CVE-2026-40021
Last modified
CVE-2026-40021 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in MDC property keys and values, as well as the identity field that may carry attacker-influenced data. This causes an exception during serialization and the silent loss of the affected log event. An attacker who can influence any of these fields can exploit this to suppress individual log records, impairing audit trails and detection of malicious activity. Users are advised to upgrade to Apache Log4net 3.3.0, which fixes this issue.. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets in MDC property keys and values, as well as the identity field that may carry attacker-influenced data. This causes an exception during serialization and the silent loss of the affected log event. An attacker who can influence any of these fields can exploit this to suppress individual log records, impairing audit trails and detection of malicious activity. Users are advised to upgrade to Apache Log4net 3.3.0, which fixes this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Log4net | < 3.3.0 |
References
- https://github.com/apache/logging-log4net/pull/280Issue Tracking
- https://lists.apache.org/thread/q8otftjswhk69n3kxslqg7cobr0x4st7Mailing List, Vendor Advisory
- https://logging.apache.org/security.html#CVE-2026-40021Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/04/10/11Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-40021?
How severe is CVE-2026-40021?
How do I fix CVE-2026-40021?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40010Missing invocation of Servlet http web request method change…9.1
- CVE-2026-40011An attacker sending a large number of crafted DNS queries mi…3.7
- CVE-2026-40012ECS zero scoped answers are stored in the packet cache while…5.3
- CVE-2026-40016Attacker can upload a malicious Sieve script over ManageSiev…6.5
- CVE-2026-4002The Petje.af plugin for WordPress is vulnerable to Cross-Sit…4.3
- CVE-2026-40020Attacker can use the IMAP SETACL command to inject the anyon…4.3
- CVE-2026-40022When authentication is enabled on the Apache Camel embedded …8.2
- CVE-2026-40023Apache Log4cxx's XMLLayout https://logging.apache.org/log4c…5.3
- CVE-2026-40024The Sleuth Kit through 4.14.0 contains a path traversal vuln…7.1
- CVE-2026-40025The Sleuth Kit through 4.14.0 contains an out-of-bounds read…6.1
- CVE-2026-40026The Sleuth Kit through 4.14.0 contains an out-of-bounds read…7.1
- CVE-2026-40027ALEAPP (Android Logs Events And Protobuf Parser) through 3.4…8.4
Are you affected by CVE-2026-40021?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
