Skip to content
Rota Nacional

Cyber ·

CVE-2026-105240: NUL character truncates OutputDebugStringAppender logs in Apache log4net

Moderate advisory for Apache log4net: a NUL character in logged content ends the OutputDebugStringAppender debug output in versions before 3.5.0.

On October 6, 2026, the identifier CVE-2026-105240 was published on the oss-sec feed, concerning Apache log4net. The issue is rated moderate severity, with CVSS 3.1 score 5.3 (medium) and vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N. According to the description, a NUL character in logged content ends the debug output of the OutputDebugStringAppender, so records are truncated. The stated impact is low integrity, with no declared impact on confidentiality or availability. Affected versions are Apache log4net 1.2.9 before 3.5.0 and a range of revisions identified by commit hash. The text we received is an automatic translation of the feed content; for technical details and the official list of versions, consult the original advisory on the oss-sec feed and the Apache log4net project page. Nothing in this note indicates that Rota Nacional fixes or reproduces this flaw: it is a logging library in .NET applications, the responsibility of whoever uses it.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free