{"apiVersion":"1.0","identifier":"CVE-2026-66256","description":"** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","publishedAt":"2026-08-13T15:19:56","lastModifiedAt":"2026-08-14T19:04:48","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66256","cvssScore":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00522,"riskScore":0.75,"affectedProduct":"Apache Shindig","affectedVersions":"unknown","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-66256","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-66256","en":"https://www.redsauce.net/en/cves/CVE-2026-66256","fr":"https://www.redsauce.net/fr/cves/CVE-2026-66256","pt":"https://www.redsauce.net/pt/cves/CVE-2026-66256","de":"https://www.redsauce.net/de/cves/CVE-2026-66256","sk":"https://www.redsauce.net/sk/cves/CVE-2026-66256","el":"https://www.redsauce.net/el/cves/CVE-2026-66256"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-66256"}}