CVE-2026-9828

Severity CVSS v4.0:
LOW
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
28/05/2026
Last modified:
29/05/2026

Description

Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.<br /> <br /> More precisely, an attacker able to influence serialized data sent to <br /> SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from<br /> classes in the java.lang and java.util packages that are not explicitly<br /> blocked.<br /> <br /> Although deserialization is heavily restricted by HardenedObjectInputStream and no <br /> practical way to achieve remote code execution or significant privilege <br /> escalation has been identified, this issue constitutes a bypass of the <br /> intended security restrictions.<br /> <br /> <br /> <br /> This issue affects logback: through 1.5.32 inclusive.

References to Advisories, Solutions, and Tools