grok_connect_extended:bleeding-edge — vulnerability report

0 critical · 50 high · 71 medium · 21 low · 142 total (deduped by CVE) · 8 reviewed not-affected

Image datagrok/grok_connect_extended:bleeding-edge · digest sha256:b30783f33e33a04d71ee081db0c0e1e6e1ca819a7f68d74786a8ef5322a1a15b

Open findings

OpenVEX status affected (an upstream fix exists — the action is to apply it) or under_investigation (no upstream fix is available yet; a version match alone does not establish exploitability).

VulnerabilityStatusSeverityPackage InstalledFixed inCVSSDescription
CVE-2021-35515affectedHIGHorg.apache.commons:commons-compress1.201.217.5CVE-2021-35515
CVE-2021-35516affectedHIGHorg.apache.commons:commons-compress1.201.217.5CVE-2021-35516
CVE-2021-35517affectedHIGHorg.apache.commons:commons-compress1.201.217.5CVE-2021-35517
CVE-2021-36090affectedHIGHorg.apache.commons:commons-compress1.201.217.5CVE-2021-36090
CVE-2021-39239affectedHIGHorg.apache.jena:jena-core3.17.04.2.07.5CVE-2021-39239
CVE-2023-1370affectedHIGHnet.minidev:json-smart2.4.72.4.97.5CVE-2023-1370
CVE-2024-21634under_investigationHIGHsoftware.amazon.ion:ion-java1.0.27.5CVE-2024-21634
CVE-2024-47554affectedHIGHcommons-io:commons-io2.11.02.14.04.3CVE-2024-47554
CVE-2024-7254affectedHIGHcom.google.protobuf:protobuf-java3.21.93.25.57.5CVE-2024-7254
CVE-2025-24970affectedHIGHio.netty:netty-handler4.1.94.Final4.1.118.Final7.5CVE-2025-24970
CVE-2025-48734affectedHIGHcommons-beanutils:commons-beanutils1.9.41.11.08.8CVE-2025-48734
CVE-2025-52999affectedHIGHcom.fasterxml.jackson.core:jackson-core2.13.42.15.08.7CVE-2025-52999
CVE-2025-52999affectedHIGHcom.fasterxml.jackson.core:jackson-core2.14.12.15.08.7CVE-2025-52999
CVE-2025-55163affectedHIGHio.netty:netty-codec-http24.1.101.Final4.1.124.Final7.5CVE-2025-55163
CVE-2025-59419affectedHIGHio.netty:netty-codec-smtp4.1.101.Final4.1.128.Final5.5CVE-2025-59419
CVE-2026-33870affectedHIGHio.netty:netty-codec-http4.1.101.Final4.1.132.Final7.5CVE-2026-33870
CVE-2026-33871affectedHIGHio.netty:netty-codec-http24.1.101.Final4.1.132.Final7.5CVE-2026-33871
CVE-2026-42579affectedHIGHio.netty:netty-codec-dns4.1.101.Final4.1.133.Final9.1CVE-2026-42579
CVE-2026-42583affectedHIGHio.netty:netty-codec4.1.94.Final4.1.133.Final7.5CVE-2026-42583
CVE-2026-42584affectedHIGHio.netty:netty-codec-http4.1.101.Final4.1.133.Final9.1CVE-2026-42584
CVE-2026-42587affectedHIGHio.netty:netty-codec-http4.1.101.Final4.1.133.Final7.5CVE-2026-42587
CVE-2026-42587affectedHIGHio.netty:netty-codec-http24.1.101.Final4.1.133.Final7.5CVE-2026-42587
CVE-2026-44249affectedHIGHio.netty:netty-handler4.1.94.Final4.1.135.Final8.1CVE-2026-44249
CVE-2026-44250affectedHIGHio.netty:netty-codec-redis4.1.101.Final4.1.135.Final7.5CVE-2026-44250
CVE-2026-44890affectedHIGHio.netty:netty-codec-redis4.1.101.Final4.1.135.Final7.5CVE-2026-44890
CVE-2026-44891affectedHIGHio.netty:netty-codec-stomp4.1.101.Final4.1.136.Final7.5CVE-2026-44891
CVE-2026-44893affectedHIGHio.netty:netty-codec-haproxy4.1.101.Final4.1.135.Final7.5CVE-2026-44893
