{"id":"CVE-2026-10532","summary":"Logback deserialization whitelist bypass for Proxy objects","details":"Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.\n\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.33 inclusive.","aliases":["GHSA-jhq6-gfmj-v8fx"],"modified":"2026-07-15T01:49:17.372752492Z","published":"2026-06-01T11:30:47.894Z","related":["CGA-4pvr-4r9r-r9vh","openSUSE-SU-2026:10999-1"],"database_specific":{"cna_assigner":"NCSC.ch","cwe_ids":["CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10532.json"},"references":[{"type":"WEB","url":"https://logback.qos.ch/news.html#1.5.34"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10532.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10532"},{"type":"PACKAGE","url":"https://github.com/qos-ch/logback"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qos-ch/logback","events":[{"introduced":"0"},{"last_affected":"124e8b49b55ac34d08743a0646bd463410192647"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.5.33"}],"source":"AFFECTED_FIELD"}}],"versions":["v_1.5.33","v_1.5.32","v_1.5.31","v_1.5.30","v_1.5.29","v_1.5.28","v_1.5.27","v_1.5.26","v_1.5.25","v_1.5.24","v_1.5.23","v_1.5.22","v_1.5.21","v_1.5.20","v_1.5.19","v_1.5.18","v_1.5.17","v_1.5.16","v_1.5.15","v_1.5.14","v_1.5.13","v_1.5.12","v_1.5.11","v_1.5.10","v_1.5.9","v_1.5.8","v_1.5.7","v_1.5.6","v_1.5.5","v_1.5.4","v_1.5.3","v_1.5.1","v_1.5.0","v_1.4.14","v_1.4.13","v_4.1.12","v_1.4.12","v_1.4.11","v_1.4.10","v_1.4.9","v_1.4.8","v_1.4.7","v_1.4.6","v_1.4.5","v_1.4.4","v_1.4.3","v1.4.2","possible_mvn_issue","v_1.4.1","v_1.4.0","v_1.3.0-beta0","v_1.3.0-alpha16","v_1.3.0-alpha15","v_1.3.0-alpha14","v_1.3.0-alpha13","v_1.3.0-alpha12","v_1.3.0-alpha12-SNAPSHOT","v_1.3.0-alpha11","v_1.3.0-alpha10","v_1.3.0-alpha9","v_1.3.0-alpha8","v_1.3.0-alpha7","v_1.3.0-alpha6","v_1.3.0-alpha5","list","v_1.3.0-alpha4","v_1.3.0-alpha3","v_1.3.0-alpha2","v_1.8.0-alpha1","v_1.3.0-alpha0","v_1.2.2","v_1.1.10","v_1.2.1","v_1.2.0","v_1.1.8","v_1.1.7","v_1.1.6","v_1.1.5","v_1.1.4","v_1.1.1","v_1.1.0","v_1.0.11","v1.0.10","v_1.0.9","v_1.0.8","v_1.0.7","v_1.0.6","v_1.0.5","v_1.0.4","v_1.0.3","v_1.0.2","v_1.0.1","v_1.0.0","v_0.9.30","v_0.9.29","v_0.9.28","v_0.9.27","v_0.9.26","v_0.9.25","v_0.9.24","v_0.9.23","v_0.9.22","v_0.9.21","v0.9.20","release_0.9.19","v0.9.18"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10532.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:M/U:Green"}]}