Apache log4net 的 EventLogAppender 存在日志记录不足的漏洞。 当日志消息过长时,其内容会被截断至固定长度。在计入日志名和事件源名的长度后,该固定长度可能超过 Windows 事件日志所接受的上限。此时,事件日志无法存储任何内容,也不会生成任何报告。攻击者可通过构造足够长的日志消息,使其自身数据到达日志记录点,从而阻止整条日志记录的生成。 此漏洞仅影响在 Windows 平台上使用 EventLogAppender 的应用程序。 受影响的 Apache log4net 版本范围为:1.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache log4net | 1.2.9< 3.5.0 |
affected |
02e1e115435888485f2e28b414d267e39e799e07< 28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache log4net | 1.2.9 ~ 3.5.0 | - |
|
| Apache Software Foundation | Apache log4net | 02e1e115435888485f2e28b414d267e39e799e07 ~ 28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94114 | 5.9 MEDIUM | Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in |
| CVE-2026-105244 | 5.3 MEDIUM | Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content |
| CVE-2026-105242 | 5.3 MEDIUM | Apache log4net: Request validation failure drops the event in the aspnet-request converter |
| CVE-2026-105241 | 5.3 MEDIUM | Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch |
| CVE-2026-105240 | 5.3 MEDIUM | Apache log4net: NUL character truncates OutputDebugStringAppender records |
| CVE-2026-105239 | 5.3 MEDIUM | Apache log4net: NUL character truncates EventLogAppender records |
| CVE-2026-105111 | 4.7 MEDIUM | Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS |
No comments yet