Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net.

Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected.

This issue affects Apache log4net: from 1.2.9 before 3.5.0.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Project Subscriptions

Vendors Products
Log4net Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Oct 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache log4net
Vendors & Products Apache
Apache log4net

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.
Title Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
Weaknesses CWE-176
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-06T19:49:03.994Z

Reserved: 2026-10-04T16:20:44.036Z

Link: CVE-2026-105241

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:15.907

Modified: 2026-10-06T20:17:15.907

Link: CVE-2026-105241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:00:09Z

Weaknesses