Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected.
This issue affects Apache log4net: from 1.2.11 before 3.5.0.
Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 06 Oct 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache log4net |
|
| Vendors & Products |
Apache
Apache log4net |
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. | |
| Title | Apache log4net: Request validation failure drops the event in the aspnet-request converter | |
| Weaknesses | CWE-755 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-07T06:11:58.703Z
Reserved: 2026-10-04T16:21:12.546Z
Link: CVE-2026-105242
No data.
Status : Received
Published: 2026-10-06T20:17:16.037
Modified: 2026-10-07T07:16:59.073
Link: CVE-2026-105242
No data.
OpenCVE Enrichment
Updated: 2026-10-07T00:45:09Z