CVE-2026-105242

NameCVE-2026-105242
DescriptionImproper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
log4net (PTS)trixie1.2.10+dfsg-9undetermined
forky, sid1.2.10+dfsg-10undetermined

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
log4netsource(unstable)undetermined

Notes

https://github.com/apache/logging-log4net/pull/316
Fixed by: https://github.com/apache/logging-log4net/commit/145203420c579a703008b4b723b6a080757f4964 (rc/3.5.0-rc1)
https://lists.apache.org/thread/zg6dbqm4ztm7j3c21nfsqj0yxm5yrpdx
check, might not affect our old version, upstream claims 12.11 onwards

Search for package or bug name: Reporting problems