Hi,
The following vulnerability was published for logback.
CVE-2026-19880[0]:
| Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java
| (logback-classic module) allows path-traversal vulnerability. More
| specifically, an MDC-based discriminator value flows unsanitized
| into a nested FileAppender path, letting an attacker who influences
| that MDC value (e.g. via an HTTP header) create and append log
| files outside the intended directory. This issue affects Logback-
| classic: from 0.9.14 through 1.6.2.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-19880
https://www.cve.org/CVERecord?id=CVE-2026-19880
[1] https://logback.qos.ch/news.html#1.6.3
Regards,
Salvatore