CVE-2026-45416affectedHIGHio.netty:netty-handler4.1.94.Final4.1.135.Final7.5CVE-2026-45416
CVE-2026-45674affectedHIGHio.netty:netty-resolver-dns4.1.101.Final4.1.135.Final10CVE-2026-45674
CVE-2026-46340affectedHIGHio.netty:netty-transport-sctp4.1.101.Final4.1.135.Final7.5CVE-2026-46340
CVE-2026-47691affectedHIGHio.netty:netty-resolver-dns4.1.101.Final4.1.135.Final10CVE-2026-47691
CVE-2026-48006affectedHIGHio.netty:netty-codec-redis4.1.101.Final4.1.135.Final7.5CVE-2026-48006
CVE-2026-48059affectedHIGHio.netty:netty-codec-haproxy4.1.101.Final4.1.135.Final7.5CVE-2026-48059
CVE-2026-50010affectedHIGHio.netty:netty-handler4.1.94.Final4.1.135.Final7.5CVE-2026-50010
CVE-2026-50011affectedHIGHio.netty:netty-codec-redis4.1.101.Final4.1.135.Final7.5CVE-2026-50011
CVE-2026-54399affectedHIGHorg.apache.httpcomponents.core5:httpcore55.1.35.4.37.5CVE-2026-54399
CVE-2026-54428affectedHIGHorg.apache.httpcomponents.core5:httpcore5-h25.1.35.4.37.5CVE-2026-54428
CVE-2026-54512affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.13.4.22.18.88.1CVE-2026-54512
CVE-2026-54512affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.14.12.18.88.1CVE-2026-54512
CVE-2026-54513affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.13.4.22.18.88.1CVE-2026-54513
CVE-2026-54513affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.14.12.18.88.1CVE-2026-54513
CVE-2026-55831affectedHIGHio.netty:netty-codec-http4.1.101.Final4.1.136.Final7.5CVE-2026-55831
CVE-2026-55833affectedHIGHio.netty:netty-codec-http4.1.101.Final4.1.136.Final7.5CVE-2026-55833
CVE-2026-55851affectedHIGHio.netty:netty-codec-haproxy4.1.101.Final4.1.136.Final7.5CVE-2026-55851
CVE-2026-56745affectedHIGHio.netty:netty-codec-http4.1.101.Final4.1.136.Final7.5CVE-2026-56745
CVE-2026-56817affectedHIGHio.netty:netty-codec-xml4.1.101.Final4.1.136.Final9.8CVE-2026-56817
CVE-2026-56819affectedHIGHio.netty:netty-codec-http24.1.101.Final4.1.136.Final7.5CVE-2026-56819
CVE-2026-56820affectedHIGHio.netty:netty-handler-ssl-ocsp4.1.101.Final4.1.136.Final9.1CVE-2026-56820
CVE-2026-56821affectedHIGHio.netty:netty-handler-ssl-ocsp4.1.101.Final4.1.136.Final7.4CVE-2026-56821
CVE-2026-56822affectedHIGHio.netty:netty-handler-ssl-ocsp4.1.101.Final4.1.136.Final7.4CVE-2026-56822
CVE-2026-59901affectedHIGHio.netty:netty-codec4.1.94.Final4.1.136.Final7.5CVE-2026-59901
CVE-2026-59902affectedHIGHio.netty:netty-transport-sctp4.1.101.Final4.1.137.Final7.5CVE-2026-59902
CVE-2026-73507affectedHIGHio.netty:netty-codec-xml4.1.101.Final4.1.136.Final7.5CVE-2026-73507
GHSA-r7wm-3cxj-wff9affectedHIGHcom.fasterxml.jackson.core:jackson-core2.13.42.18.8GHSA-r7wm-3cxj-wff9
GHSA-r7wm-3cxj-wff9affectedHIGHcom.fasterxml.jackson.core:jackson-core2.14.12.18.8GHSA-r7wm-3cxj-wff9
CVE-2023-2976affectedMEDIUMcom.google.guava:guava31.1-jre32.0.0-android7.1CVE-2023-2976
CVE-2023-31486under_investigationMEDIUMperl5.34.0-3ubuntu1.78.1CVE-2023-31486
CVE-2024-10041under_investigationMEDIUMpam1.4.0-11ubuntu2.74.7CVE-2024-10041
