Description
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig.

This issue affects Apache Shindig: all versions.

Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-08-13
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a deserialization of untrusted data flaw that allows attackers to execute arbitrary code on the host running Apache Shindig. An attacker who can send crafted requests to the Shindig REST API can trigger the flaw, resulting in full compromise of the server’s confidentiality, integrity, and availability.

Affected Systems

All releases of Apache Shindig Common and Apache Shindig Social-Api are affected. The project has been retired and no future fixes will be released.

Risk and Exploitability

The vulnerability can be exploited by any authenticated or unauthenticated user with access to the OpenSocial REST API, but the description does not specify additional prerequisites. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Given the lack of a patch and the nature of remote code execution, the risk remains high and attackers can rely on this flaw without restrictions. The CVSS score is 7.2, indicating high severity.

Generated by OpenCVE AI on August 13, 2026 at 17:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Migrate from Apache Shindig to a supported, actively maintained solution that meets the same needs.
  • Configure network and application-level controls to restrict the Shindig REST API to trusted users only, such as authentication or IP filtering.
  • Disable the Shindig REST API or remove the service if it is not required for business functions.

Generated by OpenCVE AI on August 13, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache shindig
Vendors & Products Apache
Apache shindig

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
References

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Title Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)
Weaknesses CWE-502
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-13T16:18:21.390Z

Reserved: 2026-07-24T09:55:56.665Z

Link: CVE-2026-66256

cve-icon Vulnrichment

Updated: 2026-08-13T16:18:21.390Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T15:19:56.557

Modified: 2026-08-14T19:04:48.700

Link: CVE-2026-66256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:14:56Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data