It's generated by cveprocess On Thu, Sep 17, 2026 at 5:35 PM sebb <[email protected]> wrote:
> The Subject seems unnecessarily long ... > > If needed, the URL should be in the body of the email, not part of the > subject > > Sebb > > On Thu, 17 Sept 2026 at 16:30, Jean-Baptiste Onofré <[email protected]> > wrote: > > > > Severity: moderate > > > > Affected versions: > > > > - Apache Karaf before 4.4.11 > > > > Description: > > > > Apache Karaf's XmlUtils cached XML parser/transformer factories in > static ThreadLocal fields on long-lived container threads. Because a > ThreadLocal value outlives the OSGi bundle that created it, repeated bundle > or feature install, update, or refresh operations can leave successive > bundle ClassLoader's pinned in memory and unreachable for garbage > collection, leading to unbounded Metaspace growth and eventual denial of > service of the Karaf instance. > > > > This issue is being tracked as > https://github.com/apache/karaf/issues/2278 > > > > Credit: > > > > Baoquan Cui & Yucheng Qiu (reporter) > > > > References: > > > > https://karaf.apache.org/ > > https://www.cve.org/CVERecord?id=CVE-2026-92230 > > > https://issues.apache.org/jira/browse/https://github.com/apache/karaf/issues/2278 > > >
