← Advisories

Apache Commons JCS 3.2.1 Unauthenticated Java Deserialization

High
Advisory ID
ZSL-2026-6008
Release Date
06 October 2026
Vendor
The Apache Software Foundation - https://www.apache.org
Affected Version
3.2.1
CVE
N/A
Tested On
Microsoft Windows 10 (x86_64), Eclipse Temurin OpenJDK 21.0.6 (LTS)
Summary

JCS is a distributed caching system written in Java. It is intended to speed up applications by providing a means to manage cached data of various dynamic natures. Like any caching system, JCS is most useful for high read, low put applications. Latency times drop sharply and bottlenecks move away from the database in an effectively cached system.

Description

Apache Commons JCS suffers from an unauthenticated Java deserialization vulnerability on its TCP Lateral Cache. The lateral listener deserializes incoming objects through an ObjectInputStream guarded only by a three-prefix class denylist, which is bypassable with widely available gadgets, so a remote attacker who can reach the lateral port can send a crafted object and execute code. On deployments that enable the TCP lateral cache this is unauthenticated remote code execution.

Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
19.08.2026Contact with the vendor.
20.08.2026Vendor forwards details to appropriate PMC.
05.10.2026No response from the vendor.
06.10.2026Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
06.10.2026Initial release