CVE-2026-105243
Received Received - Intake

Insufficient Logging in Apache log4net EventLogAppender

Vulnerability report for CVE-2026-105243, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Apache Software Foundation

Description

Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Apache Software Foundation Apache log4net 1.2.9
Apache Software Foundation Apache log4net 02e1e115435888485f2e28b414d267e39e799e07

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-778 When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an insufficient logging issue in Apache log4net's EventLogAppender. When log messages are too long, Windows Event Log truncates them beyond its size limit, causing the log entry to be lost without any error notification. Attackers could exploit this by crafting overly long log messages to suppress critical logging records.

Detection Guidance

Check if your system uses Apache log4net with EventLogAppender on Windows. Inspect log4net configuration files for EventLogAppender usage. Monitor Windows Event Logs for truncated or missing log entries, which may indicate exploitation.

Impact Analysis

If you use Apache log4net on Windows with EventLogAppender, attackers could hide malicious activities by making log messages long enough to be truncated. This could prevent detection of security incidents, errors, or compliance violations, leading to undetected breaches or operational issues.

Compliance Impact

This vulnerability could impact compliance by preventing proper logging of critical events required by regulations like GDPR (data processing records) or HIPAA (audit trails). Without complete logs, organizations may fail audits or be unable to prove compliance with data protection or security standards.

Mitigation Strategies

Upgrade Apache log4net to version 3.5.0 or later to address the insufficient logging vulnerability. Review and update log4net configurations to avoid using EventLogAppender if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105243. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart