---
id: CVE-2026-66256
title: >-
  ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data
  vulnerability in Apache Shindig.


  This issue affects Apache Shindig: all versions.


  Users with access to the Shindig REST API can send specially-crafted requests
  to trigge…
summary: >-
  ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data
  vulnerability in Apache Shindig.


  This issue affects Apache Shindig: all versions.


  Users with access to the Shindig REST API can send specially-crafted requests
  to trigge…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: apache
product: shindig
affected:
  - shindig <= 3.0.0
published: '2026-08-13'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T13:53:49.327'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66256'
references:
  - url: 'https://lists.apache.org/thread/opgpnhk149614gx6vcy3lvyjnycw8mkh'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/08/13/7'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-13T15:53:08.626107Z'
ingestedAt: '2026-09-13T16:08:42.541Z'
epss: 0.00935
epssPercentile: 0.59128
---

## Overview

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig.

This issue affects Apache Shindig: all versions.

Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

## Affected

- `shindig <= 3.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
