CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-11226: Logback-core 0.9.20 through 1.5.18

CVE-2025-11226. EPSS 0.00194 (percentile 0.08266), scored 2026-10-08.

Affected technology

Logback-core · 0.9.20 through 1.5.18
QOS.CH Sarl

Description’s affected range: up to and including version 1.5.18 in Java applications,

Component: logback-core

Attack conditions (Vendor/CNA, CVSS 4.0): Local · High privileges required · No user interaction required

What an attacker can do

An attacker can execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution. Vendor/CNA’s CVSS 4.0 assessment (base score 7.0/10) rates confidentiality and integrity impact as high; availability impact as none.

Published

CWE
CWE-20
CCR priority
0.0 /100 (P5)
EPSS
0.00194 · percentile 0.08266 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-11226.html