PT-2026-95070 · Apache · Apache Karaf
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Karaf (affected versions not specified)
Description
The
XmlUtils component caches XML parser and transformer factories within static ThreadLocal fields on long-lived container threads. Since a ThreadLocal value persists longer than the OSGi bundle that created it, repeated operations such as installing, updating, or refreshing bundles and features can cause successive bundle ClassLoaders to remain pinned in memory. This prevents garbage collection, resulting in unbounded Metaspace growth and an eventual denial of service of the instance.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Memory Leak
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Karaf