Maven incidents
Recent Maven vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover
Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover
com.linecorp.centraldogma:centraldogma-server: before 0.84.0
Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)
Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)
com.linecorp.centraldogma:centraldogma-server-mirror-git: before 0.84.0
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion
com.linecorp.centraldogma:centraldogma-server-auth-shiro: before 0.84.0
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
org.geonetwork-opensource:gn-web-app: 4.4.0 → 4.4.12
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
io.netty:netty-handler: 4.2.0.Final → 4.2.17.Final
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
io.netty:netty-handler: 4.2.0.Final → 4.2.17.Final
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
com.github.jknack:handlebars-springmvc: before 4.5.3
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
org.yamcs:yamcs-core: 5.13.0 → 5.13.2
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
org.yamcs:yamcs-core: 5.13.0 → 5.13.2
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
org.graylog2:graylog2-server: 7.1.0 → 7.1.4
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
org.yamcs:yamcs-core: 5.13.0 → 5.13.2
PowSyBl Core has Command Injection in LocalCommandExecutor-s
PowSyBl Core has Command Injection in LocalCommandExecutor-s
com.powsybl:powsybl-computation-local: before 7.2.2
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
org.yamcs:yamcs-core: before 5.12.8
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
org.mariadb:r2dbc-mariadb: before 1.4.1
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
org.yamcs:yamcs-core: 5.13.0 → 5.13.2
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
org.graylog2:graylog2-server: 6.2.0 → 6.3.12
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
org.mariadb:r2dbc-mariadb: before 1.4.1
Spinnaker: Improper yaml processing on kustomize bake operations
Spinnaker: Improper yaml processing on kustomize bake operations
io.spinnaker.rosco:rosco-manifests: before 2025.3.4
MapFish Print has XXE that allows reading arbitrary files of certain types
MapFish Print has XXE that allows reading arbitrary files of certain types
org.mapfish.print:print-lib: 3.0.0 → 3.28.30
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
org.yamcs:yamcs-core: 5.13.0 → 5.13.2
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
org.mariadb.jdbc:mariadb-java-client: before 2.7.14
Yamcs has Reflected XSS in the URL of the Authorize Endpoint
Yamcs has Reflected XSS in the URL of the Authorize Endpoint
org.yamcs:yamcs-core: before 5.9.4
Yamcs has DOM XSS in Extension Routing
Yamcs has DOM XSS in Extension Routing
org.yamcs:yamcs-core: 5.13.0 → 5.13.2
Yamcs has Unauthenticated Directory Traversal
Yamcs has Unauthenticated Directory Traversal
org.yamcs:yamcs-core: before 5.12.0
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
org.yamcs:yamcs-core: 5.13.0 → 5.13.2
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
org.graylog2:graylog2-server: before 6.3.12
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
org.mariadb.jdbc:mariadb-java-client: before 2.7.14
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
org.mariadb.jdbc:mariadb-java-client: before 2.7.14
http4s has HTTP/2 Denial of Service with Ember Backend
http4s has HTTP/2 Denial of Service with Ember Backend
org.http4s:http4s-ember-core_2.12: before 0.23.35
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
org.codehaus.izpack:izpack-installer: all versions
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.25
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
org.asynchttpclient:async-http-client: 3.0.0.Beta1 → 3.0.11
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability
org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.25
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability
org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.25
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
org.apache.camel:camel-undertow: 4.11.0 → 4.14.9
Sakai Profile Image Deletion has an IDOR
Sakai Profile Image Deletion has an IDOR
org.sakaiproject.profile2:profile2-api: 23.0 → 23.5
Sakai Conversations has a Stored XSS Issue
Sakai Conversations has a Stored XSS Issue
org.sakaiproject.conversations:sakai-conversations-impl: ≥ 23.0
Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
org.apache.camel:camel-azure-storage-datalake: 4.0.0 → 4.14.9
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
org.apache.camel:camel-platform-http-main: 4.8.0 → 4.22.0
Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
org.apache.camel:camel-knative: 3.15.0 → 4.14.9
Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
org.apache.camel:camel-azure-storage-blob: 4.0.0 → 4.14.9
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
org.apache.camel:camel-google-storage: 4.0.0 → 4.14.9
Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
org.apache.camel:camel-mail: 2.17.0 → 4.14.9
Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace
Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace
org.apache.camel:camel-atmosphere-websocket: 4.0.0 → 4.14.9
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
org.geotools.jdbc:gt-jdbc-postgis: 35.0 → 35.1
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
io.netty.incubator:netty-incubator-codec-ohttp: before 0.0.23.Final
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl: before 0.0.23.Final
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
org.geoserver:gs-main: before 2.27.0
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
org.xwiki.platform:xwiki-platform-livedata-livetable: 13.4-rc-1 → 16.10.17
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
com.rabbitmq:amqp-client: before 5.33.0
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
com.rabbitmq:amqp-client: before 5.33.0
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass
org.keycloak:keycloak-services: 26.0.0 → 26.4.15
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
com.rabbitmq:amqp-client: before 5.33.1
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
com.rabbitmq:amqp-client: before 5.33.0
RabbitMQ Java client malformed body frame triggers raw command assembler exception
RabbitMQ Java client malformed body frame triggers raw command assembler exception
com.rabbitmq:amqp-client: before 5.31.0
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
com.rabbitmq:amqp-client: before 5.33.1
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
io.kestra:kestra: before 1.3.24
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
io.netty:netty-codec-http: 4.2.0.Final → 4.2.17.Final
Netty: Memory Exhaustion in SctpMessageCompletionHandler
Netty: Memory Exhaustion in SctpMessageCompletionHandler
io.netty:netty-transport-sctp: 4.2.0.Final → 4.2.17.Final
OpenAM Insecure SSO Cookie Initialization
OpenAM Insecure SSO Cookie Initialization
org.openidentityplatform.openam:openam-core: before 16.1.1
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
com.mchange:mchange-commons-java: before 0.6.0
Apache Ranger has a Command Injection vulnerability
Apache Ranger has a Command Injection vulnerability
org.apache.ranger:ranger: ≥ 0.6.0
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
io.netty:netty-codec-redis: before 4.1.136.Final
jsoup: Cleaner may expose markup with custom raw-text elements
jsoup: Cleaner may expose markup with custom raw-text elements
org.jsoup:jsoup: 1.14.3 → 1.23.1
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
org.apache.httpcomponents.client5:httpclient5: 5.0-alpha1 → 5.6.3
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
io.netty:netty-codec-http2: 4.2.0 → 4.2.16.Final
core-geonetwork has an Open Redirect Bypass
core-geonetwork has an Open Redirect Bypass
org.geonetwork-opensource:geonetwork: ≥ 3.12.0
veraPDF Validation XXE via Rich Text
veraPDF Validation XXE via Rich Text
org.verapdf:validation-model: 1.25.73 → 1.30.2
veraPDF Parser DoS via PostScript CMap Streams
veraPDF Parser DoS via PostScript CMap Streams
org.verapdf:parser: before 1.30.2
veraPDF Parser DoS via PostScript Type 1 Font Programs
veraPDF Parser DoS via PostScript Type 1 Font Programs
org.verapdf:parser: before 1.30.2
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.28.0-alpha
veraPDF Validation XXE via XFA
veraPDF Validation XXE via XFA
org.verapdf:validation-model: 1.17.35 → 1.30.2
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
io.quarkus:quarkus-vertx-http: before 3.20.6.2
