HomeApacheCVE-2026-24656

CVE-2026-24656

LOW
3.7CVSS
Published: 2026-01-26
Updated: 2026-01-27
AI Analysis

Description

Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS. NB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue. This issue affects Apache Karaf Decanter before 2.12.0. Users are recommended to upgrade to version 2.12.0, which fixes the issue.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
network
Complexity
high
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
none
Availability
low
Weaknesses
CWE-502

Metadata

Primary Vendor
APACHE
Published
1/26/2026
Last Modified
1/27/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

apache : karaf_decanter

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2026-24656 | LOW Severity | CVEDatabase.com | CVEDatabase.com