CVE-2026-104721: Logback: Incomplete protection against CVE-2026-19880

Published Oct 2, 2026
·
Updated

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory.

This issue affects Logback-classic: from 0.9.14 through 1.6.4.  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.

Affected Software

1 affected component
QOS.CH Sarl Logback-classic>=0.9.14<=1.6.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Logback-classic to a version that resolves this vulnerability.

    Fixed in 1.6.5

Event History

Oct 2, 2026
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using the Logback-classic module in versions 0.9.14 through 1.6.4 are affected when an MDC-based discriminator value is used in a nested FileAppender path. Exposure is especially relevant where an external party can influence the MDC value, such as through an HTTP header.

2

What does an attacker need to exploit the vulnerability?

The attacker needs to control or influence the MDC-based discriminator value that is incorporated into a nested FileAppender path. The provided example is influence through an HTTP header; the unsanitized value can then be used for path traversal.

3

What is the impact of successful exploitation?

An attacker can create and append to log files outside the intended directory by supplying traversal sequences through the MDC discriminator value.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203