PT-2026-45408 · Unknown · Logback-Core

·

CVE-2026-10532

·

Published

2026-06-01

·

Updated

2026-07-21

CVSS v4.0

2.9

Low

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:M/U:Green
Name of the Vulnerable Software and Affected Versions logback-core versions prior to 1.5.34
Description Deserialization of untrusted data in the HardenedObjectInputStream module allows for Object Injection, although the impact is heavily restricted. An attacker capable of influencing serialized data sent to the 'SimpleSocketServer' or 'SimpleSSLSocketServer' endpoints can instantiate Proxy objects. This issue represents a bypass of intended security restrictions, though no practical method for remote code execution or significant privilege escalation has been identified.
Recommendations Update to a version later than 1.5.33.

Exploit

Fix

LPE

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-WT54034
CVE-2026-10532
GHSA-JHQ6-GFMJ-V8FX
OPENSUSE-SU-2026:10999-1

Affected Products

Logback-Core