All 6 CVE vulnerabilities found in logback, with AI-generated Chinese analysis, references, and POCs.
Vendor: QOS.ch
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-10532 | Logback deserialization whitelist bypass for Proxy objects CWE-502 | - | - | 2026-06-01 |
| CVE-2026-9828 | Logback deserialization whitelist bypass for java.lang and java.util CWE-502 | - | - | 2026-05-28 |
| CVE-2024-12801 | SaxEventRecorder vulnerable to Server-Side Request Forgery (SSRF) attacks CWE-918 | 7.5 | - | 2024-12-19 |
| CVE-2023-6481 | Logback "receiver" DOS vulnerability CVE-2023-6378 incomplete fix | 7.1 | High | 2023-12-04 |
| CVE-2023-6378 | Logback "receiver" DOS vulnerability | 7.1 | High | 2023-11-29 |
| CVE-2021-42550 | RCE from attacker with configuration edit priviledges through JNDI lookup CWE-502 | 6.6 | Medium | 2021-12-16 |
All 6 known CVE vulnerabilities affecting logback with full Chinese analysis, references, and POCs where available.