Advisory published by Jan Friedrich on 6 October and carried by the oss-sec mailing list feed. The flaw, identified as CVE-2026-105243, affects the EventLogAppender in Apache log4net: long messages are truncated to a fixed size that exceeds the limit accepted by the Windows Event Log and are then dropped without warning. Severity is rated moderate, with CVSS 3.1 score 5.3 (medium), a network attack vector, no privileges required, no user interaction, low integrity impact, and no stated impact on confidentiality or availability. The listed affected versions are log4net 1.2.9 up to before 3.5.0, and a range of commits identified by hash, before a later commit also identified by hash. The feed text is an automatic translation and a summary of the description; the version list and scope should be checked against the original source. For anyone relying on this appender for audit trails, the practical risk is losing long records without the application noticing. The text does not describe a specific fix beyond the stated version boundary.
Cyber ·
CVE-2026-105243: log4net silently drops large records in EventLogAppender
Apache log4net advisory on EventLogAppender: long messages are truncated to a size above what the Windows Event Log accepts and are then dropped without warning. Moderate severity, CVSS 3.1 score 5.3.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.