Apache log4net 的 OutputDebugStringAppender 中存在空字节(NUL 字符)处理不当的漏洞。 当被记录的日志内容中包含 NUL 字符时,调试输出记录会在该位置终止,导致布局后续渲染的所有内容(包括异常文本和尾部字段)被静默丢弃。如果攻击者能够控制进入日志消息的数据,则可能隐藏记录中剩余的部分。仅在使用 OutputDebugStringAppender 的 Windows 平台上运行的应用程序会受到此问题影响。 该漏洞影响 Apache log4net 1.2.9 至 3.5.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache log4net | 1.2.9< 3.5.0 |
affected |
02e1e115435888485f2e28b414d267e39e799e07< 6046fe9d7f353b49fe995361c071ec2eea8f7ef6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache log4net | 1.2.9 ~ 3.5.0 | - |
|
| Apache Software Foundation | Apache log4net | 02e1e115435888485f2e28b414d267e39e799e07 ~ 6046fe9d7f353b49fe995361c071ec2eea8f7ef6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94114 | 5.9 MEDIUM | Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in |
| CVE-2026-105244 | 5.3 MEDIUM | Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content |
| CVE-2026-105243 | 5.3 MEDIUM | Apache log4net: Oversize EventLogAppender record silently discarded |
| CVE-2026-105242 | 5.3 MEDIUM | Apache log4net: Request validation failure drops the event in the aspnet-request converter |
| CVE-2026-105241 | 5.3 MEDIUM | Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch |
| CVE-2026-105239 | 5.3 MEDIUM | Apache log4net: NUL character truncates EventLogAppender records |
| CVE-2026-105111 | 4.7 MEDIUM | Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS |
No comments yet