Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-10532

Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-502 Deserialización de datos no confiables
Fecha de publicación:
01/06/2026
Última modificación:
01/06/2026

Descripción

*** Pendiente de traducción *** Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.<br /> <br /> More precisely, an attacker able to influence serialized data sent to <br /> SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.<br /> <br /> <br /> Although deserialization is heavily restricted by HardenedObjectInputStream and no <br /> practical way to achieve remote code execution or significant privilege <br /> escalation has been identified, this issue constitutes a bypass of the <br /> intended security restrictions.<br /> <br /> <br /> <br /> This issue affects logback: through 1.5.33 inclusive.

Referencias a soluciones, herramientas e información