CVE-2026-10532
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.
More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.
Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions.
This issue affects logback: through 1.5.33 inclusive.
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green
- Base score: 2.9
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.37%
- Percentile among all scored CVEs: 29
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-502
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-10532",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-10532",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-01T13:56:13.272183Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "vulnerability@ncsc.ch",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 2.9,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green",
"exploitMaturity": "PROOF_OF_CONCEPT",
"providerUrgency": "GREEN",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "MODERATE",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "vulnerability@ncsc.ch",
"affectedData": [
{
"repo": "https://github.com/qos-ch/logback",
"vendor": "QOS.CH Sarl",
"modules": [
"HardenedObjectInputStream (logback-core)"
],
"product": "logback",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "maven",
"lessThanOrEqual": "1.5.33"
},
{
"status": "unaffected",
"version": "1.5.34"
}
],
"packageName": "logback-core",
"programFiles": [
"HardenedObjectInputStream.java"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-01T13:16:30.340",
"references": [
{
"url": "https://logback.qos.ch/news.html#1.5.34",
"source": "vulnerability@ncsc.ch"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "vulnerability@ncsc.ch",
"description": [
{
"lang": "en",
"value": "CWE-502"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.\n\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.33 inclusive."
},
{
"lang": "es",
"value": "Vulnerabilidad de deserialización de datos no confiables en QOS.CH Sarl logback logback-core (módulos HardenedObjectInputStream (logback-core)) permite la inyección de objetos, aunque muy restringida.\n\nMás precisamente, un atacante capaz de influir en los datos serializados enviados a SimpleSocketServer o SimpleSSLSocketServer puede instanciar objetos Proxy.\n\nAunque la deserialización está muy restringida por HardenedObjectInputStream y no se ha identificado ninguna forma práctica de lograr la ejecución remota de código o una escalada significativa de privilegios, este problema constituye un bypass de las restricciones de seguridad previstas.\n\nEste problema afecta a logback: hasta la versión 1.5.33 inclusive."
}
],
"lastModified": "2026-07-22T07:10:00.107",
"sourceIdentifier": "vulnerability@ncsc.ch"
}