CVE-2026-105242
Received
Received - Intake
Improper Exception Handling in Apache log4net ASP.NET Request Pattern
Vulnerability report for CVE-2026-105242, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: Apache Software Foundation
Description
Description
Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net.
Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected.
This issue affects Apache log4net: from 1.2.11 before 3.5.0.
Users are recommended to upgrade to version 3.5.0, which fixes the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Apache | Software | Foundation Apache log4net 1.2.11 |
| Apache | Software | Foundation Apache log4net 243f1e9f3ee235955bade4b4fe664a903378719a |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-755 | The product does not handle or incorrectly handles an exceptional condition. |