Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.ritense.valtimo/inbox
  4. ›
  5. CVE-2026-34164

CVE-2026-34164: Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService

April 16, 2026 (updated April 24, 2026)

The InboxHandlingService logs the full content of every incoming inbox message at INFO level (logger.info("Received message: {}", message)). Inbox messages are wrappers around outbox message data, which can contain highly sensitive information such as personal data (PII), citizen identifiers (BSN), and case details.

References

  • github.com/advisories/GHSA-hfrg-mcvw-8mch
  • github.com/generiekzaakafhandelcomponent/gzac-issues/issues/653
  • github.com/valtimo-platform/valtimo
  • github.com/valtimo-platform/valtimo/commit/f16a1940ba7b34627c0b966f98ca78655ace9335
  • github.com/valtimo-platform/valtimo/pull/497
  • github.com/valtimo-platform/valtimo/releases/tag/13.22.0
  • github.com/valtimo-platform/valtimo/security/advisories/GHSA-hfrg-mcvw-8mch
  • nvd.nist.gov/vuln/detail/CVE-2026-34164

Code Behaviors & Features

Detect and mitigate CVE-2026-34164 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 13.0.0.RELEASE before 13.22.0.RELEASE

Fixed versions

  • 13.22.0.RELEASE

Solution

Upgrade to version 13.22.0.RELEASE or above.

Impact 4.9 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-532: Insertion of Sensitive Information into Log File

Source file

maven/com.ritense.valtimo/inbox/CVE-2026-34164.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:20:19 +0000.