Description
Insufficient Logging vulnerability in the EventLogAppender of Apache log4net.

Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected.

This issue affects Apache log4net: from 1.2.9 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Audit Failure
Action: Upgrade
AI Analysis

Impact

The EventLogAppender in Apache log4net limits an event record to a fixed size. When the combined lengths of the log message and its metadata exceed the Windows Event Log limit, the entire record is silently discarded, leaving no trace. This loss of audit evidence can impede incident detection and forensic investigations. An attacker who can influence log content can construct a long message that causes the event to be omitted, effectively erasing their activity from the event log.

Affected Systems

Any application on Windows that uses Apache log4net with the EventLogAppender between versions 1.2.9 and just before 3.5.0 is affected. Non‑Windows platforms or other log4net appenders are not impacted.

Risk and Exploitability

The CVSS base score is 5.3, indicating moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is an application that accepts untrusted input and logs it using EventLogAppender; the attacker can craft a large log entry to suppress evidence. While the flaw does not provide direct code execution, the ability to hide logs increases the risk of undetected malicious activity.

Generated by OpenCVE AI on October 7, 2026 at 00:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache log4net to version 3.5.0 or later, which removes the silent discard behavior.
  • Verify that all EventLogAppender usages in production limit log message size; truncate or sanitize content that may exceed the Windows Event Log capacity.
  • Optionally, replace EventLogAppender with an alternative appender (e.g., FileAppender or RollingFileAppender) for critical audit trails to avoid silent data loss.

Generated by OpenCVE AI on October 7, 2026 at 00:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache log4net
Vendors & Products Apache
Apache log4net

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Title Apache log4net: Oversize EventLogAppender record silently discarded
Weaknesses CWE-778
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-06T19:51:25.116Z

Reserved: 2026-10-04T16:21:38.272Z

Link: CVE-2026-105243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:16.167

Modified: 2026-10-06T20:17:16.167

Link: CVE-2026-105243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T00:45:09Z

Weaknesses