GHSA-jmw5-58c7-587h

Suggest an improvement
Source
https://github.com/advisories/GHSA-jmw5-58c7-587h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jmw5-58c7-587h/GHSA-jmw5-58c7-587h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jmw5-58c7-587h
Aliases
Published
2026-01-26T12:30:29Z
Modified
2026-01-27T00:12:07.763719Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Apache Karaf Decanter has Deserialization of Untrusted Data in its Log Socket Collector
Details

Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.

The Decanter Log Socket Collector exposes port 4560 without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. The Log Socket Collector is vulnerable to deserialization of untrusted data, eventually causing DoS.

NB: Decanter Log Socket Collector is not installed by default. Users who have not installed the Decanter Log Socket are not impacted by this issue.

This issue affects Apache Karaf Decanter before 2.12.0.

Users are recommended to upgrade to version 2.12.0, which fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-502"
    ],
    "severity": "LOW",
    "nvd_published_at": "2026-01-26T10:16:09Z",
    "github_reviewed": true,
    "github_reviewed_at": "2026-01-26T23:43:29Z"
}
References

Affected packages

Maven / org.apache.karaf.decanter.collector:org.apache.karaf.decanter.collector.log.socket

Package

Name
org.apache.karaf.decanter.collector:org.apache.karaf.decanter.collector.log.socket
View open source insights on deps.dev
Purl
pkg:maven/org.apache.karaf.decanter.collector/org.apache.karaf.decanter.collector.log.socket

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12.0

Affected versions

1.*

1.1.0
1.2.0
1.3.0
1.4.0

2.*

2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.10.0
2.11.0

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jmw5-58c7-587h/GHSA-jmw5-58c7-587h.json"