CVE-2026-9828: CWE-502 Deserialization of untrusted data in QOS.CH Sarl logback
CVE-2026-9828 is a low-severity deserialization vulnerability in QOS.CH Sarl's logback-core module affecting versions prior to 1.5.33. It involves the HardenedObjectInputStream component, where an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate certain java.lang and java.util objects that are not explicitly blocked. Despite this, the deserialization restrictions are strong, and no practical remote code execution or significant privilege escalation has been identified.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-9828) affects the logback-core module of QOS.CH Sarl's logback library, specifically in the HardenedObjectInputStream class. An attacker who can control serialized data sent to the SimpleSocketServer or SimpleSSLSocketServer may instantiate some objects from java.lang and java.util packages that are not explicitly blocked by the deserialization restrictions. However, these restrictions are robust, and no confirmed remote code execution or major privilege escalation has been demonstrated. The vulnerability impacts all logback versions up to and including 1.5.32.
Potential Impact
The impact is limited due to strong deserialization restrictions. While an attacker can instantiate certain objects during deserialization, no practical remote code execution or significant privilege escalation has been identified. The CVSS score of 2.9 reflects the low severity and limited impact of this vulnerability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation has been documented at this time. Users should monitor vendor communications for updates regarding patches or recommended mitigations.
CVE-2026-9828: CWE-502 Deserialization of untrusted data in QOS.CH Sarl logback
Description
CVE-2026-9828 is a low-severity deserialization vulnerability in QOS.CH Sarl's logback-core module affecting versions prior to 1.5.33. It involves the HardenedObjectInputStream component, where an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate certain java.lang and java.util objects that are not explicitly blocked. Despite this, the deserialization restrictions are strong, and no practical remote code execution or significant privilege escalation has been identified.
CVSS v4.0
Score 2.9low
Affected software
pkg:maven/ch.qos.logback/logback-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-9828) affects the logback-core module of QOS.CH Sarl's logback library, specifically in the HardenedObjectInputStream class. An attacker who can control serialized data sent to the SimpleSocketServer or SimpleSSLSocketServer may instantiate some objects from java.lang and java.util packages that are not explicitly blocked by the deserialization restrictions. However, these restrictions are robust, and no confirmed remote code execution or major privilege escalation has been demonstrated. The vulnerability impacts all logback versions up to and including 1.5.32.
Potential Impact
The impact is limited due to strong deserialization restrictions. While an attacker can instantiate certain objects during deserialization, no practical remote code execution or significant privilege escalation has been identified. The CVSS score of 2.9 reflects the low severity and limited impact of this vulnerability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation has been documented at this time. Users should monitor vendor communications for updates regarding patches or recommended mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- NCSC.ch
- Date Reserved
- 2026-05-28T11:55:19.674Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a184ec2e29bf47b50f3f931
Added to database: 05/28/2026, 14:18:42 UTC
Last enriched: 07/02/2026, 23:25:41 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.