Description
Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net.

Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected.

This issue affects Apache log4net: from 1.2.12 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Data integrity loss due to removal of non‑ASCII characters in logs, enabling malicious masking of identities
Action: Immediate patch
AI Analysis

Impact

The RemoteSyslogAppender of Apache log4net fails to escape or encode characters outside the visible ASCII range and spaces; any such characters—including non‑ASCII symbols and control characters—are silently deleted from the log entry. As a result, log data intended to carry unique identifiers may appear indistinguishable, allowing an attacker to conceal a distinct value such as a user name containing a zero‑width space. This flaw does not provide code execution but can compromise the integrity and reliability of audit trails.

Affected Systems

Apache Software Foundation’s log4net library, specifically versions 1.2.12 through the pre‑3.5.0 series, is affected. Only deployments that employ the RemoteSyslogAppender are vulnerable; applications using other appenders are not impacted.

Risk and Exploitability

The vulnerability has a medium CVSS score of 5.3 and no EPSS data is available. It is not listed in CISA KEV. Because the flaw resides in a logging component that processes application data, an attacker who can influence log output, such as through user‑supplied input, could exploit the defect. The likely attack vector is local or remote application injection where the attacker causes the app to log crafted content. The risk is moderate; however, the potential impact on audit integrity warrants prompt remediation.

Generated by OpenCVE AI on October 7, 2026 at 00:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache log4net to version 3.5.0 or later, which removes the deletion bug.
  • If an immediate upgrade is not possible, disable RemoteSyslogAppender or replace it with another appender that correctly preserves non‑ASCII characters.
  • Implement a verification step or filter to confirm that non‑ASCII characters are no longer omitted from log entries.

Generated by OpenCVE AI on October 7, 2026 at 00:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected. This issue affects Apache log4net: from 1.2.12 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Title Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
Weaknesses CWE-116
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-06T19:52:31.116Z

Reserved: 2026-10-04T16:22:18.416Z

Link: CVE-2026-105244

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:16.297

Modified: 2026-10-06T20:17:16.297

Link: CVE-2026-105244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T00:45:09Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output