Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105241— Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch

Quick assessment

Affected
Apache Software Foundation Apache log4net
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache log4net 中 SmtpPickupDirAppender 存在不当处理 Unicode 编码的漏洞。 当邮件文件写入器无法编码某些内容(例如未配对的 UTF-16 代理对)时,会导致写入操作抛出异常。在此情况下,批处理中的每一个缓冲事件(包括非问题事件)都会被丢弃,仅问题事件所携带的内容导致异常,但最终结果是整个批次的所有日志事件记录全部丢失,且在邮件拾取目录中可能残留一封不完整(截断)的邮件。如果攻击者能够控制数据并将其插入到日志消息中,则可阻止其他事件记录的保存,从而抑制日志记录。 仅使用

CVSS 5.3 · Medium

Possible ATT&CK Techniques 2 AI

T1078 · Valid Accounts T1562

Affected Version Matrix 2

VendorProduct Version RangeStatus
Apache Software Foundation Apache log4net 1.2.9< 3.5.0 affected
02e1e115435888485f2e28b414d267e39e799e07< 4d2e10f0908199604b4326f9df6d0b43b871e333 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105241

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
Unicode编码处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache log4net 1.2.9 ~ 3.5.0 -
Apache Software Foundation Apache log4net 02e1e115435888485f2e28b414d267e39e799e07 ~ 4d2e10f0908199604b4326f9df6d0b43b871e333 -

II. Public POCs for CVE-2026-105241

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105241

请登录查看更多情报信息。

Other References for CVE-2026-105241 (3)

Same Patch Batch · Apache Software Foundation · 2026-10-06 · 8 CVEs total

CVE-2026-94114 5.9 MEDIUM Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in
CVE-2026-105244 5.3 MEDIUM Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
CVE-2026-105243 5.3 MEDIUM Apache log4net: Oversize EventLogAppender record silently discarded
CVE-2026-105242 5.3 MEDIUM Apache log4net: Request validation failure drops the event in the aspnet-request converter
CVE-2026-105240 5.3 MEDIUM Apache log4net: NUL character truncates OutputDebugStringAppender records
CVE-2026-105239 5.3 MEDIUM Apache log4net: NUL character truncates EventLogAppender records
CVE-2026-105111 4.7 MEDIUM Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS

IV. Related Vulnerabilities

V. Comments for CVE-2026-105241

No comments yet


Leave a comment