{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-9828", "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c", "state": "PUBLISHED", "assignerShortName": "NCSC.ch", "dateReserved": "2026-05-28T11:55:19.674Z", "datePublished": "2026-05-28T12:52:45.852Z", "dateUpdated": "2026-05-29T08:07:39.510Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "455daabc-a392-441d-aa46-37d35189897c", "shortName": "NCSC.ch", "dateUpdated": "2026-05-29T08:07:39.510Z" }, "title": "Logback deserialization whitelist bypass for java.lang and java.util", "datePublic": "2026-05-28T07:47:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-502", "description": "CWE-502 Deserialization of untrusted data", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-586", "descriptions": [ { "lang": "en", "value": "CAPEC-586 Object Injection" } ] } ], "affected": [ { "vendor": "QOS.CH Sarl", "product": "logback", "packageName": "logback-core", "repo": "https://github.com/qos-ch/logback", "modules": [ "HardenedObjectInputStream (logback-core)" ], "programFiles": [ "HardenedObjectInputStream.java" ], "versions": [ { "status": "affected", "version": "0", "lessThanOrEqual": "1.5.32", "versionType": "maven" }, { "status": "unaffected", "version": "1.5.33" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate objects from\n classes in the java.lang and java.util packages that are not explicitly\n blocked.\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.32 inclusive.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.

More precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate objects from\n classes in the java.lang and java.util packages that are not explicitly\n blocked.

Although deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.

This issue affects logback: through 1.5.32 inclusive.


" } ] } ], "references": [ { "url": "https://logback.qos.ch/news.html#1.5.33" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "HIGH", "attackRequirements": "PRESENT", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "subConfidentialityImpact": "LOW", "vulnIntegrityImpact": "LOW", "subIntegrityImpact": "LOW", "vulnAvailabilityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "PROOF_OF_CONCEPT", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "LOW", "providerUrgency": "GREEN", "version": "4.0", "baseSeverity": "LOW", "baseScore": 2.9, "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:L/U:Green" } } ], "configurations": [ { "lang": "en", "value": "SimpleSocketServer or SimpleSSLSockerServer must be running on the target host and reachable by the attacker.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "SimpleSocketServer or SimpleSSLSockerServer must be running on the target host and reachable by the attacker." } ] } ], "solutions": [ { "lang": "en", "value": "Upgrade to logback version 1.5.33.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Upgrade to logback version 1.5.33." } ] } ], "exploits": [ { "lang": "en", "value": "Given that HardenedObjectInputStream used by SimpleSocketServer and SimpleSSLSockerServer already heavily restricts the set of deserializable classes, it is unlikely that the attacker can escalate the vulnerability to gain control of the target host.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Given that HardenedObjectInputStream used by SimpleSocketServer and SimpleSSLSockerServer already heavily restricts the set of deserializable classes, it is unlikely that the attacker can escalate the vulnerability to gain control of the target host. " } ] } ], "credits": [ { "lang": "en", "value": "York Shen https://github.com/york-shen", "type": "finder" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 1.0.2" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-28T14:20:28.756230Z", "id": "CVE-2026-9828", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-28T14:20:37.401Z" } } ] } }