Vulnerability Details CVE-2026-66256
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig.
This issue affects Apache Shindig: all versions.
Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 51.4%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2026-66256
-
cpe:2.3:a:apache:shindig:-
-
cpe:2.3:a:apache:shindig:1.0
-
cpe:2.3:a:apache:shindig:1.0.1
-
cpe:2.3:a:apache:shindig:1.1
-
cpe:2.3:a:apache:shindig:2.0.0
-
cpe:2.3:a:apache:shindig:2.0.1
-
cpe:2.3:a:apache:shindig:2.0.2
-
cpe:2.3:a:apache:shindig:2.5.0
-
cpe:2.3:a:apache:shindig:2.5.1
-
cpe:2.3:a:apache:shindig:2.5.2
-
cpe:2.3:a:apache:shindig:3.0.0