This is an automated email from the ASF dual-hosted git repository.
jbonofre pushed a commit to branch trunk
in repository https://gitbox.apache.org/repos/asf/karaf-site.git
The following commit(s) were added to refs/heads/trunk by this push:
new e6c98bd Publish CVE-2026-92230 advisory
e6c98bd is described below
commit e6c98bdee5611ccf53a6ef04b4e5c17c7aa683c1
Author: JB Onofré <[email protected]>
AuthorDate: Thu Sep 17 16:00:57 2026 +0200
Publish CVE-2026-92230 advisory
---
security/cve-2026-92230.txt | 43 +++++++++++++++++++++++++++++++++++++++++++
1 file changed, 43 insertions(+)
diff --git a/security/cve-2026-92230.txt b/security/cve-2026-92230.txt
new file mode 100644
index 0000000..48a37d6
--- /dev/null
+++ b/security/cve-2026-92230.txt
@@ -0,0 +1,43 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA256
+
+CVE-2026-92230: Apache Karaf: Improper release of ClassLoader references via
static ThreadLocal caching
+
+Severity: moderate
+
+Affected versions:
+
+- - Apache Karaf before 4.4.11
+
+Description:
+
+Apache Karaf's XmlUtils cached XML parser/transformer factories in static
ThreadLocal fields on long-lived container threads. Because a ThreadLocal value
outlives the OSGi bundle that created it, repeated bundle or feature install,
update, or refresh operations can leave successive bundle ClassLoader's pinned
in memory and unreachable for garbage collection, leading to unbounded
Metaspace growth and eventual denial of service of the Karaf instance.
+
+This issue is being tracked as https://github.com/apache/karaf/issues/2278
+
+Credit:
+
+Baoquan Cui & Yucheng Qiu (reporter)
+
+References:
+
+https://karaf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-92230
+https://issues.apache.org/jira/browse/https://github.com/apache/karaf/issues/2278
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmqr6nIbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52p40P/R3b/84TGGjSpBGLsQSJ
+V+jUn7PXGPkNx25f3osUYXhB0s1HaaQ9BNWiUMCEa0F8l8+NB8AMYoZFC1KGlDKD
+dTps6yEH5nSmcHwa46MguO/27V9W1KozEvsA0VZ9dcvTrT2Qv52KSWDZahPo79xS
+CyBKcncw846wTo02CPXFlVkDI/EmIYm2UXdIGY1HVGBAG6/C3XvfYY4+iCHP5CXL
+PiAU8b2oWl6kI7+7sRCMI6EW7M0vutLv6cznKNvK0xfCt29aHaMH6nMtAROmWzYp
+x8xdU3m9b/2WoeGDp2mHOx2W2hC2u3OrE1opswRIra8aiLhvLXiaLqlzxebhZn5r
+8tJyfovAo01brIF2p0Maocrd5t6rNFlTXVFdb+2pmU/a7qSSRxg/9CYL/kMCdeB1
+UNk+0gFNxCIQPLaEM8wR4T+m20tZ2AnQfCzT4ihxtqYCcxwIBsQ+S0QPdXSmmyCB
+vZGs6nK0qI117GHsVyG8d+Pf929256IU7AXMKu4PzPGDXQrZyBzOSV+/PiuMAaBK
+sk9tOhOqm/sEFw2c7/LaW1msy+K1RGjxTYWuD0KasvVrQY0nPt+ORUhlwC0GhoTs
+RcuR7B3QOYVu++ULiGMKWnJg86XM+OoCHRaMrQN1DieCNFgf/tmPqFBx7Q8weY1Z
+kcn3yO9M9UjYFzqs8pbQpjme
+=vee7
+-----END PGP SIGNATURE-----