Description
Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.


The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.
It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS.


NB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue.

This issue affects Apache Karaf Decanter before 2.12.0.

Users are recommended to upgrade to version 2.12.0, which fixes the issue.
Published: 2026-01-26
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Deserialization of Untrusted Data leading to Denial of Service
Action: Upgrade
AI Analysis

Impact

The vulnerability stems from the Deserialization of Untrusted Data in the Decanter log socket collector of Apache Karaf. When an unauthenticated client connects to the exposed port 4560 and sends malicious payloads, the collector processes them without proper validation, potentially triggering DoS conditions. This weakness is classified as CWE‑502, encompassing insecure deserialization threats.

Affected Systems

The issue affects Apache Karaf Decanter versions prior to 2.12.0. The log socket collector is not installed by default; therefore, only deployments that have installed Decanter and left the collector enabled are impacted. The unprotected port 4560 serves as the attack surface.

Risk and Exploitability

The CVSS score of 3.7 indicates a low overall severity, and the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not currently listed in the CISA KEV catalog. An attacker can exploit the flaw by sending crafted serialized objects to the collector; if the configuration exposes allowed classes, authentication bypass may occur, leading to service disruption.

Generated by OpenCVE AI on April 18, 2026 at 02:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Karaf Decanter to version 2.12.0 or newer.
  • Remove or disable the Decanter log socket collector if it is not required.
  • Restrict network access to port 4560 using firewall rules or network segmentation.

Generated by OpenCVE AI on April 18, 2026 at 02:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jmw5-58c7-587h Apache Karaf Decanter has Deserialization of Untrusted Data in its Log Socket Collector
History

Tue, 27 Jan 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache karaf Decanter
CPEs cpe:2.3:a:apache:karaf_decanter:*:*:*:*:*:*:*:*
Vendors & Products Apache karaf Decanter

Tue, 27 Jan 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache karaf
Vendors & Products Apache
Apache karaf

Mon, 26 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Mon, 26 Jan 2026 10:30:00 +0000

Type Values Removed Values Added
References

Mon, 26 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS. NB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue. This issue affects Apache Karaf Decanter before 2.12.0. Users are recommended to upgrade to version 2.12.0, which fixes the issue.
Title Apache Karaf: Decanter log-socket collector has deserialization vulnerability
Weaknesses CWE-502
References

Subscriptions

Apache Karaf Karaf Decanter
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-01-26T18:35:51.514Z

Reserved: 2026-01-23T17:55:14.286Z

Link: CVE-2026-24656

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-01-26T10:16:09.597

Modified: 2026-01-27T20:30:09.037

Link: CVE-2026-24656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T02:45:27Z

Weaknesses