| Name | CVE-2026-105242 |
| Description | Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| log4net (PTS) | trixie | 1.2.10+dfsg-9 | undetermined |
| forky, sid | 1.2.10+dfsg-10 | undetermined |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| log4net | source | (unstable) | undetermined | | | |
Notes
https://github.com/apache/logging-log4net/pull/316
Fixed by: https://github.com/apache/logging-log4net/commit/145203420c579a703008b4b723b6a080757f4964 (rc/3.5.0-rc1)
https://lists.apache.org/thread/zg6dbqm4ztm7j3c21nfsqj0yxm5yrpdx
check, might not affect our old version, upstream claims 12.11 onwards