🔐 CVE Alert

CVE-2026-104721

UNKNOWN 0.0

Logback: Incomplete protection against CVE-2026-19880

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.4.  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.

CWE CWE-22
Vendor qos.ch sarl
Product logback-classic
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for qos.ch sarl logback-classic

Be the first to know when new unknown vulnerabilities affecting qos.ch sarl logback-classic are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

QOS.CH Sarl / Logback-classic
0.9.14 ≤ 1.6.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
logback.qos.ch: https://logback.qos.ch/news.html#1.6.5

Credits

François Martin (GitHub: @martinfrancois, https://github.com/martinfrancois)