Package
kayenta-fips-2026.1
Component
logback-core
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Logback 1.4.x has no OSS patch for CVE-2024-12798; the fix landed in 1.5.13 (logback 1.4.x EOL'd before the fix). Bumping past 1.4.x requires Spring Boot 3.2+: Spring Boot 3.1.x's LogbackConfigurator calls LoggerContext.getConfigurationLock(), which was removed in logback 1.5.x — kayenta-fips-2026.1 currently pins Spring Boot 3.1.x. A 1.5.25 bump was attempted and the test pod crashed with NoSuchMethodError during logging-system init.
Status