Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105244— Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content

Quick assessment

Affected
Apache Software Foundation Apache log4net
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache log4net 的 RemoteSyslogAppender 存在输出编码或转义不当漏洞。 该漏洞导致记录中所有非可见 ASCII 字符和空格字符被直接移除,而非进行正确转义,因此非 ASCII 文本和控制字符(如制表符)会无声消失。攻击者可以利用此特性,通过在其数据中插入特殊字符(例如零宽空格),使原本不同的值在日志记录中变得相同。例如,包含零宽空格的用户名可能在日志中显示为 “admin”,从而引发混淆或安全绕过。 仅使用 RemoteSyslogAppender 的应用程序受此漏洞影响。 该漏洞

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1564.004 · NTFS File Attributes

Affected Version Matrix 2

VendorProduct Version RangeStatus
Apache Software Foundation Apache log4net 1.2.12< 3.5.0 affected
56a2e146e21ff4737e1ff3ec308810e667873947< 77717061b20d4346b6c0ce6b54643d85fb348bc7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105244

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected. This issue affects Apache log4net: from 1.2.12 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对输出编码和转义不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache log4net 1.2.12 ~ 3.5.0 -
Apache Software Foundation Apache log4net 56a2e146e21ff4737e1ff3ec308810e667873947 ~ 77717061b20d4346b6c0ce6b54643d85fb348bc7 -

II. Public POCs for CVE-2026-105244

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105244

请登录查看更多情报信息。

Other References for CVE-2026-105244 (3)

Same Patch Batch · Apache Software Foundation · 2026-10-06 · 8 CVEs total

CVE-2026-94114 5.9 MEDIUM Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in
CVE-2026-105243 5.3 MEDIUM Apache log4net: Oversize EventLogAppender record silently discarded
CVE-2026-105242 5.3 MEDIUM Apache log4net: Request validation failure drops the event in the aspnet-request converter
CVE-2026-105241 5.3 MEDIUM Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
CVE-2026-105240 5.3 MEDIUM Apache log4net: NUL character truncates OutputDebugStringAppender records
CVE-2026-105239 5.3 MEDIUM Apache log4net: NUL character truncates EventLogAppender records
CVE-2026-105111 4.7 MEDIUM Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS

IV. Related Vulnerabilities

V. Comments for CVE-2026-105244

No comments yet


Leave a comment