CVE-2024-25710affectedMEDIUMorg.apache.commons:commons-compress1.201.26.05.5CVE-2024-25710
CVE-2024-29025affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.108.Final5.3CVE-2024-29025
CVE-2024-29131affectedMEDIUMorg.apache.commons:commons-configuration22.9.02.10.17.3CVE-2024-29131
CVE-2024-29133affectedMEDIUMorg.apache.commons:commons-configuration22.9.02.10.15.4CVE-2024-29133
CVE-2024-47535affectedMEDIUMio.netty:netty-common4.1.94.Final4.1.115.Final5.5CVE-2024-47535
CVE-2025-15649under_investigationMEDIUMperl5.34.0-3ubuntu1.75.5CVE-2025-15649
CVE-2025-25193affectedMEDIUMio.netty:netty-common4.1.94.Final4.1.118.Final5.5CVE-2025-25193
CVE-2025-48924under_investigationMEDIUMcommons-lang:commons-lang2.45.3CVE-2025-48924
CVE-2025-48924affectedMEDIUMorg.apache.commons:commons-lang33.12.03.18.05.3CVE-2025-48924
CVE-2025-58057affectedMEDIUMio.netty:netty-codec4.1.94.Final4.1.125.Final7.5CVE-2025-58057
CVE-2025-67735affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.129.Final6.5CVE-2025-67735
CVE-2025-68161affectedMEDIUMorg.apache.logging.log4j:log4j-core2.17.12.25.34.8CVE-2025-68161
CVE-2026-12087under_investigationMEDIUMperl5.34.0-3ubuntu1.79.1CVE-2026-12087
CVE-2026-13221under_investigationMEDIUMperl5.34.0-3ubuntu1.79.1CVE-2026-13221
CVE-2026-13595under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.55.3CVE-2026-13595
CVE-2026-13757under_investigationMEDIUMp11-kit0.24.0-6build16.2CVE-2026-13757
CVE-2026-15534under_investigationMEDIUMperl5.34.0-3ubuntu1.75.7CVE-2026-15534
CVE-2026-18938under_investigationMEDIUMp11-kit0.24.0-6build16.2CVE-2026-18938
CVE-2026-19487under_investigationMEDIUMperl5.34.0-3ubuntu1.75.3CVE-2026-19487
CVE-2026-27456under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.54.7CVE-2026-27456
CVE-2026-34477affectedMEDIUMorg.apache.logging.log4j:log4j-core2.17.12.25.45.9CVE-2026-34477
CVE-2026-34480affectedMEDIUMorg.apache.logging.log4j:log4j-core2.17.12.25.47.5CVE-2026-34480
CVE-2026-41417affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.133.Final5.3CVE-2026-41417
CVE-2026-42497under_investigationMEDIUMperl5.34.0-3ubuntu1.77.5CVE-2026-42497
CVE-2026-42580affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.133.Final6.5CVE-2026-42580
CVE-2026-42581affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.133.Final9.8CVE-2026-42581
CVE-2026-42585affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.133.Final7.5CVE-2026-42585
CVE-2026-42586affectedMEDIUMio.netty:netty-codec-redis4.1.101.Final4.1.133.Final7.1CVE-2026-42586
CVE-2026-44248affectedMEDIUMio.netty:netty-codec-mqtt4.1.101.Final4.1.133.Final7.5CVE-2026-44248
CVE-2026-45205affectedMEDIUMorg.apache.commons:commons-configuration22.9.02.15.05.3CVE-2026-45205
CVE-2026-45536affectedMEDIUMio.netty:netty-transport-native-epoll4.1.101.Final4.1.135.Final4CVE-2026-45536
CVE-2026-45536affectedMEDIUMio.netty:netty-transport-native-kqueue4.1.101.Final4.1.135.Final4CVE-2026-45536
CVE-2026-45673affectedMEDIUMio.netty:netty-resolver-dns4.1.101.Final4.1.135.Final6.8CVE-2026-45673
CVE-2026-47244affectedMEDIUMio.netty:netty-codec-http24.1.101.Final4.1.135.Final5.3CVE-2026-47244
CVE-2026-48043affectedMEDIUMio.netty:netty-codec-http24.1.101.Final4.1.135.Final7.5CVE-2026-48043
CVE-2026-48959under_investigationMEDIUMperl5.34.0-3ubuntu1.77.5CVE-2026-48959
CVE-2026-48961under_investigationMEDIUMperl5.34.0-3ubuntu1.77.3CVE-2026-48961
CVE-2026-48962under_investigationMEDIUMperl5.34.0-3ubuntu1.77.3CVE-2026-48962
CVE-2026-49844affectedMEDIUMorg.apache.logging.log4j:log4j-api2.17.12.25.55.9CVE-2026-49844
CVE-2026-50020affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.135.Final5.3CVE-2026-50020
CVE-2026-50193affectedMEDIUMcom.fasterxml.jackson.core:jackson-databind2.13.4.22.14.07.5CVE-2026-50193
CVE-2026-50560affectedMEDIUMio.netty:netty-codec-http24.1.101.Final4.1.135.Final5.3CVE-2026-50560
CVE-2026-53613under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.5CVE-2026-53613
CVE-2026-53615under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.5CVE-2026-53615
CVE-2026-53910under_investigationMEDIUMdiffutils1:3.8-0ubuntu2CVE-2026-53910
CVE-2026-54369under_investigationMEDIUMacl2.3.1-18.4CVE-2026-54369
CVE-2026-54370under_investigationMEDIUMacl2.3.1-17.2CVE-2026-54370
CVE-2026-54371under_investigationMEDIUMattr1:2.5.1-1build18.4CVE-2026-54371
CVE-2026-54514affectedMEDIUMcom.fasterxml.jackson.core:jackson-databind2.13.4.22.18.85.3CVE-2026-54514
CVE-2026-54514affectedMEDIUMcom.fasterxml.jackson.core:jackson-databind2.14.12.18.85.3CVE-2026-54514
CVE-2026-54515affectedMEDIUMcom.fasterxml.jackson.core:jackson-databind2.13.4.22.18.95.3CVE-2026-54515
CVE-2026-54515affectedMEDIUMcom.fasterxml.jackson.core:jackson-databind2.14.12.18.95.3CVE-2026-54515
CVE-2026-56391under_investigationMEDIUMcoreutils8.32-4.1ubuntu1.3CVE-2026-56391
CVE-2026-56392under_investigationMEDIUMcoreutils8.32-4.1ubuntu1.3CVE-2026-56392
CVE-2026-56746affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.136.Final6.5CVE-2026-56746
CVE-2026-56818affectedMEDIUMio.netty:netty-codec-redis4.1.101.Final4.1.136.Final6.5CVE-2026-56818
CVE-2026-57432under_investigationMEDIUMperl5.34.0-3ubuntu1.78.4CVE-2026-57432
CVE-2026-57433under_investigationMEDIUMperl5.34.0-3ubuntu1.79.8CVE-2026-57433
CVE-2026-59898affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.136.Final7.5CVE-2026-59898
CVE-2026-59899affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.136.Final7.5CVE-2026-59899
CVE-2026-59900affectedMEDIUMio.netty:netty-codec-http24.1.101.Final4.1.136.Final5.3CVE-2026-59900
CVE-2026-59903affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.137.Final6.5CVE-2026-59903
CVE-2026-59919affectedMEDIUMio.netty:netty-codec-haproxy4.1.101.Final4.1.136.Final5.5CVE-2026-59919
CVE-2026-59920affectedMEDIUMio.netty:netty-codec-stomp4.1.101.Final4.1.136.Final6.5CVE-2026-59920
CVE-2026-59921affectedMEDIUMio.netty:netty-codec-http4.1.101.Final4.1.136.Final6.5CVE-2026-59921
CVE-2026-59949affectedMEDIUMat.yawk.lz4:lz4-java1.10.11.11.16.5CVE-2026-59949
CVE-2026-6368under_investigationMEDIUMglibc2.35-0ubuntu3.14CVE-2026-6368
