Debian Package Tracker
Register | Log in
Subscribe

log4net

Choose email to subscribe with

general
  • source: log4net (main)
  • version: 1.2.10+dfsg-10
  • maintainer: Debian .NET Team (archive) (DMD)
  • uploaders: James Montgomery [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.2.10+dfsg-8
  • stable: 1.2.10+dfsg-9
  • testing: 1.2.10+dfsg-10
  • unstable: 1.2.10+dfsg-10
versioned links
  • 1.2.10+dfsg-8: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.10+dfsg-9: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.10+dfsg-10: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • liblog4net-cil-dev
  • liblog4net1.2-cil
action needed
7 security issues in trixie high

There are 7 open security issues in trixie.

6 important issues:
  • CVE-2026-105239: Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently not stored. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105240: Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NUL character in logged content ended the debug output record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently lost. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use OutputDebugStringAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105241: Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105242: Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105243: Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105244: Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected. This issue affects Apache log4net: from 1.2.12 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
1 issue left for the package maintainer to handle:
  • CVE-2026-40021: (needs triaging) Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in MDC property keys and values, as well as the identity field that may carry attacker-influenced data. This causes an exception during serialization and the silent loss of the affected log event. An attacker who can influence any of these fields can exploit this to suppress individual log records, impairing audit trails and detection of malicious activity. Users are advised to upgrade to Apache Log4net 3.3.0, which fixes this issue.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-04-11 Last update: 2026-10-07 11:30
6 security issues in sid high

There are 6 open security issues in sid.

6 important issues:
  • CVE-2026-105239: Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently not stored. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105240: Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NUL character in logged content ended the debug output record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently lost. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use OutputDebugStringAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105241: Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105242: Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105243: Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105244: Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected. This issue affects Apache log4net: from 1.2.12 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Created: 2026-10-07 Last update: 2026-10-07 11:30
6 security issues in forky high

There are 6 open security issues in forky.

6 important issues:
  • CVE-2026-105239: Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently not stored. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105240: Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NUL character in logged content ended the debug output record at that point, so everything the layout rendered after it, including exception text and trailing fields, was silently lost. A party whose data reaches a log message could hide the rest of that record. Only applications on Windows that use OutputDebugStringAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105241: Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105242: Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105243: Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
  • CVE-2026-105244: Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected. This issue affects Apache log4net: from 1.2.12 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Created: 2026-10-07 Last update: 2026-10-07 11:30
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-06-24 Last update: 2026-10-07 11:30
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-06-07 Last update: 2026-09-14 19:01
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 1.2.10+dfsg-10 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-07 12:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2015-09-09 Last update: 2026-06-06 22:30
news
[rss feed]
  • [2026-06-24] log4net 1.2.10+dfsg-10 MIGRATED to testing (Debian testing watch)
  • [2026-06-06] Accepted log4net 1.2.10+dfsg-10 (source) into unstable (James Montgomery) (signed by: bage@debian.org)
  • [2025-10-25] log4net REMOVED from testing (Debian testing watch)
  • [2023-09-07] log4net 1.2.10+dfsg-9 MIGRATED to testing (Debian testing watch)
  • [2023-09-01] Accepted log4net 1.2.10+dfsg-9 (source) into unstable (Mirco Bauer) (signed by: bage@debian.org)
  • [2022-01-13] log4net REMOVED from testing (Debian testing watch)
  • [2021-04-18] log4net 1.2.10+dfsg-8 MIGRATED to testing (Debian testing watch)
  • [2021-04-11] Accepted log4net 1.2.10+dfsg-8 (source) into unstable (Mirco Bauer) (signed by: Christian Hofstaedtler)
  • [2021-01-08] log4net 1.2.10+dfsg-7.1 MIGRATED to testing (Debian testing watch)
  • [2021-01-02] Accepted log4net 1.2.10+dfsg-7.1 (source) into unstable (Holger Levsen)
  • [2020-05-15] Accepted log4net 1.2.10+dfsg-6+deb8u1 (source all) into oldoldstable (Chris Lamb)
  • [2015-09-15] log4net 1.2.10+dfsg-7 MIGRATED to testing (Britney)
  • [2015-09-09] Accepted log4net 1.2.10+dfsg-7 (source all) into unstable (Jo Shields)
  • [2012-02-04] log4net 1.2.10+dfsg-6 MIGRATED to testing (Debian testing watch)
  • [2012-01-22] Accepted log4net 1.2.10+dfsg-6 (source all) (Jo Shields)
  • [2011-07-22] log4net 1.2.10+dfsg-5 MIGRATED to testing (Debian testing watch)
  • [2011-07-11] Accepted log4net 1.2.10+dfsg-5 (source all) (Julian Taylor) (signed by: Iain Lane)
  • [2010-01-17] log4net 1.2.10+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2010-01-06] Accepted log4net 1.2.10+dfsg-4 (source all) (Jo Shields)
  • [2009-03-18] log4net 1.2.10+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2009-03-07] Accepted log4net 1.2.10+dfsg-3 (source all) (Mirco Bauer)
  • [2009-03-06] Accepted log4net 1.2.10+dfsg-2 (source all) (Jo Shields) (signed by: Mirco Bauer)
  • [2008-04-15] log4net 1.2.10+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2008-04-03] Accepted log4net 1.2.10+dfsg-1 (source all) (Sebastian Dröge)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.2.10+dfsg-10

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing