Deserialization of Untrusted Data in JFrog Artifactory - CVE-2026-65617
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to affect confidentiality, integrity, and availability.
The vulnerability exists due to deserialization of untrusted data in the package-handling component when processing package data. A remote user can submit specially crafted serialized package content to affect confidentiality, integrity, and availability.