Maven incidents

Recent Maven vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

HIGHMaven

Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

io.netty:netty-codec-http2: 4.2.0 → 4.2.16.Final

5 days agoEPSS 0%
HIGHMaven

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

5 days agoEPSS 0%
MODERATEMaven

core-geonetwork has an Open Redirect Bypass

core-geonetwork has an Open Redirect Bypass

org.geonetwork-opensource:geonetwork: ≥ 3.12.0

5 days agoEPSS 0%
HIGHMaven

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

io.quarkus:quarkus-vertx-http: before 3.20.6.2

1 week agoEPSS 0%
MODERATEMaven

veraPDF Parser DoS via PostScript Type 1 Font Programs

veraPDF Parser DoS via PostScript Type 1 Font Programs

org.verapdf:parser: before 1.30.2

1 week agoEPSS 0%
MEDIUMMaven

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

org.verapdf:validation-model: 1.17.35 → 1.30.2

1 week agoEPSS 0%
MODERATEMaven

veraPDF Parser DoS via PostScript CMap Streams

veraPDF Parser DoS via PostScript CMap Streams

org.verapdf:parser: before 1.30.2

1 week agoEPSS 0%
HIGHMaven

veraPDF Validation XXE via XFA

veraPDF Validation XXE via XFA

org.verapdf:validation-model: 1.17.35 → 1.30.2

1 week agoEPSS 0%
HIGHMaven

veraPDF Validation XXE via Rich Text

veraPDF Validation XXE via Rich Text

org.verapdf:validation-model: 1.25.73 → 1.30.2

1 week agoEPSS 0%
MEDIUMMaven

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.27.0

1 week agoEPSS 0%
HIGHMaven

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.28.0-alpha

1 week agoEPSS 0%
HIGHMaven

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

1 week agoEPSS 0%
CRITICALMaven

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

org.openidentityplatform.openam:openam-core: before 16.1.2

1 week ago
HIGHMaven

Netty: STOMP CONNECT Frame Header Injection in Netty

Netty: STOMP CONNECT Frame Header Injection in Netty

io.netty:netty-codec-stomp: 4.2.0.Final → 4.2.16.Final

2 weeks agoEPSS 0%
HIGHMaven

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.5

2 weeks agoEPSS 0%
HIGHMaven

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

com.fasterxml.jackson.core:jackson-core: before 2.18.8

2 weeks ago
HIGHMaven

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

com.arcadedb:arcadedb-engine: before 26.7.2

2 weeks agoEPSS 0%
HIGHMaven

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

com.arcadedb:arcadedb-server: before 26.7.2

2 weeks agoEPSS 0%
HIGHMaven

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

com.arcadedb:arcadedb-engine: before 26.7.2

2 weeks agoEPSS 1%
HIGHMaven

dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

com.datadoghq:dd-java-agent: before 1.62.0

3 weeks ago
CRITICALMaven

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.18.8

1 month agoEPSS 1%
HIGHMaven

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

io.netty:netty-codec-http3: 4.2.0.Final → 4.2.15.Final

1 month agoEPSS 0%
HIGHMaven

Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.15.Final

1 month agoEPSS 1%
MEDIUMMaven

netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

io.netty:netty-codec-http2: before 4.1.135.Final

1 month agoEPSS 1%
MEDIUMMaven

Spring Framework Denial of Service via Unbounded Cache in SpEL

Spring Framework Denial of Service via Unbounded Cache in SpEL

org.springframework:spring-expression: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Cross-site Scripting via JavaScriptUtils

Spring Framework Cross-site Scripting via JavaScriptUtils

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Algorithmic Denial of Service via SpEL Expressions

Spring Framework Algorithmic Denial of Service via SpEL Expressions

org.springframework:spring-expression: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Open Redirect in Spring MVC and WebFlux

Spring Framework Open Redirect in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Arbitrary Method Invocation in SpEL Expressions

Spring Framework Arbitrary Method Invocation in SpEL Expressions

org.springframework:spring-expression: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Cross-site Scripting via JSP Form Tags

Spring Framework Cross-site Scripting via JSP Form Tags

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring LDAP has Authentication Bypass with Empty Password

Spring LDAP has Authentication Bypass with Empty Password

org.springframework.ldap:spring-ldap-core: 4.0.0 → 4.0.4

1 month agoEPSS 0%
HIGHMaven

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Predictable Session ID in WebSocket Module

Spring Framework Predictable Session ID in WebSocket Module

org.springframework:spring-websocket: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Escalation via Session Fixation in WebFlux

Spring Framework Escalation via Session Fixation in WebFlux

org.springframework:spring-webflux: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

org.springframework:spring-expression: all versions

1 month agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Multipart Requests in WebFlux

Spring Framework Denial of Service via Multipart Requests in WebFlux

org.springframework:spring-webflux: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

org.springframework:spring-webflux: all versions

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Denial of Service via AntPathMatcher

Spring Framework Denial of Service via AntPathMatcher

org.springframework:spring-core: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4

1 month agoEPSS 0%
HIGHMaven

Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service

Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service

org.springframework.retry:spring-retry: 2.0.0 → 2.0.13

1 month agoEPSS 0%
MEDIUMMaven

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

io.projectreactor.netty:reactor-netty: 1.3.0 → 1.3.6

1 month agoEPSS 0%
HIGHMaven

Spring HATEOAS heap exhaustion through unbounded internal caching

Spring HATEOAS heap exhaustion through unbounded internal caching

org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4

1 month agoEPSS 0%
HIGHMaven

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final

1 month agoEPSS 0%
HIGHMaven

Netty has Insufficient Bailiwick Validation for NS Records

Netty has Insufficient Bailiwick Validation for NS Records

io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final

1 month agoEPSS 0%
CRITICALMaven

ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases

ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases

com.arcadedb:arcadedb-server: 21.10.1 → 26.4.2

3 months agoEPSS 0%
CRITICALMaven

OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution

OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution

io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.26.1

4 months agoEPSS 1%
MODERATEMaven

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

tools.jackson.core:jackson-core: 3.0.0 → 3.1.0

5 months ago
CRITICALMaven

jinjava has Sandbox Bypass via JavaType-Based Deserialization

jinjava has Sandbox Bypass via JavaType-Based Deserialization

com.hubspot.jinjava:jinjava: 2.8.0 → 2.8.1

10 months agoEPSS 2%
HIGHMaven

json-smart Uncontrolled Recursion vulnerability

json-smart Uncontrolled Recursion vulnerability

net.minidev:json-smart: before 2.4.9

3 years agoEPSS 1%

Tooling for Maven

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GohexNuGetPyPIRubyGemscrates.ionpm