Bug 2516044 (CVE-2026-19880)

Summary: CVE-2026-19880 ch.qos.logback/logback-classic: Logback-classic: Path traversal allows arbitrary log file creation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: amctagga, anthomas, aoconnor, aschwart, aszczucz, bniver, boliveir, csutherl, dhanak, drichtar, drosa, dsimansk, dsoumis, ehelms, flucifre, ggainey, gmalinko, gmeno, groman, gtanzill, janstey, jbuscemi, jclere, jpasqual, juwatts, jwon, kingland, mbenjamin, mdellweg, mhackett, mhulan, mnovotny, mposolda, nmoumoul, osousa, pcreech, pdelbell, pjindal, plodge, rchan, rhel-process-autobot, rjohnson, rmartinc, rmaucher, rstepani, sausingh, sdawley, smallamp, sostapov, ssilvert, sthorger, szappis, tmalecek, vereddy, vmuzikar, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Logback-classic. This path-traversal vulnerability allows a remote attacker to create and append log files outside the intended directory. This occurs because an unsanitized discriminator value, influenced by the attacker (for example, via an HTTP header), is used in a file path within the logging mechanism.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-14 14:41:16 UTC
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an 
MDC-based discriminator value flows unsanitized into a nested 
FileAppender path, letting an attacker who influences that MDC value 
(e.g. via an HTTP header)
 create and append log files outside the intended directory. 


This issue affects Logback-classic: from 0.9.14 through 1.6.2.