CVE-2026-105239

NameCVE-2026-105239
DescriptionImproper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently not stored. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
log4net (PTS)trixie1.2.10+dfsg-9vulnerable
forky, sid1.2.10+dfsg-10vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
log4netsource(unstable)(unfixed)

Notes

https://github.com/apache/logging-log4net/pull/315
Fixed by: https://github.com/apache/logging-log4net/commit/dc5855a0720c91590fd7a81d729ea01fdd69e000 (rc/3.5.0-rc1)
https://lists.apache.org/thread/9fx1qo5hc0tg8ym0t6p9gt1zpb2qlxpq

Search for package or bug name: Reporting problems