[
https://issues.apache.org/jira/browse/KAFKA-20945?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Krishna Chidrawar resolved KAFKA-20945.
---------------------------------------
Resolution: Invalid
> [CVE-2026-9828] , [ CVE-2026-10532] [logback-core] [1.5.25]
> ------------------------------------------------------------
>
> Key: KAFKA-20945
> URL: https://issues.apache.org/jira/browse/KAFKA-20945
> Project: Kafka
> Issue Type: Bug
> Reporter: Krishna Chidrawar
> Priority: Major
>
> *Aqua Description :* Deserialization of untrusted data vulnerability in
> QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core)
> modules) allows Object Injection albeit heavily restricted.
> More precisely, an attacker able to influence serialized data sent to
> SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from
> classes in the java.lang and java.util packages that are not explicitly
> blocked.
> Although deserialization is heavily restricted by HardenedObjectInputStream
> and no
> practical way to achieve remote code execution or significant privilege
> escalation has been identified, this issue constitutes a bypass of the
> intended security restrictions.
> This issue affects logback: through 1.5.32 inclusive.
> *NVD URL :* [https://nvd.nist.gov/vuln/detail/CVE-2026-9828]
> *Aqua Description :* Deserialization of untrusted data vulnerability in
> QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core)
> modules) allows Object Injection, albeit heavily restricted.
> More precisely, an attacker able to influence serialized data sent to
> SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.
> Although deserialization is heavily restricted by HardenedObjectInputStream
> and no
> practical way to achieve remote code execution or significant privilege
> escalation has been identified, this issue constitutes a bypass of the
> intended security restrictions.
> This issue affects logback: through 1.5.33 inclusive.
> *Vendor Statement :* null
> *Vendor URL :* null
> *NVD URL :* [https://nvd.nist.gov/vuln/detail/CVE-2026-10532]
> *Fix Version :* 1.5.35
--
This message was sent by Atlassian Jira
(v8.20.10#820010)