CVE-2026-9828
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-502
Deserialización de datos no confiables
Fecha de publicación:
28/05/2026
Última modificación:
29/05/2026
Descripción
*** Pendiente de traducción *** Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.<br />
<br />
More precisely, an attacker able to influence serialized data sent to <br />
SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from<br />
classes in the java.lang and java.util packages that are not explicitly<br />
blocked.<br />
<br />
Although deserialization is heavily restricted by HardenedObjectInputStream and no <br />
practical way to achieve remote code execution or significant privilege <br />
escalation has been identified, this issue constitutes a bypass of the <br />
intended security restrictions.<br />
<br />
<br />
<br />
This issue affects logback: through 1.5.32 inclusive.



