10 Total advisories
10 Vulnerabilities
0 Malware
Dependency scanning
Check whether ch.qos.logback:logback-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-10532
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
UNKNOWN
CVE-2026-9828
QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability
UNKNOWN
CVE-2025-11226
QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing
HIGH 7.1
CVE-2023-6378
logback serialization vulnerability
UNKNOWN
CVE-2024-12798
QOS.CH logback-core Expression Language Injection vulnerability
UNKNOWN
CVE-2026-1225
Logback allows an attacker to instantiate classes already present on the class path
UNKNOWN
CVE-2024-12801
QOS.CH logback-core Server-Side Request Forgery vulnerability
HIGH 7.1
CVE-2023-6481
Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
CRITICAL 9.8
CVE-2017-5929
QOS.ch Logback vulnerable to Deserialization of Untrusted Data
MEDIUM 6.6
CVE-2021-42550
Deserialization of Untrusted Data in logback
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes