Junglewise Threat Intelligence

CVE-2026-1225: Logback allows an attacker to instantiate classes already present on the class path

CVE-2026-1225 · Severity: medium · CVSS 4 · Published 2026-01-22

Technologies: ch.qos.logback:logback-core (Maven). Vendors: Maven.

Executive brief

Logback allows an attacker to instantiate classes already present on the class path

Affected products

  • Maven ch.qos.logback:logback-core

Related threats