CVE-2026-105242: Apache log4net: Request validation failure drops the event in the aspnet-request converter

Published Oct 6, 2026
·
Updated

Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net.

Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected.

This issue affects Apache log4net: from 1.2.11 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Affected Software

1 affected component
Apache log4net>=1.2.11<3.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache log4net to a version that resolves this vulnerability.

    Fixed in 3.5.0

Event History

Oct 6, 2026
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Only ASP.NET applications running on .NET Framework are affected, and only when their log4net layout uses the %aspnet-request pattern converter. Applications outside that combination are not identified as affected.

2

What does an attacker need to do to exploit this?

An unauthenticated remote sender can submit a request containing content that triggers ASP.NET request validation, such as markup. When %aspnet-request reads the request parameters, the resulting exception causes the appender to discard that request's entire log event.

3

What is the security impact?

The attacker can suppress the log record for their own request. The provided impact vector indicates integrity impact only; no confidentiality or availability impact is specified.

4

What versions should be remediated?

Apache log4net versions from 1.2.11 before 3.5.0 are affected in the specified ASP.NET .NET Framework configuration. Upgrade to version 3.5.0, which fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203