CVE-2026-10532
Severity CVSS v4.0:
LOW
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
01/06/2026
Last modified:
01/06/2026
Description
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.<br />
<br />
More precisely, an attacker able to influence serialized data sent to <br />
SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.<br />
<br />
<br />
Although deserialization is heavily restricted by HardenedObjectInputStream and no <br />
practical way to achieve remote code execution or significant privilege <br />
escalation has been identified, this issue constitutes a bypass of the <br />
intended security restrictions.<br />
<br />
<br />
<br />
This issue affects logback: through 1.5.33 inclusive.



