Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-9828

Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-502 Deserialización de datos no confiables
Fecha de publicación:
28/05/2026
Última modificación:
29/05/2026

Descripción

*** Pendiente de traducción *** Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.<br /> <br /> More precisely, an attacker able to influence serialized data sent to <br /> SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from<br /> classes in the java.lang and java.util packages that are not explicitly<br /> blocked.<br /> <br /> Although deserialization is heavily restricted by HardenedObjectInputStream and no <br /> practical way to achieve remote code execution or significant privilege <br /> escalation has been identified, this issue constitutes a bypass of the <br /> intended security restrictions.<br /> <br /> <br /> <br /> This issue affects logback: through 1.5.32 inclusive.

Referencias a soluciones, herramientas e información