Executive brief
Apache Karaf is an open-source OSGi container used to build enterprise applications and middleware. A defect in how the system caches XML processing factories causes ClassLoader references to persist in memory even after bundles are removed, leading to unbounded memory growth in the Metaspace region and eventual server unavailability without restart.
Technical details
The vulnerability exists in Apache Karaf's XmlUtils class, which caches XML parser and transformer factories in static ThreadLocal fields. These ThreadLocal values persist on long-lived container threads and are never released, even after the OSGi bundle that created them is unloaded. Repeated bundle install, update, or refresh operations leave successive ClassLoader references pinned in memory and unreachable for garbage collection, causing unbounded Metaspace growth. The attack vector is local/administrative—only operators who can trigger bundle operations are affected. An attacker with bundle management privileges can exhaust Metaspace, leading to a denial of service condition. Patches are available in Apache Karaf 4.4.11 and later.
Affected products
- Apache Karaf before 4.4.11
Timeline
- 2026-09-17: disclosed
- 2026-09-17: advisory