CVE-2026-24656 is a deserialization of untrusted data vulnerability affecting Apache Karaf Decanter versions prior to 2.12.0, specifically within the Decanter log socket collector. This flaw allows an unauthenticated attacker to potentially cause a Denial of Service (DoS) by sending specially crafted data to the exposed port 4560. While the CVSS score is low (3.7), indicating a low impact, the attack complexity is high. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.12.0CPE matchmatch criteria | cpe:2.3:a:apache:karaf_decanter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Karaf Decanter has Deserialization of Untrusted Data in its Log Socket Collector
Jan 26, 2026https://karaf.apache.org/security/cve-2026-24656.txt: CVE-2026-24656: Apache Karaf: Decanter log-socket collector has deserialization vulnerability
Jan 24, 2026