Description
Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net.
Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected.
This issue affects Apache log4net: from 1.2.11 before 3.5.0.
Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected.
This issue affects Apache log4net: from 1.2.11 before 3.5.0.
Users are recommended to upgrade to version 3.5.0, which fixes the issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 06 Oct 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache log4net |
|
| Vendors & Products |
Apache
Apache log4net |
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. | |
| Title | Apache log4net: Request validation failure drops the event in the aspnet-request converter | |
| Weaknesses | CWE-755 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-06T19:50:19.075Z
Reserved: 2026-10-04T16:21:12.546Z
Link: CVE-2026-105242
No data.
Status : Received
Published: 2026-10-06T20:17:16.037
Modified: 2026-10-06T20:17:16.037
Link: CVE-2026-105242
No data.
OpenCVE Enrichment
Updated: 2026-10-06T23:00:08Z
Weaknesses
-
CWE-755
Improper Handling of Exceptional Conditions