Maven incidents
Recent Maven vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
io.netty:netty-codec-http2: 4.2.0 → 4.2.16.Final
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
core-geonetwork has an Open Redirect Bypass
core-geonetwork has an Open Redirect Bypass
org.geonetwork-opensource:geonetwork: ≥ 3.12.0
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
io.quarkus:quarkus-vertx-http: before 3.20.6.2
veraPDF Parser DoS via PostScript Type 1 Font Programs
veraPDF Parser DoS via PostScript Type 1 Font Programs
org.verapdf:parser: before 1.30.2
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
org.verapdf:validation-model: 1.17.35 → 1.30.2
veraPDF Parser DoS via PostScript CMap Streams
veraPDF Parser DoS via PostScript CMap Streams
org.verapdf:parser: before 1.30.2
veraPDF Validation XXE via XFA
veraPDF Validation XXE via XFA
org.verapdf:validation-model: 1.17.35 → 1.30.2
veraPDF Validation XXE via Rich Text
veraPDF Validation XXE via Rich Text
org.verapdf:validation-model: 1.25.73 → 1.30.2
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.27.0
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.28.0-alpha
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
org.openidentityplatform.openam:openam-core: before 16.1.2
Netty: STOMP CONNECT Frame Header Injection in Netty
Netty: STOMP CONNECT Frame Header Injection in Netty
io.netty:netty-codec-stomp: 4.2.0.Final → 4.2.16.Final
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.5
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
com.fasterxml.jackson.core:jackson-core: before 2.18.8
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
com.arcadedb:arcadedb-engine: before 26.7.2
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
com.arcadedb:arcadedb-server: before 26.7.2
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
com.arcadedb:arcadedb-engine: before 26.7.2
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
com.datadoghq:dd-java-agent: before 1.62.0
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.18.8
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
io.netty:netty-codec-http3: 4.2.0.Final → 4.2.15.Final
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.15.Final
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
io.netty:netty-codec-http2: before 4.1.135.Final
Spring Framework Denial of Service via Unbounded Cache in SpEL
Spring Framework Denial of Service via Unbounded Cache in SpEL
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Cross-site Scripting via JavaScriptUtils
Spring Framework Cross-site Scripting via JavaScriptUtils
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Spring Framework Algorithmic Denial of Service via SpEL Expressions
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Open Redirect in Spring MVC and WebFlux
Spring Framework Open Redirect in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Arbitrary Method Invocation in SpEL Expressions
Spring Framework Arbitrary Method Invocation in SpEL Expressions
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Cross-site Scripting via JSP Form Tags
Spring Framework Cross-site Scripting via JSP Form Tags
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring LDAP has Authentication Bypass with Empty Password
Spring LDAP has Authentication Bypass with Empty Password
org.springframework.ldap:spring-ldap-core: 4.0.0 → 4.0.4
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Predictable Session ID in WebSocket Module
Spring Framework Predictable Session ID in WebSocket Module
org.springframework:spring-websocket: 7.0.0 → 7.0.8
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Escalation via Session Fixation in WebFlux
Spring Framework Escalation via Session Fixation in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
org.springframework:spring-expression: all versions
Spring Framework Denial of Service via Multipart Requests in WebFlux
Spring Framework Denial of Service via Multipart Requests in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.8
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
org.springframework:spring-webflux: all versions
Spring Framework Denial of Service via AntPathMatcher
Spring Framework Denial of Service via AntPathMatcher
org.springframework:spring-core: 7.0.0 → 7.0.8
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
org.springframework.retry:spring-retry: 2.0.0 → 2.0.13
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
io.projectreactor.netty:reactor-netty: 1.3.0 → 1.3.6
Spring HATEOAS heap exhaustion through unbounded internal caching
Spring HATEOAS heap exhaustion through unbounded internal caching
org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final
Netty has Insufficient Bailiwick Validation for NS Records
Netty has Insufficient Bailiwick Validation for NS Records
io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
com.arcadedb:arcadedb-server: 21.10.1 → 26.4.2
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.26.1
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
tools.jackson.core:jackson-core: 3.0.0 → 3.1.0
jinjava has Sandbox Bypass via JavaType-Based Deserialization
jinjava has Sandbox Bypass via JavaType-Based Deserialization
com.hubspot.jinjava:jinjava: 2.8.0 → 2.8.1
json-smart Uncontrolled Recursion vulnerability
json-smart Uncontrolled Recursion vulnerability
net.minidev:json-smart: before 2.4.9
Tooling for Maven
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.