CVE-2023-6378: Qos Logback

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

Affected products

  • Qos Logback: from 1.2.0, before 1.2.13 (fixed in 1.2.13); from 1.3.0, before 1.3.12 (fixed in 1.3.12); from 1.4.0, before 1.4.12 (fixed in 1.4.12)

Published 2023-11-29. Last modified 2026-06-17.