#1126748 logback: CVE-2026-1225

Package:
src:logback
Source:
src:logback
Submitter:
Salvatore Bonaccorso
Date:
2026-09-13 03:35:02 UTC
Severity:
normal
Tags:
#1126748#5
Date:
2026-02-01 07:48:39 UTC
From:
To:
Hi Tony and Java maintainers team,

The following vulnerability was published for logback.

I'm not certain that is affecting the older version we have, please
check ideally provide back if you find where the issue has been
introduced. OTOH the issue might be considered minor? If you can
isolate the fixing commit from 1.5.25 that would be great.

CVE-2026-1225[0]:
| ACE vulnerability in configuration file processing  by QOS.CH
| logback-core up to and including version 1.5.24 in Java
| applications, allows an attacker to instantiate classes already
| present on the class path by compromising an existing logback
| configuration file.     The instantiation of a potentially malicious
| Java class requires that said class is present on the user's class-
| path. In addition, the attacker must  have write access to a
| configuration file. However, after successful instantiation, the
| instance is very likely to be discarded with no further ado.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-1225
https://www.cve.org/CVERecord?id=CVE-2026-1225
[1] https://logback.qos.ch/news.html#1.5.25

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1126748#10
Date:
2026-09-13 03:33:46 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
logback, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1126748@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jérôme Charaoui <jerome@riseup.net> (supplier of updated logback package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 12 Sep 2026 21:01:00 -0400
Source: logback
Architecture: source
Version: 1:1.6.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Jérôme Charaoui <jerome@riseup.net>
Closes: 1091319 1091320 1126748 1138632 1139180 1140922 1146719
Changes:
 logback (1:1.6.3-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream version 1.6.3, fixes CVE-2026-19880, CVE-2026-13006,
     CVE-2026-10532, CVE-2026-9828, CVE-2026-1225, CVE-2025-11226,
     CVE-2026-1225, CVE-2024-12801, CVE-2024-12798 (Closes: #1146719, #1140922,
     #1139180, #1138632, #1126748, #1091320, #1091319)
     - The logback-access module is no longer part of the upstream project, and
       will instead available via the new logback-access source package, see ITP
       #1146286.
   * update poms
   * refresh maven rules
   * drop obsolete lintian overrides
   * d/control: build with headless jdk
   * d/control: update build dependencies
   * d/control: add liblogback-access-java to Suggests
   * d/copyright: drop obsolete Files-Excluded stanza
   * d/copyright: refresh upstream copyright per LICENSE.txt
   * d/copyright: upstream switch to EPL-2.0
   * d/NEWS: add entry about logback-access split
   * d/patches: drop obsolete patches
   * d/patches: new patch to use older jansi package
   * d/upstream: add metadata
   * d/watch: update to v5 format
   * Remove redundant Priority: optional from source stanza.
   * Removed Rules-Requires-Root
   * Update standards version to 4.7.4, no changes needed.
Checksums-Sha1:
 3fcdbfe728bd4b854e424cc8af739b5774b81570 1501 logback_1.6.3-1.dsc
 a33cdcd844ad78821a0fe2a9d0b7ae842e3aeb5e 581848 logback_1.6.3.orig.tar.xz
 ef7c277792396a74709751c119ee002b7dda1f63 11664 logback_1.6.3-1.debian.tar.xz
 a81c70cc5c219903aed85221e95e2db959029903 10967 logback_1.6.3-1_amd64.buildinfo
Checksums-Sha256:
 62c2dd5927e15e8531300cdd24f592192457d9d22d285ecdc27685efaa401796 1501 logback_1.6.3-1.dsc
 9c971ebb0dd62936a671677868dc1845cd4a1596f360fcf08732886941eec1db 581848 logback_1.6.3.orig.tar.xz
 7907eccc8216dcfff25dcdf97dd8943cc7f364f2b69daa4c0d9444a2c48bac22 11664 logback_1.6.3-1.debian.tar.xz
 dd182d59f783b2aba5821265ba752504fbc89ab7af14d696089f95882507a335 10967 logback_1.6.3-1_amd64.buildinfo
Files:
 f3a509ced2a453ac51e8c2f3f5e972b1 1501 java optional logback_1.6.3-1.dsc
 945ffe907d4a89388ddf02875c54ca68 581848 java optional logback_1.6.3.orig.tar.xz
 e9bef2aee264173c75036c5275081a8e 11664 java optional logback_1.6.3-1.debian.tar.xz
 ece5d76203c866ebb8c5a733785a8790 10967 java optional logback_1.6.3-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQTAq04Rv2xblqv/eu5pxS9ljpiFQgUCaqYXFgAKCRBpxS9ljpiF
QrshAP9a6EQ5kXGAwx0T8wyJ6CjpK//whEVihp69zxb/4/NIewD/Z0vcQbAXGJOY
ADZga36BTG4F2Y31wjr4II8SG2WJDAk=
=zSSw
-----END PGP SIGNATURE-----