Apache log4net 中 aspnet-request 模式转换器的异常条件处理不当漏洞 读取请求参数会触发 ASP.NET 请求验证,因此,携带包含标记(markup)等内容的请求会导致布局(layout)引发异常,进而导致附加器(appender)丢弃整个事件。攻击者(发送者)可以抑制自身请求的日志记录。仅使用 %aspnet-request 布局的 .NET Framework ASP.NET 应用程序会受到此问题影响。 此漏洞影响 Apache log4net:从 1.2.11 至 3.5.0 之前
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache log4net | 1.2.11< 3.5.0 |
affected |
243f1e9f3ee235955bade4b4fe664a903378719a< 145203420c579a703008b4b723b6a080757f4964 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache log4net | 1.2.11 ~ 3.5.0 | - |
|
| Apache Software Foundation | Apache log4net | 243f1e9f3ee235955bade4b4fe664a903378719a ~ 145203420c579a703008b4b723b6a080757f4964 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94114 | 5.9 MEDIUM | Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in |
| CVE-2026-105244 | 5.3 MEDIUM | Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content |
| CVE-2026-105243 | 5.3 MEDIUM | Apache log4net: Oversize EventLogAppender record silently discarded |
| CVE-2026-105241 | 5.3 MEDIUM | Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch |
| CVE-2026-105240 | 5.3 MEDIUM | Apache log4net: NUL character truncates OutputDebugStringAppender records |
| CVE-2026-105239 | 5.3 MEDIUM | Apache log4net: NUL character truncates EventLogAppender records |
| CVE-2026-105111 | 4.7 MEDIUM | Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS |
No comments yet