VendorsApachelog4netany version
Vulnerabilities

Apache Software Foundation any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2018-1285
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
Published 2020-05-11 · Modified
9.8EPSS 0.174
CVE-2026-40021
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
Published 2026-04-10 · Analyzed
6.3EPSS 0.010