CVE-2026-64607affectedMEDIUMorg.apache.httpcomponents.client5:httpclient55.1.35.6.35.3CVE-2026-64607
CVE-2026-6791under_investigationMEDIUMglibc2.35-0ubuntu3.14CVE-2026-6791
CVE-2026-7017under_investigationMEDIUMperl5.34.0-3ubuntu1.77.1CVE-2026-7017
CVE-2026-73508affectedMEDIUMio.netty:netty-codec-dns4.1.101.Final4.1.136.Final5.3CVE-2026-73508
CVE-2026-9538under_investigationMEDIUMperl5.34.0-3ubuntu1.77.5CVE-2026-9538
CVE-2016-2781under_investigationLOWcoreutils8.32-4.1ubuntu1.36.5CVE-2016-2781
CVE-2020-8908affectedLOWcom.google.guava:guava31.1-jre32.0.0-android3.3CVE-2020-8908
CVE-2022-27943under_investigationLOWgcc-1212.3.0-1ubuntu1~22.04.35.5CVE-2022-27943
CVE-2022-3219under_investigationLOWgnupg22.2.27-3ubuntu2.53.3CVE-2022-3219
CVE-2022-41409under_investigationLOWpcre210.39-3ubuntu0.17.5CVE-2022-41409
CVE-2022-4899under_investigationLOWlibzstd1.4.8+dfsg-3build17.5CVE-2022-4899
CVE-2023-29383under_investigationLOWshadow1:4.8.1-2ubuntu2.23.3CVE-2023-29383
CVE-2023-50495under_investigationLOWncurses6.3-2ubuntu0.26.5CVE-2023-50495
CVE-2024-2236under_investigationLOWlibgcrypt201.9.4-3ubuntu3.25.9CVE-2024-2236
CVE-2024-56433under_investigationLOWshadow1:4.8.1-2ubuntu2.2CVE-2024-56433
CVE-2025-5278under_investigationLOWcoreutils8.32-4.1ubuntu1.34.4CVE-2025-5278
CVE-2025-58056affectedLOWio.netty:netty-codec-http4.1.101.Final4.1.125.Final7.5CVE-2025-58056
CVE-2025-6141under_investigationLOWncurses6.3-2ubuntu0.24.8CVE-2025-6141
CVE-2026-42250under_investigationLOWbzip21.0.8-5build1CVE-2026-42250
CVE-2026-42578affectedLOWio.netty:netty-handler-proxy4.1.101.Final4.1.133.Final7.5CVE-2026-42578
CVE-2026-57062under_investigationLOWgnupg22.2.27-3ubuntu2.5CVE-2026-57062
CVE-2026-75803under_investigationLOWopenssl3.0.2-0ubuntu1.26CVE-2026-75803
CVE-2016-20013under_investigationMINIMALglibc2.35-0ubuntu3.147.5CVE-2016-20013
CVE-2017-11164under_investigationMINIMALpcre32:8.39-13ubuntu0.22.04.17.5CVE-2017-11164
CVE-2018-5709under_investigationMINIMALkrb51.19.2-2ubuntu0.87.5CVE-2018-5709
CVE-2023-47039under_investigationMINIMALperl5.34.0-3ubuntu1.77.8CVE-2023-47039

Reviewed findings — not affected

Manually reviewed findings with OpenVEX status not_affected. Each row carries the spec justification label and the evidence for why the vulnerable code does not affect this image's functionality (and where that was verified). Excluded from the severity counts above; present as full statements in the OpenVEX document.

VulnerabilitySeverityPackageInstalled JustificationEvidence / where
CVE-2025-59250HIGHcom.microsoft.sqlserver:mssql-jdbc12.10.2vulnerable_code_not_presentmssql-jdbc 12.10.2.jre8 (previously 12.8.2.jre8) is well past the fix wave; scanners mis-order the bare '12.10.2' from the jar's pom.properties against the '12.8.2.jre11' fixed-version string because the .jreN suffix breaks their version comparators (known Trivy/Grype issue: aquasecurity/trivy#9745, anchore/grype#3042). The jre11 artifact cannot be used on the Java-8 runtime. Applies to any X.Y.Z.jre8 >= 12.8.2.
