Skip to content
Rota Nacional

Cyber ·

CVE-2026-105239: NUL character truncates EventLogAppender records in Apache log4net

Advisory from the oss-sec feed dated October 6, 2026, on the EventLogAppender in Apache log4net. A NUL character in logged content ends the Windows Event Log record. Moderate severity, CVSS 3.1 score of 5.3.

Security advisory published on October 6, 2026 by Jan Friedrich on the oss-sec feed, with the source record dated October 7, 2026. The vulnerability, identified as CVE-2026-105239, affects the EventLogAppender in Apache log4net: a NUL character in logged content ends the record written to the Windows Event Log, resulting in truncated records. Severity is moderate, with CVSS 3.1 score 5.3 (medium) and vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N, meaning network exploitation, no privileges or user interaction, and impact limited to integrity. Affected versions: Apache log4net 1.2.9 up to before 3.5.0, and the commit range from 02e1e115435888485f2e28b414d267e39e799e07 up to before dc5855a0720c91590fd7a81d729ea01fdd69e000. To verify, consult the original advisory on the oss-sec security list feed by searching for CVE-2026-105239, and check the log4net version used on your Windows systems. The recommended action is to upgrade to version 3.5.0 or later. Relevance to Rota Nacional: Rota does not fix third-party logging libraries. If your team uses AI to study this advisory, do not paste production logs containing personal data or credentials; the platform detects personal data before any model runs, but the best protection is not exposing raw content.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free