Upstream information

CVE-2026-105244 at MITRE

Description

Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net.

Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected.

This issue affects Apache log4net: from 1.2.12 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v3 Scores
CVSS detail CNA (Apache Software Foundation)
Base Score 5.3
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact None
CVSSv3 Version 3.1
SUSE Bugzilla entry: 1284393 [NEW]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Wed Oct 7 14:13:59 2026
CVE page last modified: Wed Oct 7 14:13:59 2026