CVE-2026-104721: Logback: Incomplete protection against CVE-2026-19880
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory.
This issue affects Logback-classic: from 0.9.14 through 1.6.4. This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Logback-classicto a version that resolves this vulnerability.Fixed in 1.6.5
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using the Logback-classic module in versions 0.9.14 through 1.6.4 are affected when an MDC-based discriminator value is used in a nested FileAppender path. Exposure is especially relevant where an external party can influence the MDC value, such as through an HTTP header.
What does an attacker need to exploit the vulnerability?
The attacker needs to control or influence the MDC-based discriminator value that is incorporated into a nested FileAppender path. The provided example is influence through an HTTP header; the unsanitized value can then be used for path traversal.
What is the impact of successful exploitation?
An attacker can create and append to log files outside the intended directory by supplying traversal sequences through the MDC discriminator value.