PT-2026-4647 · Apache · Apache Karaf+1

R00T4Dm

·

Published

2026-01-25

·

Updated

2026-03-03

·

CVE-2026-24656

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Apache Karaf Decanter versions prior to 2.12.0
Description The Decanter log socket collector in Apache Karaf has a deserialization issue. The collector operates on port 4560 without authentication. If the allowed classes property is exposed, its configuration can be bypassed, leading to potential denial-of-service (DoS) conditions due to untrusted data deserialization. The Decanter log socket collector is not installed by default, meaning users who have not installed it are not affected.
Recommendations Upgrade to version 2.12.0 or later.

Fix

DoS

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-24656
GHSA-JMW5-58C7-587H

Affected Products

Apache Karaf
Decanter