CVE-2026-19880Patch

LOWCVSS 6.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-18: 2Patch / Workaround · 2026-08-18: 2Technical Details · 2026-08-18: 108-18
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • Repojournal@repojournal
    Patch

    Logback 1.6.3 closes CVE-2026-19880, which sat in the logging path of Spring Security and Session. If you're on those, pin it now. Spring Framework heads to 7.0.10-SNAPSHOT, with a fix for synchronous exceptions from AsynchronousFileChannel. spring-grpc now documents and tests OAuth2 opaque token support. The docs caught up to the code. Spring Tools adds validation and a quick fix for scope annotations, plus a conversion to. Less boilerplate, fewer mistakes. Logback 1.6.3 is the day's real headline. Patch before the scanners find you. https://repojournal.com/showcase/spring-projects/2026-08-18/logback-1-6-3-shuts-down-cve-2026-19880-in-spring-security-and-session

    Post summary

    The post announces that Logback 1.6.3 contains a patch for CVE‑2026‑19880 affecting Spring Security and Session, urging users to upgrade to mitigate potential scanner-detected vulnerabilities.

    0304066
    409 followersView on X
  • Repojournal@repojournal
    Patch

    CVE-2026-19880 shuts down in Logback 1.6.3, and Spring Security and Spring Session both pulled the fix in overnight. Spring Security bumps logback-classic from 1.6.2 to 1.6.3; Spring Session does the same for logback-core. Both patches close the same hole. Spring Security also moves jackson-bom from 3.2.1 to 3.2.2, clearing a few Jackson CVEs on the side. Spring LDAP is quieter: just an Antora docs prerelease bump from 3.2.0-rc.2 to rc.3. Logback's fix is the one worth reading before your next deploy. If you pin logback on any Spring app, 1.6.3 is the floor now. https://repojournal.com/showcase/spring-projects/2026-08-18/logback-1-6-3-shuts-down-cve-2026-19880-in-spring-security-and-session

    Post summary

    CVE‑2026‑19880 has been fixed in Logback 1.6.3, with Spring Security and Spring Session adopting the update, and the article urges users to upgrade before deployment.

    0304062
    408 followersView on X

Explore more