Log4net Apache Log4net

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Apache Log4net.

By the Year

In 2026 there have been 1 vulnerability in Apache Log4net. Log4net did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 0.00
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 1 9.80

It may take a day or so for new Log4net vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Log4net Security Vulnerabilities

Apache Log4net 3.3.0 Unsanitized XML in XmlLayout Suppresses Logs
CVE-2026-40021 - April 10, 2026

Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in MDC property keys and values, as well as the identity field that may carry attacker-influenced data. This causes an exception during serialization and the silent loss of the affected log event. An attacker who can influence any of these fields can exploit this to suppress individual log records, impairing audit trails and detection of malicious activity. Users are advised to upgrade to Apache Log4net 3.3.0, which fixes this issue.

Output Sanitization

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files
CVE-2018-1285 9.8 - Critical - May 11, 2020

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

XXE

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apache Log4net or by Apache? Click the Watch button to subscribe.

Apache
Vendor

subscribe