SSerguey Asael Shinder
Java coding notes: the JVM, and writing software that lasts

Serguey Asael Shinder: Logback 1.6.5 stops trying to clean MDC values and rejects bad ones instead

· by Serguey Asael Shinder / Serguey Shinder

Logback 1.6.5, dated 30 September and published on GitHub on 2 October, fixes a vulnerability that an earlier fix did not close. If you use SiftingAppender with values from the MDC, it is the release to take.

The problem. SiftingAppender writes log events to different appenders, often different files, chosen by a key; MDCBasedDiscriminator takes that key from the MDC, the per-thread context many applications fill with request data such as a user or tenant id. When that value ends up in a file name, an attacker who controls it controls part of a path. Version 1.6.3 addressed CVE-2026-19880 by stripping forward and back slashes from MDC values. According to the release notes, that was insufficient: a value could still contain relative path components such as .., variable references, or characters that are special in file name patterns and email addresses. The new issue, CVE-2026-104721, was reported by François Martin.

Serguey Asael Shinder: Logback 1.6.5 stops trying to clean MDC values and rejects bad ones instead
Logback 1.6.5 stops trying to clean MDC values and rejects bad ones instead — Serguey Asael Shinder

The fix. MDCBasedDiscriminator now rejects values instead of editing them. A value is rejected if it is empty, longer than 64 characters, contains .., or contains any of / \ $ { } [ ] ( ) | ? * + % , @. A rejected value is replaced by the discriminator's DefaultValue, and a rate-limited warning is logged for each one.

Also in the release. With compression enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also delete old log files that were never compressed, for example because the application was down at rollover time; previously maxHistory ignored them and they accumulated indefinitely. SimpleInvocationGate, deprecated in 1.6.3, is now marked for removal in favour of FixedIntervalInvocationGate. The release notes also state that a bit-for-bit identical binary can be reproduced from the tagged commit with Java 21.

What to do. Upgrade if any SiftingAppender uses MDC values. Then check what your default value is, because legitimate keys that happen to contain a @ or exceed 64 characters - an email address, a long tenant name - will now land in the default appender, and the only sign will be a warning in the log.