
CVE-2026-105239 | Apache log4net | Medium NUL characters can truncate EventLogAppender records on Windows. Fixed in 3.5.0. Details and official source: https://vulnipulse.com/advisories/apache-cve-2026-105239
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently not stored. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-105239 | Apache log4net | Medium NUL characters can truncate EventLogAppender records on Windows. Fixed in 3.5.0. Details and official source: https://vulnipulse.com/advisories/apache-cve-2026-105239