CVE-2026-91842 | OpenBankProject OBP-API up to 1.10.1 Kryo Redis.scala KryoInjection.invert deserialization (Issue 2888)
A vulnerability was found in OpenBankProject OBP-API up to 1.10.1 and classified as problematic. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2026-91842. The attack can be launched remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More