GHSA-h8w2-rv57-vc6f
CRITICALIn versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. An attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability:
- Affected
- < 2.26.1
- Fixed in
- 2.26.1
- Weakness
- CWE-502
- Published
- 2026-03-26
- Source
- github