Low severityGHSA Advisory· Published Jan 22, 2026· Updated Apr 15, 2026
CVE-2026-1225
CVE-2026-1225
Description
ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.
The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ch.qos.logback:logback-coreMaven | < 1.5.25 | 1.5.25 |
Affected products
158- osv-coords157 versionspkg:apk/chainguard/akhqpkg:apk/chainguard/apache-nifipkg:apk/chainguard/apache-nifi-registrypkg:apk/chainguard/apache-nifi-registry-toolkitpkg:apk/chainguard/cassandra-5.0pkg:apk/chainguard/cassandra-reaperpkg:apk/chainguard/dependency-trackpkg:apk/chainguard/dependency-track-apiserverpkg:apk/chainguard/dependency-track-bundledpkg:apk/chainguard/kafbat-uipkg:apk/chainguard/kafbat-ui-fipspkg:apk/chainguard/keycloak-config-clipkg:apk/chainguard/keycloak-config-cli-iamguarded-compatpkg:apk/chainguard/knative-kafka-broker-1.21-dispatcher-loompkg:apk/chainguard/knative-kafka-broker-1.21-receiver-loompkg:apk/chainguard/knative-kafka-broker-1.22-dispatcher-loompkg:apk/chainguard/knative-kafka-broker-1.22-receiver-loompkg:apk/chainguard/knative-kafka-broker-fips-1.22-dispatcher-loompkg:apk/chainguard/knative-kafka-broker-fips-1.22-receiver-loompkg:apk/chainguard/kserve-modelmeshpkg:apk/chainguard/localstackpkg:apk/chainguard/management-api-for-apache-cassandra-4.0pkg:apk/chainguard/management-api-for-apache-cassandra-4.1pkg:apk/chainguard/management-api-for-apache-cassandra-5.0pkg:apk/chainguard/nacospkg:apk/chainguard/nacos-dockerpkg:apk/chainguard/nextflowpkg:apk/chainguard/sonarqubepkg:apk/chainguard/sonar-scanner-clipkg:apk/chainguard/trinopkg:apk/chainguard/trino-plugin-ai-functionspkg:apk/chainguard/trino-plugin-bigquerypkg:apk/chainguard/trino-plugin-blackholepkg:apk/chainguard/trino-plugin-cassandrapkg:apk/chainguard/trino-plugin-clickhousepkg:apk/chainguard/trino-plugin-delta-lakepkg:apk/chainguard/trino-plugin-druidpkg:apk/chainguard/trino-plugin-duckdbpkg:apk/chainguard/trino-plugin-elasticsearchpkg:apk/chainguard/trino-plugin-exasolpkg:apk/chainguard/trino-plugin-exchange-filesystempkg:apk/chainguard/trino-plugin-exchange-hdfspkg:apk/chainguard/trino-plugin-fakerpkg:apk/chainguard/trino-plugin-functions-pythonpkg:apk/chainguard/trino-plugin-google-sheetspkg:apk/chainguard/trino-plugin-hivepkg:apk/chainguard/trino-plugin-http-event-listenerpkg:apk/chainguard/trino-plugin-hudipkg:apk/chainguard/trino-plugin-icebergpkg:apk/chainguard/trino-plugin-ignitepkg:apk/chainguard/trino-plugin-jmxpkg:apk/chainguard/trino-plugin-kafkapkg:apk/chainguard/trino-plugin-kafka-event-listenerpkg:apk/chainguard/trino-plugin-lakehousepkg:apk/chainguard/trino-plugin-ldap-group-providerpkg:apk/chainguard/trino-plugin-lokipkg:apk/chainguard/trino-plugin-mariadbpkg:apk/chainguard/trino-plugin-memorypkg:apk/chainguard/trino-plugin-mongodbpkg:apk/chainguard/trino-plugin-mysqlpkg:apk/chainguard/trino-plugin-opapkg:apk/chainguard/trino-plugin-openlineagepkg:apk/chainguard/trino-plugin-opensearchpkg:apk/chainguard/trino-plugin-oraclepkg:apk/chainguard/trino-plugin-password-authenticatorspkg:apk/chainguard/trino-plugin-pinotpkg:apk/chainguard/trino-plugin-postgresqlpkg:apk/chainguard/trino-plugin-prometheuspkg:apk/chainguard/trino-plugin-redispkg:apk/chainguard/trino-plugin-redshiftpkg:apk/chainguard/trino-plugin-resource-group-managerspkg:apk/chainguard/trino-plugin-session-property-managerspkg:apk/chainguard/trino-plugin-singlestorepkg:apk/chainguard/trino-plugin-snowflakepkg:apk/chainguard/trino-plugin-spooling-filesystempkg:apk/chainguard/trino-plugin-sqlserverpkg:apk/chainguard/trino-plugin-thriftpkg:apk/chainguard/trino-plugin-tpcdspkg:apk/chainguard/trino-plugin-tpchpkg:apk/chainguard/trino-plugin-verticapkg:apk/chainguard/zookeeper-3.8pkg:apk/chainguard/zookeeper-3.9pkg:apk/chainguard/zookeeper-custompkg:apk/chainguard/zookeeper-fips-3.8pkg:apk/chainguard/zookeeper-fips-3.9pkg:apk/wolfi/akhqpkg:apk/wolfi/apache-nifipkg:apk/wolfi/apache-nifi-registrypkg:apk/wolfi/apache-nifi-registry-toolkitpkg:apk/wolfi/cassandra-5.0pkg:apk/wolfi/cassandra-reaperpkg:apk/wolfi/dependency-trackpkg:apk/wolfi/dependency-track-bundledpkg:apk/wolfi/keycloak-config-clipkg:apk/wolfi/keycloak-config-cli-iamguarded-compatpkg:apk/wolfi/kserve-modelmeshpkg:apk/wolfi/management-api-for-apache-cassandra-4.1pkg:apk/wolfi/management-api-for-apache-cassandra-5.0pkg:apk/wolfi/nextflowpkg:apk/wolfi/sonarqubepkg:apk/wolfi/sonar-scanner-clipkg:apk/wolfi/trinopkg:apk/wolfi/trino-plugin-ai-functionspkg:apk/wolfi/trino-plugin-bigquerypkg:apk/wolfi/trino-plugin-blackholepkg:apk/wolfi/trino-plugin-cassandrapkg:apk/wolfi/trino-plugin-clickhousepkg:apk/wolfi/trino-plugin-delta-lakepkg:apk/wolfi/trino-plugin-druidpkg:apk/wolfi/trino-plugin-duckdbpkg:apk/wolfi/trino-plugin-elasticsearchpkg:apk/wolfi/trino-plugin-exasolpkg:apk/wolfi/trino-plugin-exchange-filesystempkg:apk/wolfi/trino-plugin-exchange-hdfspkg:apk/wolfi/trino-plugin-fakerpkg:apk/wolfi/trino-plugin-functions-pythonpkg:apk/wolfi/trino-plugin-google-sheetspkg:apk/wolfi/trino-plugin-hivepkg:apk/wolfi/trino-plugin-http-event-listenerpkg:apk/wolfi/trino-plugin-hudipkg:apk/wolfi/trino-plugin-icebergpkg:apk/wolfi/trino-plugin-ignitepkg:apk/wolfi/trino-plugin-jmxpkg:apk/wolfi/trino-plugin-kafkapkg:apk/wolfi/trino-plugin-kafka-event-listenerpkg:apk/wolfi/trino-plugin-lakehousepkg:apk/wolfi/trino-plugin-ldap-group-providerpkg:apk/wolfi/trino-plugin-lokipkg:apk/wolfi/trino-plugin-mariadbpkg:apk/wolfi/trino-plugin-memorypkg:apk/wolfi/trino-plugin-mongodbpkg:apk/wolfi/trino-plugin-mysqlpkg:apk/wolfi/trino-plugin-opapkg:apk/wolfi/trino-plugin-openlineagepkg:apk/wolfi/trino-plugin-opensearchpkg:apk/wolfi/trino-plugin-oraclepkg:apk/wolfi/trino-plugin-password-authenticatorspkg:apk/wolfi/trino-plugin-pinotpkg:apk/wolfi/trino-plugin-postgresqlpkg:apk/wolfi/trino-plugin-prometheuspkg:apk/wolfi/trino-plugin-redispkg:apk/wolfi/trino-plugin-redshiftpkg:apk/wolfi/trino-plugin-resource-group-managerspkg:apk/wolfi/trino-plugin-session-property-managerspkg:apk/wolfi/trino-plugin-singlestorepkg:apk/wolfi/trino-plugin-snowflakepkg:apk/wolfi/trino-plugin-spooling-filesystempkg:apk/wolfi/trino-plugin-sqlserverpkg:apk/wolfi/trino-plugin-thriftpkg:apk/wolfi/trino-plugin-tpcdspkg:apk/wolfi/trino-plugin-tpchpkg:apk/wolfi/trino-plugin-verticapkg:apk/wolfi/zookeeper-3.8pkg:apk/wolfi/zookeeper-3.9pkg:maven/ch.qos.logback/logback-corepkg:rpm/opensuse/logback&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/logback&distro=openSUSE%20Tumbleweed
< 0.26.0-r7+ 156 more
- (no CPE)range: < 0.26.0-r7
- (no CPE)range: < 2.7.2-r5
- (no CPE)range: < 2.7.2-r3
- (no CPE)range: < 2.7.2-r3
- (no CPE)range: < 5.0.7-r1
- (no CPE)range: < 4.2.3-r1
- (no CPE)range: < 4.14.0-r0
- (no CPE)range: < 4.14.0-r0
- (no CPE)range: < 4.14.0-r0
- (no CPE)range: < 1.4.2-r3
- (no CPE)range: < 1.4.2-r2
- (no CPE)range: < 6.4.1-r7
- (no CPE)range: < 6.4.1-r7
- (no CPE)range: < 1.21.4-r5
- (no CPE)range: < 1.21.4-r5
- (no CPE)range: < 1.22.1-r1
- (no CPE)range: < 1.22.1-r1
- (no CPE)range: < 1.22.1-r1
- (no CPE)range: < 1.22.1-r1
- (no CPE)range: < 0.12.0-r22
- (no CPE)range: < 4.14.0-r11
- (no CPE)range: < 0.1.113-r0
- (no CPE)range: < 0.1.113-r0
- (no CPE)range: < 0.1.113-r0
- (no CPE)range: < 3.1.1-r1
- (no CPE)range: < 3.1.1-r1
- (no CPE)range: < 25.10.4-r1
- (no CPE)range: < 26.1.0.118079-r2
- (no CPE)range: < 8.0.1.6346-r2
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 3.8.5-r2
- (no CPE)range: < 3.9.4-r2
- (no CPE)range: < 3.9.4-r5
- (no CPE)range: < 3.8.5-r1
- (no CPE)range: < 3.9.4-r2
- (no CPE)range: < 0.26.0-r7
- (no CPE)range: < 2.7.2-r5
- (no CPE)range: < 2.7.2-r3
- (no CPE)range: < 2.7.2-r3
- (no CPE)range: < 5.0.7-r1
- (no CPE)range: < 4.2.3-r1
- (no CPE)range: < 4.14.0-r0
- (no CPE)range: < 4.14.0-r0
- (no CPE)range: < 6.4.1-r7
- (no CPE)range: < 6.4.1-r7
- (no CPE)range: < 0.12.0-r22
- (no CPE)range: < 0.1.113-r0
- (no CPE)range: < 0.1.113-r0
- (no CPE)range: < 25.10.4-r1
- (no CPE)range: < 26.1.0.118079-r2
- (no CPE)range: < 8.0.1.6346-r2
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 479-r3
- (no CPE)range: < 3.8.5-r2
- (no CPE)range: < 3.9.4-r2
- (no CPE)range: < 1.5.25
- (no CPE)range: < 1.2.13-150200.3.16.1
- (no CPE)range: < 1.2.13-2.1
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.