CVE-2026-66256 PUBLISHED

Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)

Assigner: apache
Reserved: 24.07.2026 Published: 13.08.2026 Updated: 13.08.2026

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig.

This issue affects Apache Shindig: all versions.

Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Product Status

Vendor Apache Software Foundation
Product Apache Shindig Common
Versions Default: unaffected
  • affected from 0 to * (incl.)
Vendor Apache Software Foundation
Product Apache Shindig Social-Api
Versions Default: unaffected
  • affected from 0 to * (incl.)

Credits

  • Daryle Bourque, Horizon3.ai finder
  • Noah King, Horizon3.ai finder

References

Problem Types

  • CWE-502 Deserialization of Untrusted Data CWE