Deserialization Vulnerability in Apache Karaf Decanter Exposes Unauthorized Access
CVE-2026-24656
What is CVE-2026-24656?
A vulnerability exists in Apache Karaf Decanter due to the deserialization of untrusted data via the exposed log socket collector on port 4560 without authentication. This issue can lead to unauthorized access and may allow an attacker to manipulate data, potentially causing a Denial of Service (DoS). Note that the Decanter log socket collector is not installed by default, which means only users who have manually configured this collector may be affected. It is recommended for all users to upgrade to version 2.12.0 to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Karaf 0 < 2.12.0
Apache Karaf 2.12.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved