PT-2026-95070 · Apache · Apache Karaf

·

CVE-2026-92230

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Karaf (affected versions not specified)
Description The XmlUtils component caches XML parser and transformer factories within static ThreadLocal fields on long-lived container threads. Since a ThreadLocal value persists longer than the OSGi bundle that created it, repeated operations such as installing, updating, or refreshing bundles and features can cause successive bundle ClassLoaders to remain pinned in memory. This prevents garbage collection, resulting in unbounded Metaspace growth and an eventual denial of service of the instance.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Leak

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92230

Affected Products

Apache Karaf