CVE-2026-105244

Source
https://cve.org/CVERecord?id=CVE-2026-105244
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105244.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105244
Downstream
Published
2026-10-06T19:52:31Z
Modified
2026-10-09T02:30:17Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
Details

Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net.

Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected.

This issue affects Apache log4net: from 1.2.12 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Database specific
{
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-116"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105244.json"
}
References

Affected packages

Git / gitbox.apache.org/repos/asf/logging-log4net.git

Affected ranges

Type
GIT
Repo
https://gitbox.apache.org/repos/asf/logging-log4net.git
Events
Introduced
56a2e146e21ff4737e1ff3ec308810e667873947
Fixed
77717061b20d4346b6c0ce6b54643d85fb348bc7
Type
GIT
Repo
https://github.com/apache/logging-log4net
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.2.12"
        },
        {
            "fixed": "3.5.0"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

rc/3.*
rc/3.0.1-preview.1
rc/3.0.1-preview.2
rc/3.0.1-rc1
rc/3.0.2-rc1
rc/3.0.3-preview.1
rc/3.0.3-rc1
rc/3.0.4-preview.1
rc/3.0.4-rc1
rc/3.1.0-rc1
rc/3.2.0-preview.1
rc/3.2.0-rc1
rc/3.3.0-rc1
rc/3.3.1-rc1
rc/3.3.2-rc1
rc/3.4.0-preview.1
rc/3.4.0-rc1
rc/3.4.1-preview.1
Other
rc/temp
rel/2.*
rel/2.0.10
rel/2.0.11
rel/2.0.12
rel/2.0.13
rel/2.0.14
rel/2.0.15
rel/2.0.16
rel/2.0.17
rel/2.x
rel/3.*
rel/3.0.1
rel/3.0.2
rel/3.0.3
rel/3.0.4
rel/3.1.0
rel/3.2.0
rel/3.3.0
rel/3.3.1
rel/3.3.2
rel/3.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105244.json"