| Summary | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to Although deserialization is heavily restricted by HardenedObjectInputStream and no This issue affects logback: through 1.5.32 inclusive. |
|---|---|
| Publication Date | May 28, 2026, 11:16 p.m. |
| Registration Date | May 29, 2026, 4:14 a.m. |
| Last Update | May 28, 2026, 11:16 p.m. |