Update dependency ch.qos.logback:logback-core to v1.5.34 [SECURITY] - #52
Open
renovate[bot] wants to merge 1 commit into
Open
Update dependency ch.qos.logback:logback-core to v1.5.34 [SECURITY]#52renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/maven-ch.qos.logback-logback-core-vulnerability
branch
from
January 22, 2026 20:39
11ef8fa to
318fdda
Compare
renovate
Bot
deleted the
renovate/maven-ch.qos.logback-logback-core-vulnerability
branch
March 27, 2026 01:43
renovate
Bot
force-pushed
the
renovate/maven-ch.qos.logback-logback-core-vulnerability
branch
2 times, most recently
from
March 30, 2026 22:08
318fdda to
d463ddf
Compare
renovate
Bot
force-pushed
the
renovate/maven-ch.qos.logback-logback-core-vulnerability
branch
from
July 6, 2026 02:34
d463ddf to
ab1ee90
Compare
renovate
Bot
force-pushed
the
renovate/maven-ch.qos.logback-logback-core-vulnerability
branch
from
July 16, 2026 04:02
ab1ee90 to
76ecc74
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.5.18→1.5.34Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing
CVE-2025-11226 / GHSA-25qh-j22f-pwp8
More information
Details
QOS.CH logback-core versions up to 1.5.18 contain an ACE vulnerability in conditional configuration file processing in Java applications. This vulnerability allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting a malicious environment variable before program execution.
A successful attack requires the Janino library and Spring Framework to be present on the user's class path. Additionally, the attacker must have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privileges.
Severity
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:H/SI:L/SA:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Logback allows an attacker to instantiate classes already present on the class path
CVE-2026-1225 / GHSA-qqpg-mvqg-649v
More information
Details
ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.
The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.
Severity
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability
CVE-2026-9828 / GHSA-p47f-322f-whfh
More information
Details
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.
More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from classes in the java.lang and java.util packages that are not explicitly blocked.
Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions.
This issue affects logback: through 1.5.32 inclusive.
Severity
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:L/U:GreenReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
CVE-2026-10532 / GHSA-jhq6-gfmj-v8fx
More information
Details
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.
More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.
Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions.
This issue affects logback: through 1.5.33 inclusive.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:M/U:GreenReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.