It's generated by cveprocess

On Thu, Sep 17, 2026 at 5:35 PM sebb <[email protected]> wrote:

> The Subject seems unnecessarily long ...
>
> If needed, the URL should be in the body of the email, not part of the
> subject
>
> Sebb
>
> On Thu, 17 Sept 2026 at 16:30, Jean-Baptiste Onofré <[email protected]>
> wrote:
> >
> > Severity: moderate
> >
> > Affected versions:
> >
> > - Apache Karaf before 4.4.11
> >
> > Description:
> >
> > Apache Karaf's XmlUtils cached XML parser/transformer factories in
> static ThreadLocal fields on long-lived container threads. Because a
> ThreadLocal value outlives the OSGi bundle that created it, repeated bundle
> or feature install, update, or refresh operations can leave successive
> bundle ClassLoader's pinned in memory and unreachable for garbage
> collection, leading to unbounded Metaspace growth and eventual denial of
> service of the Karaf instance.
> >
> > This issue is being tracked as
> https://github.com/apache/karaf/issues/2278
> >
> > Credit:
> >
> > Baoquan Cui & Yucheng Qiu (reporter)
> >
> > References:
> >
> > https://karaf.apache.org/
> > https://www.cve.org/CVERecord?id=CVE-2026-92230
> >
> https://issues.apache.org/jira/browse/https://github.com/apache/karaf/issues/2278
> >
>

Reply via email to