Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to deserialization. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserialization | |
| First Time appeared |
Openbankproject
Openbankproject obp-api |
|
| Weaknesses | CWE-20 CWE-502 |
|
| CPEs | cpe:2.3:a:openbankproject:obp-api:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openbankproject
Openbankproject obp-api |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-15T15:48:10.869Z
Reserved: 2026-09-15T08:29:14.348Z
Link: CVE-2026-91842
Updated: 2026-09-15T15:48:08.065Z
Status : Received
Published: 2026-09-15T15:17:33.120
Modified: 2026-09-15T16:17:42.280
Link: CVE-2026-91842
No data.
OpenCVE Enrichment
No data.
