Search CVE reports


Toggle filters

1 – 2 of 2 results


CVE-2026-40021

Medium priority
Needs evaluation

Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions...

1 affected package

log4net

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
log4net Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-1285

Medium priority

Some fixes available 4 of 9

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

1 affected package

log4net

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
log4net Not affected Vulnerable Fixed Fixed
Show less packages