The CVE-2026-19880 record describes a path-traversal vulnerability in Logback-classic, a Java logging library. This vulnerability allows an attacker to create and append log files outside the intended directory by influencing the MDC value, typically through an HTTP header. Affected versions include Logback-classic from 0.9.14 through 1.6.2. Organizations using Logback-classic should verify their inventor [truncated]
A deserialization of untrusted data vulnerability exists in QOS.CH Sarl logback-core, specifically within the HardenedObjectInputStream module. An attacker with the ability to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects. While deserialization is heavily restricted by HardenedObjectInputStream and no practical remote code execution or signific [truncated]