CVE-2026-104721
Logback: Incomplete protection against CVE-2026-19880
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.4. This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.
| CWE | CWE-22 |
| Vendor | qos.ch sarl |
| Product | logback-classic |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for qos.ch sarl logback-classic
Be the first to know when new unknown vulnerabilities affecting qos.ch sarl logback-classic are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
QOS.CH Sarl / Logback-classic
0.9.14 ≤ 1.6.4
Credits
François Martin (GitHub: @martinfrancois, https://github.com/martinfrancois)