Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an
MDC-based discriminator value flows unsanitized into a nested
FileAppender path, letting an attacker who influences that MDC value
(e.g. via an HTTP header)
create and append log files outside the intended directory.
This issue affects Logback-classic: from 0.9.14 through 1.6.2.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://logback.qos.ch/news.html#1.6.3 |
|
History
Fri, 14 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.2. | |
| Title | Incomplete protection against CVE-2025-11226 | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-08-14T19:46:37.661Z
Reserved: 2026-08-14T14:30:11.651Z
Link: CVE-2026-19880
Updated: 2026-08-14T19:46:33.436Z
Status : Received
Published: 2026-08-14T15:17:09.507
Modified: 2026-08-14T20:16:52.057
Link: CVE-2026-19880
No data.
OpenCVE Enrichment
Updated: 2026-08-14T15:30:03Z