CVE-2026-9828
Received Received - Intake
Deserialization Bypass in logback-core

Publication date: 2026-05-28

Last updated on: 2026-05-28

Assigner: Switzerland Government Common Vulnerability Program

Description
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from classes in the java.lang and java.util packages that are not explicitly blocked. Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions. This issue affects logback: through 1.5.32 inclusive.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-28
Last Modified
2026-05-28
Generated
2026-05-28
AI Q&A
2026-05-28
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
qos.ch logback to 1.5.32 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a deserialization of untrusted data issue in the QOS.CH Sarl logback logback-core module, specifically in the HardenedObjectInputStream component.

An attacker who can influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from certain classes in the java.lang and java.util packages that are not explicitly blocked.

Although the deserialization process is heavily restricted and no practical way to achieve remote code execution or significant privilege escalation has been identified, this vulnerability bypasses the intended security restrictions.


How can this vulnerability impact me? :

This vulnerability allows an attacker to bypass security restrictions by instantiating certain objects during deserialization.

However, since the deserialization is heavily restricted and no practical remote code execution or significant privilege escalation has been identified, the impact is limited.

The overall risk is low, as reflected by the CVSS base score of 1.2.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart