Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105242— Apache log4net: Request validation failure drops the event in the aspnet-request converter

Quick assessment

Affected
Apache Software Foundation Apache log4net
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache log4net 中 aspnet-request 模式转换器的异常条件处理不当漏洞 读取请求参数会触发 ASP.NET 请求验证,因此,携带包含标记(markup)等内容的请求会导致布局(layout)引发异常,进而导致附加器(appender)丢弃整个事件。攻击者(发送者)可以抑制自身请求的日志记录。仅使用 %aspnet-request 布局的 .NET Framework ASP.NET 应用程序会受到此问题影响。 此漏洞影响 Apache log4net:从 1.2.11 至 3.5.0 之前

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1078.001 · Default Accounts

Affected Version Matrix 2

VendorProduct Version RangeStatus
Apache Software Foundation Apache log4net 1.2.11< 3.5.0 affected
243f1e9f3ee235955bade4b4fe664a903378719a< 145203420c579a703008b4b723b6a080757f4964 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105242

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache log4net: Request validation failure drops the event in the aspnet-request converter
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对异常条件的处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache log4net 1.2.11 ~ 3.5.0 -
Apache Software Foundation Apache log4net 243f1e9f3ee235955bade4b4fe664a903378719a ~ 145203420c579a703008b4b723b6a080757f4964 -

II. Public POCs for CVE-2026-105242

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105242

请登录查看更多情报信息。

Other References for CVE-2026-105242 (3)

Same Patch Batch · Apache Software Foundation · 2026-10-06 · 8 CVEs total

CVE-2026-94114 5.9 MEDIUM Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in
CVE-2026-105244 5.3 MEDIUM Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
CVE-2026-105243 5.3 MEDIUM Apache log4net: Oversize EventLogAppender record silently discarded
CVE-2026-105241 5.3 MEDIUM Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
CVE-2026-105240 5.3 MEDIUM Apache log4net: NUL character truncates OutputDebugStringAppender records
CVE-2026-105239 5.3 MEDIUM Apache log4net: NUL character truncates EventLogAppender records
CVE-2026-105111 4.7 MEDIUM Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS

IV. Related Vulnerabilities

V. Comments for CVE-2026-105242

No comments yet


Leave a comment