Junglewise Threat Intelligence

CVE-2026-10532: QOS.CH Sarl logback-core restricted deserialization in HardenedObjectInputStream

CVE-2026-10532 · Severity: medium · CVSS 4 · Published 2026-06-01

Technologies: ch.qos.logback:logback-core (Maven), QOS.CH Sarl Logback-Core. Vendors: Maven, QOS.CH Sarl.

Executive brief

Logback is a popular logging framework used by Java applications to record system events. A vulnerability in its socket-based logging servers could allow an attacker to bypass security restrictions by sending specially crafted data. While the risk of full system takeover is considered low, it allows for unauthorized object creation within the application's memory.

Technical details

A deserialization of untrusted data vulnerability exists in the HardenedObjectInputStream module of logback-core. An attacker who can influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can bypass intended security restrictions to instantiate Proxy objects. While the HardenedObjectInputStream heavily restricts deserialization, this bypass allows for limited object injection. No practical remote code execution (RCE) or significant privilege escalation gadgets have been identified at this time. The issue is addressed in version 1.5.34 by explicitly throwing an InvalidClassException when attempting to deserialize Proxy classes.

Affected products

  • QOS.CH Sarl logback-core <= 1.5.33

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory
  • 2026-06-01: patched: Fixed in version 1.5.34

References

Related threats