 Apache log4net 1.2.9 至 3.5.

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1078.004 · Cloud Accounts

Affected Version Matrix 2

VendorProduct Version RangeStatus
Apache Software Foundation Apache log4net 1.2.9< 3.5.0 affected
02e1e115435888485f2e28b414d267e39e799e07< 6046fe9d7f353b49fe995361c071ec2eea8f7ef6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105240

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache log4net: NUL character truncates OutputDebugStringAppender records
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NUL character in logged content ended the debug output record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently lost. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use OutputDebugStringAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
空字节或NULL字符转义处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache log4net 1.2.9 ~ 3.5.0 -
Apache Software Foundation Apache log4net 02e1e115435888485f2e28b414d267e39e799e07 ~ 6046fe9d7f353b49fe995361c071ec2eea8f7ef6 -

II. Public POCs for CVE-2026-105240

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105240

请登录查看更多情报信息。

Other References for CVE-2026-105240 (3)

Same Patch Batch · Apache Software Foundation · 2026-10-06 · 8 CVEs total

CVE-2026-94114 5.9 MEDIUM Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in
CVE-2026-105244 5.3 MEDIUM Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
CVE-2026-105243 5.3 MEDIUM Apache log4net: Oversize EventLogAppender record silently discarded
CVE-2026-105242 5.3 MEDIUM Apache log4net: Request validation failure drops the event in the aspnet-request converter
CVE-2026-105241 5.3 MEDIUM Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
CVE-2026-105239 5.3 MEDIUM Apache log4net: NUL character truncates EventLogAppender records
CVE-2026-105111 4.7 MEDIUM Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS

IV. Related Vulnerabilities

V. Comments for CVE-2026-105240

No comments yet


Leave a comment