๐Ÿ” CVE Alert

CVE-2026-19880

UNKNOWN 0.0

Incomplete protection against CVE-2025-11226

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.2.

CWE CWE-22
Vendor qos.ch sarl
Product logback-classic
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for qos.ch sarl logback-classic

Be the first to know when new unknown vulnerabilities affecting qos.ch sarl logback-classic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

QOS.CH Sarl / Logback-classic
0.9.14 โ‰ค 1.6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
logback.qos.ch: https://logback.qos.ch/news.html#1.6.3

Credits

York Shen - Yong Shen - PayPal Cyber Security Team (UID 100171)