Security advisory published on October 6, 2026 by Jan Friedrich on the oss-sec feed, with the source record dated October 7, 2026. The vulnerability, identified as CVE-2026-105239, affects the EventLogAppender in Apache log4net: a NUL character in logged content ends the record written to the Windows Event Log, resulting in truncated records. Severity is moderate, with CVSS 3.1 score 5.3 (medium) and vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N, meaning network exploitation, no privileges or user interaction, and impact limited to integrity. Affected versions: Apache log4net 1.2.9 up to before 3.5.0, and the commit range from 02e1e115435888485f2e28b414d267e39e799e07 up to before dc5855a0720c91590fd7a81d729ea01fdd69e000. To verify, consult the original advisory on the oss-sec security list feed by searching for CVE-2026-105239, and check the log4net version used on your Windows systems. The recommended action is to upgrade to version 3.5.0 or later. Relevance to Rota Nacional: Rota does not fix third-party logging libraries. If your team uses AI to study this advisory, do not paste production logs containing personal data or credentials; the platform detects personal data before any model runs, but the best protection is not exposing raw content.
Cyber ·
CVE-2026-105239: NUL character truncates EventLogAppender records in Apache log4net
Advisory from the oss-sec feed dated October 6, 2026, on the EventLogAppender in Apache log4net. A NUL character in logged content ends the Windows Event Log record. Moderate severity, CVSS 3.1 score of 5.3.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.