CVE-2026-40021
published 2026-04-10CVE-2026-40021: Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.75%
50.8th percentile
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in MDC property keys and values, as well as the identity field that may carry attacker-influenced data. This causes an exception during serialization and the silent loss of the affected log event.
An attacker who can influence any of these fields can exploit this to suppress individual log records, impairing audit trails and detection of malicious activity.
Users are advised to upgrade to Apache Log4net 3.3.0, which fixes this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4net | < 3.3.0 | 3.3.0 |
| apache | log4net | >= 0 < 3.3.0 | 3.3.0 |
| apache_software_foundation | apache_log4net | < 3.3.0 | 3.3.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Log4net up to 3.2.x XmlLayout/XmlLayoutSchemaLog4J escape output (Nessus ID 306027)
vuldb·2026-04-11·CVSS 6.3
CVE-2026-40021 [MEDIUM] Apache Log4net up to 3.2.x XmlLayout/XmlLayoutSchemaLog4J escape output (Nessus ID 306027)
A vulnerability was found in Apache Log4net up to 3.2.x. It has been rated as problematic. Affected is the function XmlLayout/XmlLayoutSchemaLog4J. This manipulation causes escaping of output.
The identification of this vulnerability is CVE-2026-40021. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
ghsa·2026-04-10
CVE-2026-40021 [MEDIUM] CWE-116 Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in MDC property keys and values, as well as the identity field that may carry attacker-influenced data. This causes an exception during serialization and the silent loss of the affected log event.
An attacker who can influence any of these fields can exploit this to suppress individual log records, impairing audit trails and dete
GHSA
GHSA-4f7c-pmjv-c25w: Apache Log4net's XmlLayout https://logging
ghsa_unreviewed·2026-04-10
CVE-2026-40021 [MEDIUM] CWE-116 GHSA-4f7c-pmjv-c25w: Apache Log4net's XmlLayout https://logging
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in MDC property keys and values, as well as the identity field that may carry attacker-influenced data. This causes an exception during serialization and the silent loss of the affected log event.
An attacker who can influence any of these fields can exploit this to suppress individual log records, impairing audit trails and detection of malicious activity.
Users are advised to upgrade to Apache Log4net 3.3.0, which fixes this issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-40021 log4net: Apache Log4net: Denial of Service for logging via unsanitized XML characters [fedora-all]
bugzilla·2026-04-13·CVSS 6.3
CVE-2026-40021 [MEDIUM] CVE-2026-40021 log4net: Apache Log4net: Denial of Service for logging via unsanitized XML characters [fedora-all]
CVE-2026-40021 log4net: Apache Log4net: Denial of Service for logging via unsanitized XML characters [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40021 log4net: Apache Log4net: Denial of Service for logging via unsanitized XML characters [epel-all]
bugzilla·2026-04-13·CVSS 6.3
CVE-2026-40021 [MEDIUM] CVE-2026-40021 log4net: Apache Log4net: Denial of Service for logging via unsanitized XML characters [epel-all]
CVE-2026-40021 log4net: Apache Log4net: Denial of Service for logging via unsanitized XML characters [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40021 log4net: Apache Log4net: Denial of Service for logging via unsanitized XML characters
bugzilla·2026-04-10·CVSS 6.3
CVE-2026-40021 [MEDIUM] CVE-2026-40021 log4net: Apache Log4net: Denial of Service for logging via unsanitized XML characters
CVE-2026-40021 log4net: Apache Log4net: Denial of Service for logging via unsanitized XML characters
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in MDC property keys and values, as well as the identity field that may carry attacker-influenced data. This causes an exception during serialization and the silent loss of the affected log event.
An attacker who can influence any of these fields can exploit this to suppress individual log records, impairing audit trails and detection of malicious ac
https://github.com/apache/logging-log4net/pull/280https://lists.apache.org/thread/q8otftjswhk69n3kxslqg7cobr0x4st7https://logging.apache.org/cyclonedx/vdr.xmlhttps://logging.apache.org/log4net/manual/configuration/layouts.htmlhttps://logging.apache.org/security.html#CVE-2026-40021http://www.openwall.com/lists/oss-security/2026/04/10/11
2026-04-10
Published