CVE-2026-105242: Apache log4net: Request validation failure drops the event in the aspnet-request converter
Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net.
Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected.
This issue affects Apache log4net: from 1.2.11 before 3.5.0.
Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache log4netto a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Frequently Asked Questions
Which deployments are affected?
Only ASP.NET applications running on .NET Framework are affected, and only when their log4net layout uses the %aspnet-request pattern converter. Applications outside that combination are not identified as affected.
What does an attacker need to do to exploit this?
An unauthenticated remote sender can submit a request containing content that triggers ASP.NET request validation, such as markup. When %aspnet-request reads the request parameters, the resulting exception causes the appender to discard that request's entire log event.
What is the security impact?
The attacker can suppress the log record for their own request. The provided impact vector indicates integrity impact only; no confidentiality or availability impact is specified.
What versions should be remediated?
Apache log4net versions from 1.2.11 before 3.5.0 are affected in the specified ASP.NET .NET Framework configuration. Upgrade to version 3.5.0, which fixes the issue.