| Summary | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to Although deserialization is heavily restricted by HardenedObjectInputStream and no This issue affects logback: through 1.5.33 inclusive. |
|---|---|
| Publication Date | June 1, 2026, 10:16 p.m. |
| Registration Date | June 2, 2026, 4:17 a.m. |
| Last Update | June 2, 2026, 3:16 a.m. |