Description
A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to deserialization. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Deserialization
Action: Patch
AI Analysis

Impact

A deserialization flaw exists in the Kryo Injection component of the OBP-API, specifically the KryoInjection.invert method within Redis.scala. The vulnerability allows an attacker to externally supply crafted data that is processed by the deserialization routine, potentially leading to unintended effects or corruption of cached content. The flaw carries a CVSS score of 2.1, indicating a low innate severity from a purely technical standpoint, yet the exposure to malicious payloads introduces a notable risk in the context of untrusted input handling.

Affected Systems

OpenBankProject’s OBP-API, versions up to and including 1.10.1. The vulnerability resides in the Kryo Handler component, with the KryoInjection.invert method of the Redis module being the attack surface. Users running any version of the API prior to the latest patch are exposed to this flaw.

Risk and Exploitability

The attack can be launched remotely and requires a high level of complexity; exploitation is described as difficult. The EPSS score is below 1% and the issue is not listed in CISA’s KEV catalog, which together indicate a low probability of widespread abuse. Nonetheless, because the flaw permits deserialization of externally supplied data, a sufficiently skilled adversary with network access to the API could craft malicious input. This could lead to undesired behavior such as corruption of cached data or other impact tied to the logic that handles deserialized objects. The low CVSS base combined with the high complexity of exploitation limits the likelihood of widespread attacks but does not eliminate the need for mitigation.

Generated by OpenCVE AI on September 20, 2026 at 16:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest OBP‑API release or any vendor‑issued security update that addresses the Kryo deserialization bug.
  • If a patch is not yet available, reconfigure the API or Redis to reject or filter incoming serialized data, effectively disabling Kryo injection for remote traffic.
  • Restrict network exposure of the OBP‑API by placing it behind a firewall or VPN and limiting access to trusted hosts only.

Generated by OpenCVE AI on September 20, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to deserialization. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserialization
First Time appeared Openbankproject
Openbankproject obp-api
Weaknesses CWE-20
CWE-502
CPEs cpe:2.3:a:openbankproject:obp-api:*:*:*:*:*:*:*:*
Vendors & Products Openbankproject
Openbankproject obp-api
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:N/AC:H/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Openbankproject Obp-api
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T15:48:10.869Z

Reserved: 2026-09-15T08:29:14.348Z

Link: CVE-2026-91842

cve-icon Vulnrichment

Updated: 2026-09-15T15:48:08.065Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:33.120

Modified: 2026-09-16T17:53:40.500

Link: CVE-2026-91842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-502

    Deserialization of Untrusted Data