OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-105239

MEDIUM · CVSS 5.3 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the EventLogAppender in Apache log4net, specifically on Windows systems, where a NUL character in logged content can truncate event log records, leading to loss of critical information such as exception details. This could allow malicious actors to obscure important log data, potentially hindering incident response efforts. Organizations using affected versions of log4net (1.2.9 to 3.5.0) should prioritize upgrading to version 3.5.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105239
Severity
MEDIUM
CVSS
5.3
EPSS
0.34%
Windows Apache

Original NVD Description

Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently not stored. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)