{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-14T00:17:21.923","vulnerabilities":[{"cve":{"id":"CVE-2026-24656","sourceIdentifier":"security@apache.org","published":"2026-01-26T10:16:09.597","lastModified":"2026-01-27T20:30:09.037","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.\n\n\nThe Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.\nIt means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS.\n\n\nNB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue.\n\nThis issue affects Apache Karaf Decanter before 2.12.0.\n\nUsers are recommended to upgrade to version 2.12.0, which fixes the issue."},{"lang":"es","value":"Vulnerabilidad de deserialización de datos no confiables en Apache Karaf Decanter.\n\nEl colector de socket de registro de Decanter expone el puerto 4560, sin autenticación. Si el colector expone la propiedad de clases permitidas, esta configuración puede ser eludida.\nEsto significa que el colector de socket de registro es vulnerable a la deserialización de datos no confiables, lo que eventualmente causa DoS.\n\nNB: El colector de socket de registro de Decanter no está instalado por defecto. Los usuarios que no han instalado el socket de registro de Decanter no se ven afectados por este problema.\n\nEste problema afecta a Apache Karaf Decanter anterior a la versión 2.12.0.\n\nSe recomienda a los usuarios actualizar a la versión 2.12.0, que corrige el problema."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:karaf_decanter:*:*:*:*:*:*:*:*","versionEndExcluding":"2.12.0","matchCriteriaId":"8AC91F7D-EA3C-4D8A-95D2-BCA9902B744C"}]}]}],"references":[{"url":"https://lists.apache.org/thread/dc5wmdn6hyc992olntkl75kk04ndzx34","source":"security@apache.org","tags":["Mailing List"]},{"url":"http://www.openwall.com/lists/oss-security/2026/01/24/1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]}]}}]}