Skip to content
Rota Nacional

Cyber ·

CVE-2026-105241: log4net drops a batch in SmtpPickupDirAppender on unencodable content

Moderate vulnerability in the Apache log4net SmtpPickupDirAppender: content the e-mail file writer cannot encode, such as an unpaired UTF-16 surrogate, can cause the whole batch to be dropped. Versions before 3.5.0 are affected.

Advisory CVE-2026-105241, published on the oss-sec feed by Jan Friedrich on 6 October 2026, describes improper handling of Unicode encoding in the SmtpPickupDirAppender of Apache log4net. When content the e-mail file writer cannot encode, such as an unpaired UTF-16 surrogate, reaches the appender, the entire batch can be discarded. The severity is rated moderate, with CVSS 3.1 score 5.3 (medium), network vector, no privileges required, no user interaction, low integrity impact, and no impact on confidentiality or availability. Affected versions are Apache log4net 1.2.9 up to but not including 3.5.0, plus a range of development revisions identified by commit hash, up to the revision stated in the advisory. To verify the original, consult the advisory on the oss-sec feed cited by the source and check which log4net version your projects use.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free