Executive brief
Apache Log4net fails to sanitize XML-forbidden characters in certain fields, leading to serialization exceptions and silent loss of log events.
Affected products
- Apache log4net
- NuGet log4net
Junglewise Threat Intelligence
CVE-2026-40021 · Severity: medium · CVSS 5.3 · Published 2026-04-10
Technologies: log4net (NuGet). Vendors: Apache, NuGet.
Apache Log4net fails to sanitize XML-forbidden characters in certain fields, leading to serialization exceptions and silent loss of log events.