Executive brief
Logback is a widely used logging framework for Java applications. A security flaw was identified where the component responsible for receiving log data over a network (SimpleSocketServer) does not sufficiently restrict the types of data it processes. While the risk is considered low because the system already has significant protections in place, a sophisticated attacker could potentially bypass these restrictions to manipulate internal application objects.
Technical details
A deserialization vulnerability exists in the HardenedObjectInputStream module of logback-core. An attacker who can influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can bypass existing security restrictions to instantiate objects from the java.lang and java.util packages that are not explicitly blocked. While the HardenedObjectInputStream significantly limits the attack surface, making remote code execution (RCE) or privilege escalation difficult to achieve, it represents a bypass of intended security controls. The issue is addressed in version 1.5.33 by further hardening the deserialization whitelist.
Affected products
- QOS.CH Sarl logback-core <= 1.5.32
Timeline
- 2026-05-27: patched: Release of version 1.5.33
- 2026-05-28: advisory: GitHub Advisory and NVD publication