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
org.verapdf:validation-model: 1.17.35 → 1.30.2
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.27.0
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
com.cedarpolicy:cedar-java: before 2.3.6
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
io.netty:netty-codec-dns: 4.2.0.Final → 4.2.16.Final
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
org.http4s:http4s-blaze-server_2.13: before 0.23.18
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
org.http4s:http4s-blaze-server_2.13: before 0.23.18
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
io.netty:netty-codec-xml: 4.2.0.Final → 4.2.16.Final
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
org.http4s:blaze-http_2.13: before 0.23.18
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
org.openidentityplatform.opendj:opendj-server-legacy: before 5.1.2
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
at.yawk.lz4:lz4-java: before 1.11.1
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
org.openidentityplatform.openam:openam-core: before 16.1.2
fastjson has a remote code execution (RCE) vulnerability
fastjson has a remote code execution (RCE) vulnerability
com.alibaba:fastjson: ≥ 1.2.68
Netty: Security Control Bypass via CORS Short-Circuit Failure
Netty: Security Control Bypass via CORS Short-Circuit Failure
io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
io.netty:netty-codec-http3: before 4.2.16.Final
Netty: TOCTOU in OcspServerCertificateValidator
Netty: TOCTOU in OcspServerCertificateValidator
io.netty:netty-handler-ssl-ocsp: 4.2.0.Final → 4.2.16.Final
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling
io.netty:netty-codec-xml: 4.2.0.Final → 4.2.16.Final
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
io.netty:netty-codec-compression: 4.2.0.Final → 4.2.16.Final
Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
io.netty:netty-handler-ssl-ocsp: 4.2.0.Final → 4.2.16.Final
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
org.eclipse.jetty:jetty-server: 12.0.0 → 12.0.36
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final
Eclipse Jetty: Path parameter traversal
Eclipse Jetty: Path parameter traversal
org.eclipse.jetty:jetty-util: 12.0.0 → 12.0.35
Netty SPDY SETTINGS frame count materializes unbounded settings map
Netty SPDY SETTINGS frame count materializes unbounded settings map
io.netty:netty-codec-http: 4.2.0.Final → 4.2.16.Final
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
io.netty:netty-codec-http2: 4.2.0.Final → 4.2.16.Final
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.16.Final
Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution
Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution
org.eclipse.jetty:jetty-security: 9.4.0.v20161208 → 9.4.63
Netty: STOMP CONNECT Frame Header Injection in Netty
Netty: STOMP CONNECT Frame Header Injection in Netty
io.netty:netty-codec-stomp: 4.2.0.Final → 4.2.16.Final
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
io.netty:netty-handler-ssl-ocsp: 4.2.0.Final → 4.2.16.Final
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.16.Final
Eclipse Jetty: HTTP Authority/Host mismatch
Eclipse Jetty: HTTP Authority/Host mismatch
org.eclipse.jetty:jetty-server: ≥ 9.4.0.v20161208
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
com.fasterxml.jackson.core:jackson-core: before 2.18.8
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
com.fasterxml.jackson.core:jackson-databind: 2.15.0 → 2.18.8
PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms
PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms
org.postgresql:postgresql: 42.7.4 → 42.7.12
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.5
jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
com.fasterxml.jackson.core:jackson-databind: 2.18.0 → 2.18.9
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
com.arcadedb:arcadedb-engine: before 26.7.2
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
com.arcadedb:arcadedb-server: before 26.7.2
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
com.arcadedb:arcadedb-engine: before 26.7.2
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
com.datadoghq:dd-java-agent: before 1.62.0
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
io.netty:netty-codec-stomp: 4.2.0.Alpha1 → 4.2.16.Final
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
org.apache.logging.log4j:log4j-api: 2.13.1 → 2.25.5
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
io.micronaut:micronaut-http-client: 1.2.8 → 3.10.6
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
io.micronaut:micronaut-http-client: before 3.10.7
Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
org.apache.camel:camel-couchdb: 4.0.0 → 4.14.8
Apache Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter
Apache Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter
org.apache.camel:camel-pqc: 4.18.0 → 4.18.3
Apache Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers
Apache Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers
org.apache.camel:camel-cometd: 4.0.0 → 4.14.8
Apache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
Apache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
org.apache.camel:camel-neo4j: 4.10.0 → 4.14.8
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
org.apache.camel:camel-langchain4j-tools: 4.8.0 → 4.18.3
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
org.apache.camel:camel-jms: 4.14.0 → 4.14.8
Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy
Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy
org.apache.camel:camel-atmosphere-websocket: 4.0.0 → 4.14.8
Apache Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter
Apache Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter
org.apache.camel:camel-irc: 4.0.0 → 4.14.8
Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy
Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy
org.apache.camel:camel-vertx-websocket: 4.0.0 → 4.14.8
Apache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body
Apache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body
org.apache.camel:camel-netty-http: 4.0.0 → 4.14.8
Apache Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body
Apache Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body
org.apache.camel:camel-undertow: 4.0.0 → 4.14.8
Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
org.apache.camel:camel-solr: 4.0.0 → 4.14.8
Apache Camel JMS deserialization filter bypass
Apache Camel JMS deserialization filter bypass
org.apache.camel:camel-jms: 3.0.0 → 4.14.8
Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
org.apache.camel:camel-docling: 4.15.0 → 4.18.3
Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
org.apache.camel:camel-couchbase: 4.0.0 → 4.14.8
Apache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution
Apache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution
org.apache.camel:camel-hazelcast: 4.0.0 → 4.14.8
Apache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter
Apache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter
org.apache.camel:camel-kafka: 4.0.0 → 4.14.8
Apache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
Apache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
org.apache.camel:camel-keycloak: 4.18.0 → 4.18.3
Apache Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation
Apache Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation
org.apache.camel:camel-elasticsearch-rest-client: 4.3.0 → 4.14.8
Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy
Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy
org.apache.camel:camel-iggy: 4.17.0 → 4.18.3
Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
org.apache.camel:camel-cxf-soap: 4.0.0 → 4.14.8
Apache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
Apache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
org.apache.camel:camel-lucene: 4.0.0 → 4.14.8
Apache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
Apache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
org.apache.camel:camel-nats: 4.0.0 → 4.14.8
Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties
Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties
org.apache.camel:camel-mail: 4.0.0 → 4.14.8
Apache Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers
Apache Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers
org.apache.camel:camel-aws2-sqs: 4.0.0 → 4.14.8
Apache Camel-Vertx-Http and Camel-Netty-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
