Intel

AIKIDO-2025-10694

logback-core is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2025-11226 Published Oct 9, 2025

59

Medium Risk

This Affects:

javalogback-core
0.9.20 - 1.3.15
Fixed in 1.3.16
1.4.0 - 1.5.18
Fixed in 1.5.19
Are you affected? Scan for Free

TL;DR

Affected versions of this package do not properly validate the logback.xml configuration file when both the Janino library and the Spring Framework are present on the classpath. An attacker can execute arbitrary code by compromising an existing configuration file or injecting a malicious environment variable prior to program execution. This vulnerability is exploitable only if the attacker has write access to a configuration file or the ability to set malicious environment variables.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and both the Janino library and the Spring Framework are present on the classpath.

Background info

logback-core is vulnerable to Improper Input Validation in versions 1.4.0 - 1.5.18 and 0.9.20 - 1.3.15.

How to fix this

Upgrade the ch.qos.logback:logback-core library to a patch version.