CVE-2026-105239: Apache log4net: NUL character truncates EventLogAppender records
Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net.
A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently not stored. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use EventLogAppender are affected.
This issue affects Apache log4net: from 1.2.9 before 3.5.0.
Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache log4netto a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Frequently Asked Questions
Which deployments are affected?
Only Windows applications that use Apache log4net's EventLogAppender are affected. Other platforms and log4net configurations that do not use this appender are not identified as affected.
What must an attacker be able to do to exploit this issue?
A party must be able to cause a NUL character to reach content written to a log message. The NUL terminates the Windows Event Log record, preventing subsequently rendered content, such as exception text and trailing fields, from being stored.
Which versions need remediation?
Apache log4net versions from 1.2.9 before 3.5.0 are affected. Upgrade to version 3.5.0, which fixes the issue.