Apache Camel-Vertx-Http and Camel-Netty-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
org.apache.camel:camel-vertx-http: 4.0.0 → 4.14.8
Apache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy
Apache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy
org.apache.camel:camel-aws2-sns: 4.0.0 → 4.14.8
Apache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers
Apache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers
org.apache.camel:camel-dapr: 4.12.0 → 4.14.8
Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter
Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter
org.apache.camel:camel-jira: 4.0.0 → 4.14.8
Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter
Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter
org.apache.camel:camel-salesforce: 4.0.0 → 4.14.8
Apache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
Apache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
org.apache.camel:camel-pqc: 4.18.0 → 4.18.3
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
org.keycloak:keycloak-services: all versions
Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service
Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service
org.apache.httpcomponents.core5:httpcore5: before 5.4.3
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
org.apache.httpcomponents.core5:httpcore5-h2: before 5.4.3
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution
org.jetbrains.kotlin:kotlin-gradle-plugin: before 2.4.20-Beta1
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
com.fasterxml.jackson.core:jackson-databind: 2.0.0 → 2.18.8
jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.4
jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.18.8
jackson-databind has a @JsonView bypass for unwrapped creator parameters
jackson-databind has a @JsonView bypass for unwrapped creator parameters
com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.4
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.14.0
jackson-databind has @JsonView bypass for setterless creator properties
jackson-databind has @JsonView bypass for setterless creator properties
com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.4
jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
com.fasterxml.jackson.core:jackson-databind: 3.1.0 → 3.1.4
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.18.8
Apache Atlas UI: Authenticated User XSS
Apache Atlas UI: Authenticated User XSS
org.apache.atlas:atlas-dashboardv2: before 2.5.0
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types
io.spinnaker.rosco:rosco-core: before 2025.3.3
Apache NiFi: Missing authorization when replacing Process Groups with restricted components
Apache NiFi: Missing authorization when replacing Process Groups with restricted components
org.apache.nifi:nifi-web-api: 1.12.0 → 2.9.0
Apache NiFi fails to validate proxy host headers when constructing qualified URLs
Apache NiFi fails to validate proxy host headers when constructing qualified URLs
org.apache.nifi:nifi-jetty: before 2.10.0
Apache NiFi allows read-only users to submit component configuration verification request
Apache NiFi allows read-only users to submit component configuration verification request
org.apache.nifi:nifi-web-api: 1.15.0 → 2.10.0
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
org.jline:jline-remote-telnet: 4.1.0 → 4.2.1
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
org.jline:jline-remote-telnet: 4.1.0 → 4.2.1
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
org.apache.shiro:shiro-core: before 2.2.1
SNMP4J-Agent allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component
SNMP4J-Agent allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component
org.snmp4j:snmp4j-agent: all versions
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
io.netty:netty-codec-http3: 4.2.0.Final → 4.2.15.Final
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final
Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores
Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores
org.springframework.ai:spring-ai-opensearch-store: 1.0.0 → 1.0.9
Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
io.netty:netty-codec-http: 4.2.0.Final → 4.2.15.Final
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
io.netty:netty-codec-classes-quic: 4.2.0.Final → 4.2.15.Final
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
io.netty:netty-codec-http2: 4.2.0.Final → 4.2.15.Final
Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability
Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability
org.springframework.cloud:spring-cloud-sleuth-instrumentation: ≥ 3.1.0
Netty: Wrapping plain trust manager silently disables hostname verification
Netty: Wrapping plain trust manager silently disables hostname verification
io.netty:netty-handler: 4.2.0.Final → 4.2.15.Final
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
org.apache.cxf:cxf-rt-rs-security-jose-jaxrs: 4.2.0 → 4.2.2
Apache CXF OAuth2 Missing JWT Audience and Issuer Validation in Access Token Validator
Apache CXF OAuth2 Missing JWT Audience and Issuer Validation in Access Token Validator
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
org.apache.cxf:cxf-integration-jca: 4.2.0 → 4.2.2
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier
Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache cxf-core: No restriction on attachment headers per message
Apache cxf-core: No restriction on attachment headers per message
org.apache.cxf:cxf-core: 4.2.0 → 4.2.2
Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control
Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing
Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory
Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory
org.apache.cxf:cxf-rt-transports-jms: 4.2.0 → 4.2.2
Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection
Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Spring Boot: Predictable Temp Directory in Artemis Auto-configuration
Spring Boot: Predictable Temp Directory in Artemis Auto-configuration
org.springframework.boot:spring-boot-autoconfigure: 4.0.0 → 4.0.7
Spring Web Services: SOAP security faults leak Spring Security account state
Spring Web Services: SOAP security faults leak Spring Security account state
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Web Services: X.509 authentication bypasses Spring Security account checks
Spring Web Services: X.509 authentication bypasses Spring Security account checks
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource
Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource
org.springframework.ws:spring-xml: 5.0.0 → 5.0.2
Spring for GraphQL: Cross-Site WebSocket Hijacking
Spring for GraphQL: Cross-Site WebSocket Hijacking
org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4
Spring for GraphQL: Unsafe Deserialization
Spring for GraphQL: Unsafe Deserialization
org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.15.Final
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1
Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default
Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
io.netty:netty-codec-http2: before 4.1.135.Final
Spring for GraphQL: Annotation Detection Vulnerability
Spring for GraphQL: Annotation Detection Vulnerability
org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
org.keycloak:keycloak-rest-admin-ui-ext: before 26.7.0
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
org.springframework.boot:spring-boot-starter-mail: 4.0.0 → 4.0.7
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations
org.springframework.ws:spring-ws-core: 5.0.0 → 5.0.2
Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
org.springframework.integration:spring-integration-file: 7.0.0 → 7.0.5
Spring Web Services: WSS4J validation does not use configured replay cache
Spring Web Services: WSS4J validation does not use configured replay cache
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Jenkins: Stored XSS vulnerability in node offline cause description
Jenkins: Stored XSS vulnerability in node offline cause description
org.jenkins-ci.main:jenkins-core: 2.483 → 2.568
Jenkins: Missing permission check allows unauthorized cancellation of queue items
Jenkins: Missing permission check allows unauthorized cancellation of queue items
org.jenkins-ci.main:jenkins-core: before 2.555.3
Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean
Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean
org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4
Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters
Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods
org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6
Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference
Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference
org.springframework.restdocs:spring-restdocs-webtestclient: 4.0.0 → 4.0.1
Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization
Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization
org.springframework.pulsar:spring-pulsar: 2.0.0 → 2.0.6
Spring Data REST has Improper Access Control in its JSON Patch Implementation
Spring Data REST has Improper Access Control in its JSON Patch Implementation
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)
Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection
Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection
org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6
Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter
Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter
org.springframework.security:spring-security-oauth2-authorization-server: 7.0.0 → 7.0.6
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference
org.springframework.data:spring-data-relational: 4.0.0 → 4.0.6
Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository
Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation
Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation
org.springframework.kafka:spring-kafka: 4.0.0 → 4.0.6
Spring Data REST potentially exposes persistence-layer internals to HTTP clients
Spring Data REST potentially exposes persistence-layer internals to HTTP clients
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL
Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL
org.jenkins-ci.main:jenkins-core: before 2.555.3
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations
org.jenkins-ci.main:jenkins-core: before 2.555.3
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
org.springframework.security:spring-security-web: 6.5.0 → 6.5.11
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL
Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL
org.jenkins-ci.main:jenkins-core: 2.556 → 2.568
Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache
Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache
org.springframework.security:spring-security-web: 7.0.0 → 7.0.6
Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries
Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries
org.springframework.data:spring-data-keyvalue: 4.0.0 → 4.0.6
Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"
Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"
org.jenkins-ci.main:jenkins-core: before 2.555.3
Jenkins exposes other users' timezone and view names to users with Overall/Read permission
Jenkins exposes other users' timezone and view names to users with Overall/Read permission
org.jenkins-ci.main:jenkins-core: before 2.555.3
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation
org.jenkins-ci.main:jenkins-core: before 2.555.3
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Spring Framework Denial of Service via AntPathMatcher
Spring Framework Denial of Service via AntPathMatcher
org.springframework:spring-core: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
org.springframework:spring-expression: all versions
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Unbounded Cache in SpEL
Spring Framework Denial of Service via Unbounded Cache in SpEL
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Spring Framework Algorithmic Denial of Service via SpEL Expressions
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Escalation via Session Fixation in WebFlux
Spring Framework Escalation via Session Fixation in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.8
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
org.springframework:spring-webflux: all versions
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Predictable Session ID in WebSocket Module
Spring Framework Predictable Session ID in WebSocket Module
org.springframework:spring-websocket: 7.0.0 → 7.0.8
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
org.springframework:spring-web: 7.0.0 → 7.0.8
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4
Micrometer HTTP server instrumentations DoS
Micrometer HTTP server instrumentations DoS
io.micrometer:micrometer-core: 1.16.0 → 1.16.6
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
org.springframework.retry:spring-retry: 2.0.0 → 2.0.13
Spring Framework Arbitrary Method Invocation in SpEL Expressions
Spring Framework Arbitrary Method Invocation in SpEL Expressions
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Open Redirect in Spring MVC and WebFlux
Spring Framework Open Redirect in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
io.projectreactor.netty:reactor-netty: 1.3.0 → 1.3.6
Spring Framework Cross-site Scripting via JSP Form Tags
Spring Framework Cross-site Scripting via JSP Form Tags
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Unsafe Deserialization via Jackson JMS Converters
Spring Framework Unsafe Deserialization via Jackson JMS Converters
org.springframework:spring-jms: all versions
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring HATEOAS heap exhaustion through unbounded internal caching
Spring HATEOAS heap exhaustion through unbounded internal caching
org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4
Spring Framework Cross-site Scripting via JavaScriptUtils
Spring Framework Cross-site Scripting via JavaScriptUtils
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Multipart Requests in WebFlux
Spring Framework Denial of Service via Multipart Requests in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.8
Spring LDAP has Authentication Bypass with Empty Password
Spring LDAP has Authentication Bypass with Empty Password
org.springframework.ldap:spring-ldap-core: 4.0.0 → 4.0.4
Micrometer gRPC server instrumentation DoS
Micrometer gRPC server instrumentation DoS
io.micrometer:micrometer-core: 1.16.0 → 1.16.6
Netty has Insufficient Bailiwick Validation for NS Records
Netty has Insufficient Bailiwick Validation for NS Records
io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
io.netty:netty-handler: 4.2.0.Final → 4.2.15.Final
Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
io.netty:netty-transport-native-epoll: 4.2.0.Final → 4.2.15.Final
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
io.netty:netty-codec-http3: 4.2.0.Final → 4.2.15.Final
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.15.Final
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final
Netty's Default QUIC token handler accepts any client-supplied token
Netty's Default QUIC token handler accepts any client-supplied token
io.netty:netty-codec-classes-quic: 4.2.0.Final → 4.2.15.Final
Netty: SCTP reassembly nests buffers without bound
Netty: SCTP reassembly nests buffers without bound
io.netty:netty-transport-sctp: 4.2.0.Final → 4.2.15.Final
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
io.netty:netty-handler: 4.2.0.Final → 4.2.15.Final
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
io.netty:netty-codec-http2: 4.2.0.Final → 4.2.15.Final
Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass
Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass
org.apache.mina:mina-core: 2.2.0 → 2.2.8
Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes
Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes
org.apache.calcite:calcite-core: 1.5.0 → 1.42.0
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability
org.apache.activemq:apache-activemq: before 5.19.7
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
Logback vulnerable to Object Injection through HardenedObjectInputStream modules
ch.qos.logback:logback-core: before 1.5.34
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue
org.apache.activemq:activemq-broker: before 5.19.7
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue
org.apache.activemq:activemq-broker: before 5.19.7
Keycloak has an Authentication Bypass by Primary Weakness
Keycloak has an Authentication Bypass by Primary Weakness
org.keycloak:keycloak-services: all versions
Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition
Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition
org.keycloak:keycloak-server: before 26.6.4
Apache Artemis has an Incorrect Authorization issue
Apache Artemis has an Incorrect Authorization issue
org.apache.artemis:artemis-stomp-protocol: 2.50.0 → 2.54.0
QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability
QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability
ch.qos.logback:logback-core: before 1.5.33
Apache Ignite REST API Has a Relative Path Traversal Vulnerability
Apache Ignite REST API Has a Relative Path Traversal Vulnerability
org.apache.ignite:ignite-core: 2.0.0 → 2.18.0
Keycloak has an Improper Verification of Cryptographic Signature issue
Keycloak has an Improper Verification of Cryptographic Signature issue
org.keycloak:keycloak-services: all versions
Keycloak Services has Improper Validation of Consistency within Input
Keycloak Services has Improper Validation of Consistency within Input
org.keycloak:keycloak-services: ≥ 26.5.0
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
org.keycloak:keycloak-services: before 26.6.2
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
com.squareup.wire:wire-runtime-jvm: before 6.3.0
Keycloak: Session fixation in OIDC login flow that can lead to account takeover
Keycloak: Session fixation in OIDC login flow that can lead to account takeover
org.keycloak:keycloak-services: before 26.6.2
Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers
Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers
org.keycloak:keycloak-services: before 26.6.2
Keycloak: Access token disclosure and implicit flow bypass via forged client data
Keycloak: Access token disclosure and implicit flow bypass via forged client data
org.keycloak:keycloak-services: before 26.6.2
Keycloak: Open redirect when using wildcard valid redirect URIs in Keycloak
Keycloak: Open redirect when using wildcard valid redirect URIs in Keycloak
org.keycloak:keycloak-services: before 26.6.2
Keycloak: Denial of Service via specially crafted SAML input
Keycloak: Denial of Service via specially crafted SAML input
org.keycloak:keycloak-saml-core: before 26.6.2
Keycloak: Unauthorized account takeover via WebAuthn token replay
Keycloak: Unauthorized account takeover via WebAuthn token replay
org.keycloak:keycloak-services: before 26.6.2
Keycloak: Information Disclosure via evaluate-scopes Admin API
Keycloak: Information Disclosure via evaluate-scopes Admin API
org.keycloak:keycloak-services: before 26.6.2
GlassFish's Administration Console is Vulnerable to RCE
GlassFish's Administration Console is Vulnerable to RCE
org.glassfish.main.admingui:console-common: before 8.0.2
GlassFish's gadget handler is vulnerable to RCE
GlassFish's gadget handler is vulnerable to RCE
org.glassfish.main.admingui:admingui: before 8.0.2
Keycloak Account Resources user lookup contains broken access control
Keycloak Account Resources user lookup contains broken access control
org.keycloak:keycloak-services: before 26.4.12
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2: before 6.9.7
async-http-client: Cookie header not stripped on cross-origin redirect
async-http-client: Cookie header not stripped on cross-origin redirect
org.asynchttpclient:async-http-client: 3.0.0.Beta1 → 3.0.10
Apache Commons Configuration: StackOverflowError for YAML input with cycles
Apache Commons Configuration: StackOverflowError for YAML input with cycles
org.apache.commons:commons-configuration2: 2.2 → 2.15.0
Apache Tomcat - WebSocket authentication header exposure
Apache Tomcat - WebSocket authentication header exposure
org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
org.springframework.ai:spring-ai-client-chat: before 1.0.7
Security feature bypass vulnerability in Azure Key Vault Keys library for Java
Security feature bypass vulnerability in Azure Key Vault Keys library for Java
com.azure:azure-security-keyvault-keys: before 4.10.6
Apache Tomcat: LockOutRealm treats user names as case-sensitive
Apache Tomcat: LockOutRealm treats user names as case-sensitive
org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118
Apache Tomcat - HTTP/2 request headers not validated
Apache Tomcat - HTTP/2 request headers not validated
org.apache.tomcat.embed:tomcat-embed-core: 8.5.0 → 9.0.118
Apache Tomcat - Security constraints not correctly applied
Apache Tomcat - Security constraints not correctly applied
org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118
Apache Tomcat - AJP secret compared in non-constant time
Apache Tomcat - AJP secret compared in non-constant time
org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118
Apache Tomcat - Digest authenticator will authenticate any unknown user
Apache Tomcat - Digest authenticator will authenticate any unknown user
org.apache.tomcat.embed:tomcat-embed-core: before 9.0.118
Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
com.ritense.valtimo:web: 12.4.0 → 12.33.0
Vert.x has a DoS via unbounded server-side SNI SslContext cache growth
Vert.x has a DoS via unbounded server-side SNI SslContext cache growth
io.vertx:vertx-core: ≥ 4.3.4
Bouncy Castle LTS native GCM chunking can cause bad-tag exception on decryption
Bouncy Castle LTS native GCM chunking can cause bad-tag exception on decryption
org.bouncycastle:bcprov-lts8on: 2.73.0 → 2.73.11
Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final
Netty Redis Codec Encoder has a CRLF Injection Issue
Netty Redis Codec Encoder has a CRLF Injection Issue
io.netty:netty-codec-redis: 4.2.0.Alpha1 → 4.2.13.Final
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
com.microsoft.kiota:microsoft-kiota-abstractions: before 1.9.1
Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)
Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)
io.netty:netty-codec-dns: 4.2.0.Alpha1 → 4.2.13.Final
Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final
Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)
Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)
io.netty:netty-handler-proxy: before 4.1.133.Final
Netty Lz4FrameDecoder is vulnerable to resource exhaustion
Netty Lz4FrameDecoder is vulnerable to resource exhaustion
io.netty:netty-codec-compression: before 4.2.13.Final
Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding
Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding
io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final
Netty has HttpClientCodec response desynchronization
Netty has HttpClientCodec response desynchronization
io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final
Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.13.Final
Netty HTTP/3 QPACK literal unbounded allocation
Netty HTTP/3 QPACK literal unbounded allocation
io.netty:netty-codec-http3: 4.2.0.Final → 4.2.13.Final
Netty MQTT: Resource exhaustion in MqttDecoder
Netty MQTT: Resource exhaustion in MqttDecoder
io.netty:netty-codec-mqtt: 4.2.0.Alpha1 → 4.2.13.Final
Netty epoll transport denial of service via RST on half-closed TCP connection
Netty epoll transport denial of service via RST on half-closed TCP connection
io.netty:netty-transport-classes-epoll: 4.2.0.Final → 4.2.13.Final
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
com.getaxonflow:axonflow-sdk: before 7.0.0
Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users
Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users
com.ritense.valtimo:document: 12.0.0 → 12.32.0
Apache Wicket has a Path Traversal issue
Apache Wicket has a Path Traversal issue
org.apache.wicket:wicket-core: ≥ 8.0.0-M1
Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection
Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection
io.netty:netty-codec-http: before 4.1.133.Final
pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
org.postgresql:postgresql: 42.2.0 → 42.7.11
Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability
Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability
org.apache.thrift:libthrift: before 0.23.0
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
com.arcadedb:arcadedb-server: 21.10.1 → 26.4.2
Quarkus has Authentication/Authorization bypasses
Quarkus has Authentication/Authorization bypasses
io.quarkus:quarkus-vertx-http: before 3.20.6.1
Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing
Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing
org.apache.opennlp:opennlp-tools: before 2.5.9
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
org.apache.opennlp:opennlp-tools: 2.0.0 → 2.5.9
Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation
Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation
org.apache.opennlp:opennlp-tools: before 2.5.9
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization
org.apache.neethi:neethi: before 3.2.2
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)
org.apache.mina:mina-core: 2.1.0 → 2.1.12
Apache Neethi does not properly detect circular references in policy definitions.
