CVE-2026-105244 was posted to the oss-sec feed on 6 October 2026 by a researcher on the list, rated moderate with CVSS 3.1 score 5.3 (medium), network vector, low complexity, no privileges, no user interaction and low integrity impact. According to the advisory, the RemoteSyslogAppender in Apache log4net silently removes every character outside visible ASCII and space from log messages, which is described as inadequate output encoding or escaping. Affected versions are log4net 1.2.12 up to but not including 3.5.0, plus a range of code revisions identified by hash in the project repository. For anyone studying the case, the key point is that data loss happens without a visible error, which can undermine audit trails and later incident analysis. To verify, consult the original advisory on the oss-sec feed and the official Apache log4net project page, and check the listed versions and commit range.
Cyber ·
CVE-2026-105244: log4net silently removes non-ASCII content in the RemoteSyslogAppender
Moderate-severity advisory for Apache log4net: the RemoteSyslogAppender strips characters outside visible ASCII and space from log records in versions before 3.5.0.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.