Impact
Apache Karaf’s XmlUtils stores XML parser and transformer factories in static ThreadLocal fields on non‑terminating container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, successive bundle or feature install, update, or refresh operations can accumulate ClassLoader references that remain pinned and unreachable for garbage collection. This leak grows the JVM Metaspace without bound, eventually exhausting resources and causing the Karaf instance to become unavailable. The vulnerability is a resource leakage (CWE‑401) and improper release of class loader references (CWE‑772).
Affected Systems
Apache Software Foundation’s Apache Karaf product is affected. No specific release or patch level is listed in the advisory; any version that contains the static ThreadLocal caching of XmlUtils may be vulnerable.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high impact for a successful exploitation. The EPSS score of less than 1% suggests a very low probability that this issue will be actively exploited in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack path requires the ability to install or update bundles or features in a running Karaf container, so privileged users or attackers who can gain such access to the Karaf management interface can repeatedly trigger the memory leak leading to a denial of service.
OpenCVE Enrichment