Apache Neethi does not properly detect circular references in policy definitions.
org.apache.neethi:neethi: before 3.2.2
Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API
Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API
org.apache.neethi:neethi: before 3.2.2
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)
org.apache.mina:mina-core: 2.1.0 → 2.1.12
Keycloak has a Forced Browsing issue
Keycloak has a Forced Browsing issue
org.keycloak:keycloak-services: all versions
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
org.springframework:spring-webflux: 7.0.0 → 7.0.7
Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths
Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths
org.jenkins-ci.plugins:script-security: before 1402.v94c9ce464861
Jenkins GitHub Plugin has an XSS vulnerability
Jenkins GitHub Plugin has an XSS vulnerability
com.coravy.hudson.plugins.github:github: before 1.46.0.1
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
org.springframework:spring-webflux: 7.0.0 → 7.0.7
Spring Framework DoS with Multipart Temp Files in WebFlux
Spring Framework DoS with Multipart Temp Files in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.7
Jenkins Matrix Authorization Strategy Plugin: Unsafe deserialization allows invocation of parameterless constructors
Jenkins Matrix Authorization Strategy Plugin: Unsafe deserialization allows invocation of parameterless constructors
org.jenkins-ci.plugins:matrix-auth: 2.0-beta-1 → 3.2.10
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
org.springframework.boot:spring-boot: 4.0.0 → 4.0.6
Spring Boot accepts predictable temp directory without ownership verification
Spring Boot accepts predictable temp directory without ownership verification
org.springframework.boot:spring-boot: 4.0.0 → 4.0.6
Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)
Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)
org.apache.mina:mina-core: 2.0.0 → 2.0.28
Apache Camel Vulnerable to Authentication Bypass Using an Alternate Path or Channel
Apache Camel Vulnerable to Authentication Bypass Using an Alternate Path or Channel
org.apache.camel:camel-platform-http-main: 4.14.1 → 4.14.6
Camel-PQC Vulnerable to Deserialization of Untrusted Data
Camel-PQC Vulnerable to Deserialization of Untrusted Data
org.apache.camel:camel-pqc: before 4.18.2
Apache MINA vulnerable to Deserialization of Untrusted Data
Apache MINA vulnerable to Deserialization of Untrusted Data
org.apache.mina:mina-core: 2.0.0 → 2.0.28
Apache Camel has an incomplete fix for CVE-2025-27636
Apache Camel has an incomplete fix for CVE-2025-27636
org.apache.camel:camel-coap: 3.0.0 → 4.14.6
Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage
Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage
org.apache.camel:camel-jms: 3.0.0 → 4.14.7
Apache ActiveMQ Vulnerable to Cross-site Scripting
Apache ActiveMQ Vulnerable to Cross-site Scripting
org.apache.activemq:apache-activemq: before 5.19.6
Apache ActiveMQ Vulnerable to Improper Input Validation and Code Injection
Apache ActiveMQ Vulnerable to Improper Input Validation and Code Injection
org.apache.activemq:apache-activemq: before 5.19.6
Apache ActiveMQ Vulnerable to Code Injection
Apache ActiveMQ Vulnerable to Code Injection
org.apache.activemq:apache-activemq: before 5.19.6
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers
org.springframework.security:spring-security-config: 7.0.0 → 7.0.5
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
org.springframework.security:spring-security-config: 7.0.0 → 7.0.5
Spring Security has Potential Security Misconfiguration when Using withIssuerLocation
Spring Security has Potential Security Misconfiguration when Using withIssuerLocation
org.springframework.security:spring-security-oauth2-jose: ≥ 6.3.0
camel-infinispan Vulnerable to Deserialization of Untrusted Data
camel-infinispan Vulnerable to Deserialization of Untrusted Data
org.apache.camel:camel-infinispan: before 4.20.0
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
org.springframework.security:spring-security-core: ≥ 5.7.0
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
org.springframework.security:spring-security-web: 7.0.0 → 7.0.5
Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification
Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification
org.apache.httpcomponents.client5:httpclient5: 5.6-alpha1 → 5.6.1
Spinnaker: RCE via expression parsing due to unrestricted context handling
Spinnaker: RCE via expression parsing due to unrestricted context handling
io.spinnaker.echo:echo-pipelinetriggers: 2026.0-0 → 2026.0.1
Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
org.springframework.security:spring-security-core: 6.5.0 → 6.5.10
Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo: before 2026.0.1
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
org.apache.kafka:kafka-clients: 4.1.0 → 4.1.2
Apache Kafka exposes sensitive information in its DEBUG logs
Apache Kafka exposes sensitive information in its DEBUG logs
org.apache.kafka:kafka-clients: 0.11.0 → 3.9.2
Bouncy Castle Has Covert Timing Channel Vulnerability
Bouncy Castle Has Covert Timing Channel Vulnerability
org.bouncycastle:bcprov-jdk15to18: 1.71 → 1.80.2
Bouncy Castle Uncontrolled Resource Consumption vulnerability
Bouncy Castle Uncontrolled Resource Consumption vulnerability
org.bouncycastle:bcpg-jdk12: all versions
Bouncy Castle has an LDAP injection
Bouncy Castle has an LDAP injection
org.bouncycastle:bcprov-jdk14: 1.74 → 1.84
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
org.bouncycastle:bcprov-jdk14: ≥ 1.59
PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability
PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability
org.pac4j:pac4j-core: before 5.7.10
Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService
Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService
com.ritense.valtimo:inbox: 13.0.0.RELEASE → 13.22.0.RELEASE
Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
org.bouncycastle:bcpkix-jdk18on: 1.49 → 1.84
Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
dev.dsf:dsf-bpe-process-api-v2: all versions
AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects
AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects
org.asynchttpclient:async-http-client: 3.0.0.Beta1 → 3.0.9
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
org.eclipse.jetty:jetty-http: 12.1.0 → 12.1.7
Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration
Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration
org.apache.logging.log4j:log4j-core: 2.12.0 → 2.25.4
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
org.apache.logging.log4j:log4j-core: 2.0-alpha1 → 2.25.4
Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
org.apache.logging.log4j:log4j-1.2-api: 2.7 → 2.25.4
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
org.apache.logging.log4j:log4j-layout-template-json: 2.14.0 → 2.25.4
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
org.apache.logging.log4j:log4j-core: 2.21.0 → 2.25.4
Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
org.apache.activemq:activemq-client: before 5.19.4
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
org.apache.tomcat:tomcat-coyote-ffm: 9.0.83 → 9.0.116
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
org.apache.tomcat:tomcat-catalina: 9.0.40 → 9.0.116
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
org.apache.tomcat:tomcat-tribes: 11.0.20 → 11.0.21
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
org.apache.tomcat:tomcat-tribes: 9.0.13 → 9.0.116
Apache Tomcat has an Improper Input Validation vulnerability
Apache Tomcat has an Improper Input Validation vulnerability
org.apache.tomcat:tomcat-coyote: 9.0.113 → 9.0.116
Apache Tomcat: Configured cipher preference order not preserved
Apache Tomcat: Configured cipher preference order not preserved
org.apache.tomcat:tomcat-coyote: 9.0.114 → 9.0.116
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
org.apache.tomcat:tomcat-tribes: 9.0.13 → 9.0.117
Apache Tomcat has an Open Redirect vulnerability
Apache Tomcat has an Open Redirect vulnerability
org.apache.tomcat:tomcat-catalina: 8.5.30 → 9.0.116
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
org.apache.tomcat:tomcat-coyote: 7.0.0 → 9.0.116
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
org.apache.tomcat:tomcat-coyote-ffm: 9.0.92 → 9.0.117
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class
io.quarkiverse.openapi.generator:quarkus-openapi-generator: before 2.16.0
Authenticated Apache ActiveMQ Broker and Apache ActiveMQ users could perform RCE via Jolokia MBeans
Authenticated Apache ActiveMQ Broker and Apache ActiveMQ users could perform RCE via Jolokia MBeans
org.apache.activemq:activemq-broker: before 5.19.5
Apache ActiveMQ: Improper validation and restriction of a classpath path name
Apache ActiveMQ: Improper validation and restriction of a classpath path name
org.apache.activemq:activemq-client: before 5.19.3
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
org.apache.kafka:kafka-clients: 2.8.0 → 3.9.2
Java-SDK has a DNS Rebinding Vulnerability
Java-SDK has a DNS Rebinding Vulnerability
io.modelcontextprotocol.sdk:mcp-core: before 1.0.0
Jackson Core: Document length constraint bypass in blocking, async, and DataInput parsers
Jackson Core: Document length constraint bypass in blocking, async, and DataInput parsers
tools.jackson.core:jackson-core: 3.0.0 → 3.1.1
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
org.keycloak:keycloak-services: before 26.5.7
Keycloak: Replay of action tokens via improper handling of single-use entries
Keycloak: Replay of action tokens via improper handling of single-use entries
org.keycloak:keycloak-services: before 26.5.7
Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw
Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw
org.keycloak:keycloak-services: before 26.5.7
Keycloak: Application-Level DoS via Scope Processing
Keycloak: Application-Level DoS via Scope Processing
org.keycloak:keycloak-services: before 26.5.7
Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
org.keycloak:keycloak-services: before 26.5.7
MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
io.modelcontextprotocol.sdk:mcp-core: 1.0.0 → 1.0.1
Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
io.trino:trino-iceberg: 439 → 480
Undertow is Vulnerable to HTTP Request/Response Smuggling
Undertow is Vulnerable to HTTP Request/Response Smuggling
io.undertow:undertow-parent: all versions
Undertow is Vulnerable to HTTP Request/Response Smuggling
Undertow is Vulnerable to HTTP Request/Response Smuggling
io.undertow:undertow-parent: all versions
AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities
AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities
software.amazon.awssdk:cloudfront: 2.18.33 → 2.41.30
Undertow is Vulnerable to HTTP Request/Response Smuggling
Undertow is Vulnerable to HTTP Request/Response Smuggling
io.undertow:undertow-parent: all versions
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
org.keycloak:keycloak-services: 26.5.0 → 26.6.3
Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
io.netty:netty-codec-http: before 4.1.132.Final
Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
io.netty:netty-codec-http2: before 4.1.132.Final
pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names
pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names
org.pf4j:pf4j: before 3.14.1
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.26.1
Plexus-Utils has a Directory Traversal vulnerability in its extractFile method
Plexus-Utils has a Directory Traversal vulnerability in its extractFile method
org.codehaus.plexus:plexus-utils: 4.0.0 → 4.0.3
Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
io.undertow:undertow-core: all versions
Keycloak's identity-first login flow exposes user information
Keycloak's identity-first login flow exposes user information
org.keycloak:keycloak-services: 26.5.0 → 26.6.1
Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
org.keycloak:keycloak-services: all versions
Spring Framework Improper Path Limitation with Script View Templates
Spring Framework Improper Path Limitation with Script View Templates
org.springframework:spring-webmvc: 7.0.0-M1 → 7.0.6
Spring Security HTTP Headers Are not Written Under Some Conditions
Spring Security HTTP Headers Are not Written Under Some Conditions
org.springframework.security:spring-security-web: all versions
Spring MVC and WebFlux has Server Sent Event stream corruption
Spring MVC and WebFlux has Server Sent Event stream corruption
org.springframework:spring-webmvc: 7.0.0-M1 → 7.0.6
Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot has an Authentication Bypass under Actuator Health groups paths
org.springframework.boot:spring-boot-starter-actuator: ≥ 3.4.0
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
