No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to deserialization. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserialization | |
| First Time appeared |
Openbankproject
Openbankproject obp-api |
|
| Weaknesses | CWE-20 CWE-502 |
|
| CPEs | cpe:2.3:a:openbankproject:obp-api:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openbankproject
Openbankproject obp-api |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-15T15:48:10.869Z
Reserved: 2026-09-15T08:29:14.348Z
Link: CVE-2026-91842
Updated: 2026-09-15T15:48:08.065Z
Status : Received
Published: 2026-09-15T15:17:33.120
Modified: 2026-09-15T16:17:42.280
Link: CVE-2026-91842
No data.
OpenCVE Enrichment
No data.