{"cve":"CVE-2026-19880","enrichment":{"affected":[{"configurations":[{"platform":["java"],"status":"affected","versions":{"scheme":"semver","value":"[0.9.14,1.6.2]"}},{"platform":["java"],"status":"unaffected","versions":{"scheme":"semver","value":"1.6.3"}}],"enrichment":{"confidence":100.0,"confidence_source":"manual","scores":[{"score":100.0,"source":"manual"}]},"original":{"product":"Logback-classic","source":"cna","vendor":"QOS.CH Sarl"},"product":"logback-classic","vendor":"qos.ch_sarl"}],"created":"2026-08-14T15:30:03.800321+00:00","updated":"2026-08-17T11:02:13.599961+00:00","vendors":["qos.ch_sarl","qos.ch_sarl$PRODUCT$logback-classic"]},"epss":{"score":0.00496},"mitre":{"cpes":[],"created":"2026-08-14T14:31:02.361000+00:00","description":"Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an \nMDC-based discriminator value flows unsanitized into a nested \nFileAppender path, letting an attacker who influences that MDC value \n(e.g. via an HTTP header)\n create and append log files outside the intended directory. \n\n\nThis issue affects Logback-classic: from 0.9.14 through 1.6.2.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":6.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green"}},"mitre_repo_path":"cves/2026/19xxx/CVE-2026-19880.json","references":["https://logback.qos.ch/news.html#1.6.3"],"title":"Incomplete protection against CVE-2025-11226","updated":"2026-08-14T19:46:37.661000+00:00","vendors":[],"weaknesses":["CWE-22"]},"nvd":{"cpes":[],"created":"2026-08-14T15:17:09.507000+00:00","description":"Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an \nMDC-based discriminator value flows unsanitized into a nested \nFileAppender path, letting an attacker who influences that MDC value \n(e.g. via an HTTP header)\n create and append log files outside the intended directory. \n\n\nThis issue affects Logback-classic: from 0.9.14 through 1.6.2.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":6.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:X/V:X/RE:M/U:Green"}},"nvd_repo_path":"2026/CVE-2026-19880.json","references":["https://logback.qos.ch/news.html#1.6.3"],"title":null,"updated":"2026-08-26T16:39:50.787000+00:00","vendors":[],"weaknesses":["CWE-22"]},"opencve":{"changes":[{"created":"2026-08-14T14:45:00+00:00","data":[{"details":{"new":"Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an \nMDC-based discriminator value flows unsanitized into a nested \nFileAppender path, letting an attacker who influences that MDC value \n(e.g. via an HTTP header)\n create and append log files outside the intended directory. \n\n\nThis issue affects Logback-classic: from 0.9.14 through 1.6.2.","old":null},"type":"description"},{"details":{"new":"Incomplete protection against CVE-2025-11226","old":null},"type":"title"},{"details":{"added":["CWE-22"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://logback.qos.ch/news.html#1.6.3"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":6.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"87577d3f-97b6-4cea-8a1d-77e810d431cc"},{"created":"2026-08-14T20:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"4f9d5181-bbe4-4e7f-ab7a-38370e55a3a4"},{"created":"2026-08-17T11:30:00+00:00","data":[{"details":["qos.ch_sarl","qos.ch_sarl$PRODUCT$logback-classic"],"type":"first_time"},{"details":{"added":["qos.ch_sarl","qos.ch_sarl$PRODUCT$logback-classic"],"removed":[]},"type":"vendors"}],"id":"f685a1a3-37de-4a68-9850-b1ac00aa07ca"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-08-14T14:31:02.361000+00:00","provider":"mitre"},"description":{"data":"Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an \nMDC-based discriminator value flows unsanitized into a nested \nFileAppender path, letting an attacker who influences that MDC value \n(e.g. via an HTTP header)\n create and append log files outside the intended directory. \n\n\nThis issue affects Logback-classic: from 0.9.14 through 1.6.2.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":6.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green"},"provider":"mitre"},"epss":{"data":{"score":0.00496},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://logback.qos.ch/news.html#1.6.3"],"providers":["mitre","nvd"]},"title":{"data":"Incomplete protection against CVE-2025-11226","provider":"mitre"},"updated":{"data":"2026-08-17T11:02:13.599961+00:00","provider":"enrichment"},"vendors":{"data":["qos.ch_sarl","qos.ch_sarl$PRODUCT$logback-classic"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-22"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-08-14T14:31:02.361000+00:00","description":"Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an \nMDC-based discriminator value flows unsanitized into a nested \nFileAppender path, letting an attacker who influences that MDC value \n(e.g. via an HTTP header)\n create and append log files outside the intended directory. \n\n\nThis issue affects Logback-classic: from 0.9.14 through 1.6.2.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"Incomplete protection against CVE-2025-11226","updated":"2026-08-14T19:46:33.436000+00:00","vendors":[],"vulnrichment_repo_path":"2026/19xxx/CVE-2026-19880.json","weaknesses":[]}}