OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-105240

MEDIUM · CVSS 5.3 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects Apache log4net versions from 1.2.9 to 3.5.0 on Windows systems using the OutputDebugStringAppender, allowing a NUL character in logged content to truncate debug output and potentially conceal critical information. This could lead to loss of important exception details and other log data, making it harder to diagnose issues or detect malicious activity. Organizations utilizing affected versions of log4net should prioritize upgrading to version 3.5.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105240
Severity
MEDIUM
CVSS
5.3
EPSS
0.33%
Windows Apache

Original NVD Description

Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NUL character in logged content ended the debug output record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently lost. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use OutputDebugStringAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)