CVE-2026-2332HIGHorg.eclipse.jetty:jetty-http9.4.58.v20250814vulnerable_code_cannot_be_controlled_by_adversaryjetty-http request smuggling via chunk-extension quoted-string parsing. No OSS fix exists on the Java-8-compatible jetty 9.4 line (9.4.58.v20250814 is the newest on Maven Central and is in the affected range; the advisory's 9.4.60 fix ships only in the HeroDevs NES fork; jetty 10+ needs Java 11). Not adversary-controllable in our topology: grok_connect listens cluster-internally on :1234 with datlas as its ONLY client, connecting directly with no HTTP intermediary (proxy/LB/cache) in between — request smuggling requires a parsing-differential between two HTTP hops, and user input reaches grok_connect solely inside JSON bodies of datlas-composed requests, never as raw protocol elements. Re-review if grok_connect is ever exposed through an ingress/proxy or the spark-java/jetty stack changes. Verified 2026-08-12.
CVE-2026-10050HIGHorg.eclipse.jetty:jetty-security9.4.58.v20250814vulnerable_code_not_in_execute_pathjetty-security Digest-authentication bypass (ISO-8859-1 encoding collision). Fixed only in jetty 12.0.36/12.1.10; 9.4 is EOL (NES-only backport) and jetty 10+ needs Java 11. Not in the execute path: grok_connect configures NO HTTP authentication — spark-java 2.9.4 wires no SecurityHandler/LoginService, so jetty's DigestAuthenticator is never instantiated; the service is cluster-internal with datlas as its only client. Re-review if HTTP auth is ever added or the spark/jetty stack changes. Verified 2026-08-12.
CVE-2024-6763MEDIUMorg.eclipse.jetty:jetty-http9.4.58.v20250814vulnerable_code_not_in_execute_pathjetty-http HttpURI lenient authority parsing affects applications that use the HttpURI class programmatically for URI validation/redirect construction. Neither spark-java 2.9.4 route handling nor grok_connect code calls HttpURI (no redirects are ever issued); the fix exists only in jetty 12 (Java 17). Verified 2026-08-13.
CVE-2026-6790MEDIUMorg.eclipse.jetty:jetty-server9.4.58.v20250814vulnerable_code_cannot_be_controlled_by_adversaryjetty-server Host/authority desynchronization matters where authority selects behavior: virtual hosts, redirects, caches, reverse-proxy routing, request-log trust. grok_connect has none of these (single spark-java route set, no vhosts, no redirects, no cache) and is cluster-internal with datlas as its only client, connecting directly with no proxy hop whose routing could be confused. No fix on the Java-8-compatible jetty 9.4 line (9.4.58 is the newest on Maven Central; later 9.4.x numbers are the commercial NES fork). Verified 2026-08-13.
CVE-2026-10532LOWch.qos.logback:logback-core1.3.16vulnerable_code_not_in_execute_pathSame surface as CVE-2026-9828: object injection via the SimpleSocketServer/SimpleSSLSocketServer receivers, which grok_connect never runs (appender-only logback.xml, no receiver/server components). Fixed only in 1.5.34 (Java 11+). Verified 2026-08-13.
CVE-2026-9828LOWch.qos.logback:logback-core1.3.16vulnerable_code_not_in_execute_pathlogback-core HardenedObjectInputStream object-injection is reachable only through the SimpleSocketServer/SimpleSSLSocketServer serialized-event receivers. grok_connect never instantiates them: logback.xml configures only ConsoleAppender, AsyncAppender and the in-process QueryStreamAppender (verified src/main/resources/logback.xml). Fixed only in 1.5.33 (Java 11+). Verified 2026-08-13.
CVE-2026-1225LOWch.qos.logback:logback-core1.3.16vulnerable_code_cannot_be_controlled_by_adversarylogback-core config-processing ACE requires an attacker to MODIFY the logback configuration file. grok_connect's logback.xml is compiled into the read-only shaded jar (src/main/resources/logback.xml), the process runs as the non-root 'grok' user, and the entrypoint sets no -Dlogback.configurationFile override — there is no writable or externally-supplied config path. Fixed only in logback 1.5.25 (Java 11+); 1.3.x is the Java-8 ceiling. Verified 2026-08-13.