Path-traversal vulnerability in QOS.CH Sarl Logback...
Moderate severity
Unreviewed
Published
Oct 2, 2026
to the GitHub Advisory Database
•
Updated Oct 2, 2026
Description
Published by the National Vulnerability Database
Oct 2, 2026
Published to the GitHub Advisory Database
Oct 2, 2026
Last updated
Oct 2, 2026
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an
MDC-based discriminator value flows unsanitized into a nested
FileAppender path, letting an attacker who influences that MDC value
(e.g. via an HTTP header)
create and append log files outside the intended directory.
This issue affects Logback-classic: from 0.9.14 through 1.6.4. This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.
References