Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Baoquan Cui

#39223of 57,645
7.5Total CVSS
Vulnerabilities · 1
PT-2026-95070
7.5
2026-09-17
Apache · Apache Karaf · CVE-2026-92230
**Name of the Vulnerable Software and Affected Versions** Apache Karaf (affected versions not specified) **Description** The `XmlUtils` component caches XML parser and transformer factories within static `ThreadLocal` fields on long-lived container threads. Since a `ThreadLocal` value persists longer than the OSGi bundle that created it, repeated operations such as installing, updating, or refreshing bundles and features can cause successive bundle ClassLoaders to remain pinned in memory. This prevents garbage collection, resulting in unbounded Metaspace growth and an eventual denial of service of the instance. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.