Apache · Apache Karaf · CVE-2026-92230
**Name of the Vulnerable Software and Affected Versions**
Apache Karaf (affected versions not specified)
**Description**
The `XmlUtils` component caches XML parser and transformer factories within static `ThreadLocal` fields on long-lived container threads. Since a `ThreadLocal` value persists longer than the OSGi bundle that created it, repeated operations such as installing, updating, or refreshing bundles and features can cause successive bundle ClassLoaders to remain pinned in memory. This prevents garbage collection, resulting in unbounded Metaspace growth and an eventual denial of service of the instance.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.