Documentation
Examples
You are looking for some examples to learn how to implement bundle for Apache Karaf ? There is some usefull examples include in the source code, you can also browse and view documentation on the github of the projet.
If you are looking for examples that are missing here or you want to share your example with the community, please contact us on the mailing list and we will add it with pleasure.
Security Advisories
CVE-2014-0219 : Apache Karaf enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.
Notes »CVE-2016-8750 : Apache Karaf's LDAPLoginModule is vulnerable to LDAP injection.
Notes »CVE-2018-11786 : Enforce SSH permission based on RBAC.
Notes »CVE-2018-11787 : Unsecure access to Gogo shell in the webconsole.
Notes »CVE-2018-11788 : XXE vulnerability found on Apache Karaf.
Notes »CVE-2019-0191: Zip-slip vulnerability in KAR deployer.
Notes »CVE-2019-0226: Arbitrary file write vulnerability in Config service.
Notes »CVE-2020-11980: A remote client could create MBeans from arbitrary URLs.
Notes »CVE-2021-41766: Insecure Java Deserialization.
Notes »CVE-2022-22932: Path traversal flaws
Notes »CVE-2022-40145: JDBC JAAS LDAP injection
Notes »CVE-2024-34365: Cave SSRF and arbitrary file access
Notes »CVE-2026-24656: Decanter log socket collector: Deserialization of Untrusted Data
Notes »CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP login modules
Notes »CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
Notes »CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation
Notes »CVE-2026-91048: Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
Notes »CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
Notes »CVE-2026-92142: Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
Notes »CVE-2026-92230: Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching
Notes »