← Advisories

Apache Celix 2.4.0 EDEF XML Parser Heap-Based Buffer Overflow

High
Advisory ID
ZSL-2026-6015
Release Date
11 October 2026
Vendor
The Apache Software Foundation - https://www.apache.org
Affected Version
2.4.0
CVE
N/A
Tested On
Kali Linux, glibc 2.42-16
Summary

Apache Celix is an implementation of the OSGi specification adapted to C and C++. It is a framework to develop (dynamic) modular software applications using component and/or service-oriented programming.

Description

Apache Celix suffers from a heap-based buffer overflow vulnerability in its remote-services Endpoint Description Extender (EDEF) parser. Attacker-influenced endpoint-descriptor content is concatenated into a heap buffer without adequate bounds checking, corrupting adjacent heap memory. On deployments that use remote-services discovery, a crafted descriptor can crash the process or lead to code execution.

Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
18.08.2026Contact with the vendor.
19.08.2026Vendor forwards details to appropriate PMC.
26.08.2026Vendor confirms the issue and started investigating the affected versions, actual impact, and an appropriate minimal fix.
07.10.2026Asked vendor for status update.
10.10.2026Vendor: no updates yet.
11.10.2026Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
11.10.2026Initial release