CVE-2026-55083

Source
https://cve.org/CVERecord?id=CVE-2026-55083
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55083.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-55083
Aliases
  • GHSA-3fr2-wvqx-cmr5
Published
2026-10-01T18:00:05Z
Modified
2026-10-02T03:47:24Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)
Details

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-502"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55083.json"
}
References

Affected packages

Git / github.com/dhis2/dhis2-core

Affected ranges

Type
GIT
Repo
https://github.com/dhis2/dhis2-core
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.42.0"
        },
        {
            "fixed":  "2.42.5.1"
        },
        {
            "introduced":  "2.43.0"
        },
        {
            "fixed":  "2.43.0.1"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

2.*
2.43.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55083.json"