CVE-2026-10532

Severity CVSS v4.0:
LOW
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
01/06/2026
Last modified:
01/06/2026

Description

Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.<br /> <br /> More precisely, an attacker able to influence serialized data sent to <br /> SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.<br /> <br /> <br /> Although deserialization is heavily restricted by HardenedObjectInputStream and no <br /> practical way to achieve remote code execution or significant privilege <br /> escalation has been identified, this issue constitutes a bypass of the <br /> intended security restrictions.<br /> <br /> <br /> <br /> This issue affects logback: through 1.5.33 inclusive.

References to Advisories, Solutions, and Tools