maven package report

Is org.slf4j:slf4j-ext safe?

1 known vulnerability, worst severity CRITICAL.

cvss
9.0

how bad it is if exploited, out of 10

epss
14.7%

chance of exploitation in the next 30 days

xyz score
4.5

CyberXYZ composite, out of 10

fig. 01 — GHSA-w77p-8cfg-2x43, the advisory selected below

// advisories

GHSA-w77p-8cfg-2x43

CRITICALCVE-2018-8088

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta4 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J version 1.7.26 and later and in the 2.0.x series.

Affected
<= 1.7.25, >= 1.8.0-alpha0, <= 1.8.0-beta2
Fixed in
1.7.26
Weakness
CWE-284
Published
2022-05-13
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 01:52 UTC. The most recent advisory here was published 2022-05-13. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.slf4j:slf4j-ext safe? maven package security report | CyberXYZ