github qos-ch/logback v_1.6.5
Logback 1.6.5

4 hours ago

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829d associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Don't miss a new logback release

NewReleases is sending notifications on new releases.