CVE-2026-1225

Severity CVSS v4.0:
LOW
Type:
CWE-20 Input Validation
Publication date:
22/01/2026
Last modified:
22/01/2026

Description

ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.<br /> <br /> <br /> <br /> <br /> The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must have write access to a <br /> configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.

References to Advisories, Solutions, and Tools