Apache log4net: Request validation failure drops the event in the aspnet-request converter
Summary
| CVE | CVE-2026-105242 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 20:17:16 UTC |
| Updated | 2026-10-06 20:17:16 UTC |
| Description | Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Problem Types: CWE-755 | CWE-755 CWE-755 Improper Handling of Exceptional Conditions
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Log4net | affected 1.2.11 3.5.0 semver | Not specified |
| CNA | Apache Software Foundation | Apache Log4net | affected 243f1e9f3ee235955bade4b4fe664a903378719a 145203420c579a703008b4b723b6a080757f4964 git | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/apache/logging-log4net/pull/316 | [email protected] | github.com | |
| lists.apache.org/thread.html/zg6dbqm4ztm7j3c21nfsqj0yxm5yrpdx | [email protected] | lists.apache.org | |
| github.com/apache/logging-log4net/commit/145203420c579a703008b4b723b6a08... | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: The Apache Software Foundation (en)
CNA: Claude Security (en)
CNA: Jan Friedrich (en)
There are currently no legacy QID mappings associated with this CVE.