PT-2026-4647 · Apache · Apache Karaf+1

·

CVE-2026-24656

·

Published

2026-01-25

·

Updated

2026-03-03

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Apache Karaf Decanter versions prior to 2.12.0
Description The Decanter log socket collector in Apache Karaf has a deserialization issue. The collector operates on port 4560 without authentication. If the allowed classes property is exposed, its configuration can be bypassed, leading to potential denial-of-service (DoS) conditions due to untrusted data deserialization. The Decanter log socket collector is not installed by default, meaning users who have not installed it are not affected.
Recommendations Upgrade to version 2.12.0 or later.

Exploit

Fix

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24656
GHSA-JMW5-58C7-587H

Affected Products

Apache Karaf
Decanter