Improper Neutralization of Null Byte or NUL Character Affecting log4net package, versions [,3.5.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.33% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-LOG4NET-20550531
  • published7 Oct 2026
  • disclosed6 Oct 2026
  • creditUnknown

Introduced: 6 Oct 2026

NewCVE-2026-105240  (opens in a new tab)
CWE-158  (opens in a new tab)

How to fix?

Upgrade log4net to version 3.5.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Neutralization of Null Byte or NUL Character in OutputDebugStringAppender, which passes rendered content to OutputDebugStringW unescaped, and that API takes a null terminated string, so a NUL ends the record at that point. An attacker can have the remainder of a debug output record silently discarded, including exception text and trailing fields, by placing a NUL in content that reaches a logged message. This affects only Windows applications using OutputDebugStringAppender, and requires the attacker to control data that is logged.

CVSS Base Scores

version 4.0
version 3.1