CVE-2026-10532
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-502
Deserialización de datos no confiables
Fecha de publicación:
01/06/2026
Última modificación:
01/06/2026
Descripción
*** Pendiente de traducción *** Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.<br />
<br />
More precisely, an attacker able to influence serialized data sent to <br />
SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.<br />
<br />
<br />
Although deserialization is heavily restricted by HardenedObjectInputStream and no <br />
practical way to achieve remote code execution or significant privilege <br />
escalation has been identified, this issue constitutes a bypass of the <br />
intended security restrictions.<br />
<br />
<br />
<br />
This issue affects logback: through 1.5.33 inclusive.



