Advisory CVE-2026-105242 describes improper handling of exceptional conditions in the aspnet-request pattern converter of Apache log4net. When request parameters are read, the component can trigger an ASP.NET validation failure, and the event is no longer logged. The rating is moderate, with CVSS 3.1 of 5.3 and a network attack vector, requiring no privileges and no user interaction. The stated impact is low on integrity and none on confidentiality and availability. Affected versions are Apache log4net 1.2.11 up to before 3.5.0, plus a range of source revisions before a specific commit. The advisory was published by Jan Friedrich on October 6 on the oss-sec list, and the text received is an automatic translation. To consult the original, open the oss-sec list by the name given and check the date, severity and version range before concluding any action. It matters for anyone running systems that depend on logging because an event can go unrecorded precisely when a request generates it, which weakens audit and investigation.
Cyber ·
CVE-2026-105242: log4net flaw can drop events in the aspnet-request converter
Moderate-severity vulnerability (CVSS 3.1: 5.3) in Apache log4net: reading request parameters can trigger an ASP.NET validation failure and prevent the event from being logged in the aspnet-request converter. Versions before 3.5.0 are affected.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.