CVE-2026-105241
Received
Received - Intake
Unicode Handling Flaw in Apache log4net SmtpPickupDirAppender
Vulnerability report for CVE-2026-105241, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: Apache Software Foundation
Description
Description
Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net.
Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected.
This issue affects Apache log4net: from 1.2.9 before 3.5.0.
Users are recommended to upgrade to version 3.5.0, which fixes the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Apache | Software | Foundation Apache log4net 1.2.9 |
| Apache | Software | Foundation Apache log4net 02e1e115435888485f2e28b414d267e39e799e07 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-176 | The product does not properly handle when an input contains Unicode encoding. |