Input validation error in Logback - CVE-2026-1225
Published: March 10, 2026
Vulnerability details
The vulnerability allows a local privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A local privileged user can instantiate classes already present on the class path by compromising an existing logback configuration file. The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a configuration file.
Affected software
Rational Functional Tester (RFT)
IBM Rational ClearCase
Storage Protect Server
Maximo Application Suite - Visual Inspection Component
Rational Performance Tester
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
DevOps Test Performance
DevOps Code ClearCase
DevOps Test UI
openSUSE Leap
logback
logback-access
logback-javadoc
logback-examples
How to mitigate CVE-2026-1225
Storage Protect Server - update to 8.2.1
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.19, 9.1.12
IBM Rational ClearCase - update to 10.0.1.6
DevOps Test Performance - update to 11.0.8
DevOps Code ClearCase - update to 11.0.0.6
DevOps Test UI - update to 11.0.8
logback - update to 1.2.13-150200.3.16.1
logback-access - update to 1.2.13-150200.3.16.1
logback-javadoc - update to 1.2.13-150200.3.16.1
logback-examples - update to 1.2.13-150200.3.16.1
External References
Related Security Bulletins
- Input validation error in QOS.CH logback-core
- Multiple vulnerabilities in IBM DevOps Code ClearCase
- SUSE update for logback
- IBM Storage Protect Server update for logback-core library
- IBM DevOps Test Performance update for logback-core library
- IBM Maximo Application Suite - Visual Inspection Component update for logback-core
- IBM Rational Functional Tester / DevOps Test UI update for logback-core
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition