CVE-2026-24656

Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS. NB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue. This issue affects Apache Karaf Decanter before 2.12.0. Users are recommended to upgrade to version 2.12.0, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:karaf_decanter:*:*:*:*:*:*:*:*

History

27 Jan 2026, 20:30

Type Values Removed Values Added
References () https://lists.apache.org/thread/dc5wmdn6hyc992olntkl75kk04ndzx34 - () https://lists.apache.org/thread/dc5wmdn6hyc992olntkl75kk04ndzx34 - Mailing List
References () http://www.openwall.com/lists/oss-security/2026/01/24/1 - () http://www.openwall.com/lists/oss-security/2026/01/24/1 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:karaf_decanter:*:*:*:*:*:*:*:*
First Time Apache
Apache karaf Decanter

26 Jan 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.7

26 Jan 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 10:16

Updated : 2026-01-27 20:30


NVD link : CVE-2026-24656

Mitre link : CVE-2026-24656

CVE.ORG link : CVE-2026-24656


JSON object : View

Products Affected

apache

  • karaf_decanter
CWE
CWE-502

Deserialization of Untrusted Data