CVE-2026-66256

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://lists.apache.org/thread/opgpnhk149614gx6vcy3lvyjnycw8mkh Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/08/13/7 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:shindig:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-13 15:19

Updated : 2026-09-11 13:53


NVD link : CVE-2026-66256

Mitre link : CVE-2026-66256

CVE.ORG link : CVE-2026-66256


JSON object : View

Products Affected

apache

  • shindig
CWE
CWE-502

Deserialization of Untrusted Data