OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-105242

MEDIUM · CVSS 5.3 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Apache log4net versions from 1.2.11 to 3.5.0 are vulnerable due to improper handling of exceptional conditions in the aspnet-request pattern converter, allowing attackers to suppress log records of their requests. This could lead to a lack of visibility into malicious activities, impacting the security posture of affected ASP.NET applications. Organizations using these versions should prioritize upgrading to 3.5.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105242
Severity
MEDIUM
CVSS
5.3
EPSS
0.34%
Apache

Original NVD Description

Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)