org.springframework.boot:spring-boot-starter-actuator: 4.0.0-M1 → 4.0.4
Keycloak: Unauthorized authentication via disabled SAML Identity Provider
Keycloak: Unauthorized authentication via disabled SAML Identity Provider
org.keycloak:keycloak-services: before 26.5.5
Jenkins has a link following vulnerability allows arbitrary file creation
Jenkins has a link following vulnerability allows arbitrary file creation
org.jenkins-ci.main:jenkins-core: before 2.555
Keycloak: Denial of Service due to excessive SAMLRequest decompression
Keycloak: Denial of Service due to excessive SAMLRequest decompression
org.keycloak:keycloak-saml-adapter-core: before 26.5.4
Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
io.micronaut:micronaut-json-core: 4.0.0-M1 → 4.10.16
Micronaut Framework vulnerable to a Denial of Service in HTML error response caching
Micronaut Framework vulnerable to a Denial of Service in HTML error response caching
io.micronaut:micronaut-http-server: 4.7.0 → 4.10.17
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
io.spinnaker.clouddriver:clouddriver-artifacts: 2025.1.6 → 2025.2.4
Apache Spark: Spark History Server Code Execution Vulnerability
Apache Spark: Spark History Server Code Execution Vulnerability
org.apache.spark:spark-core_2.13: 4.0.0 → 4.0.1
Keycloak: Information disclosure of disabled user attributes via administrative endpoint
Keycloak: Information disclosure of disabled user attributes via administrative endpoint
org.keycloak:keycloak-services: all versions
Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
org.keycloak:keycloak-services: all versions
Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash
Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash
com.vaadin:flow-server: before 14.14.1
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
org.apache.pdfbox:pdfbox-examples: 2.0.24 → 3.0.7
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
org.apache.zookeeper:zookeeper: 3.8.0 → 3.8.6
Apache ZooKeeper has improper handling of configuration values
Apache ZooKeeper has improper handling of configuration values
org.apache.zookeeper:zookeeper: 3.9.0 → 3.9.5
Keycloak SAML Broken has Authentication Bypass by Primary Weakness
Keycloak SAML Broken has Authentication Bypass by Primary Weakness
org.keycloak:keycloak-broker-saml: all versions
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
org.keycloak:keycloak-services: before 26.5.5
org.eclipse.jetty:jetty-http has different parsing of invalid URIs
org.eclipse.jetty:jetty-http has different parsing of invalid URIs
org.eclipse.jetty:jetty-http: ≥ 9.4.0
The Eclipse Jetty Server Artifact has a Gzip request memory leak
The Eclipse Jetty Server Artifact has a Gzip request memory leak
org.eclipse.jetty:jetty-server: 12.1.0 → 12.1.6
Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions
Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions
org.apache.activemq:artemis-server: ≥ 2.11.0
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
org.xwiki.contrib.blog:application-blog-ui: 9.15 → 9.15.7
jackson-core has Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
jackson-core has Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
tools.jackson.core:jackson-core: 3.0.0 → 3.1.0
Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound
Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound
org.apache.activemq:apache-activemq: before 5.19.2
Apache Ranger has a Code Injection vulnerability
Apache Ranger has a Code Injection vulnerability
org.apache.ranger:ranger-plugins-common: before 2.8.0
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
tools.jackson.core:jackson-core: 3.0.0 → 3.1.0
PSI Probe vulnerable to Server-Side Request Forgery
PSI Probe vulnerable to Server-Side Request Forgery
com.github.psi-probe:psi-probe-core: all versions
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
org.keycloak:keycloak-services: before 26.4.4
PSI Probe: Broken access control can lead to DoS
PSI Probe: Broken access control can lead to DoS
com.github.psi-probe:psi-probe-core: all versions
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes
org.keycloak:keycloak-server-spi-private: before 26.5.2
mchange-commons-java: Remote Code Execution via JNDI Reference Resolution
mchange-commons-java: Remote Code Execution via JNDI Reference Resolution
com.mchange:mchange-commons-java: before 0.4.0
c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
com.mchange:c3p0: before 0.12.0
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
org.keycloak:keycloak-services: all versions
carbon-apimgt does not properly restrict uploaded files
carbon-apimgt does not properly restrict uploaded files
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1: before 9.32.167
Jenkins has a build information disclosure vulnerability through Run Parameter
Jenkins has a build information disclosure vulnerability through Run Parameter
org.jenkins-ci.main:jenkins-core: 2.542 → 2.551
Jenkins has a stored XSS vulnerability in node offline cause description
Jenkins has a stored XSS vulnerability in node offline cause description
org.jenkins-ci.main:jenkins-core: 2.542 → 2.551
Apache Tomcat - Client certificate verification bypass
Apache Tomcat - Client certificate verification bypass
org.apache.tomcat.embed:tomcat-embed-core: 11.0.0-M1 → 11.0.15
Apache Tomcat - Security constraint bypass with HTTP/0.9
Apache Tomcat - Security constraint bypass with HTTP/0.9
org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.15
Apache Tomcat has an Improper Input Validation vulnerability
Apache Tomcat has an Improper Input Validation vulnerability
org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.18
Apache Avro Java SDK is Vulnerable to Code Injection
Apache Avro Java SDK is Vulnerable to Code Injection
org.apache.avro:avro-compiler: 1.12.0 → 1.12.1
Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
org.apache.shiro:shiro-core: before 2.1.0
Keycloak logs sensitive headers
Keycloak logs sensitive headers
org.keycloak:keycloak-quarkus-server: before 26.5.6
Apache Shiro has an Authentication Bypass
Apache Shiro has an Authentication Bypass
org.apache.shiro:shiro-spring: before 2.1.0
Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log
Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log
org.neo4j:neo4j: before 2026.01
Neo4j Enterprise and Community vulnerable to a potential information disclosure
Neo4j Enterprise and Community vulnerable to a potential information disclosure
org.neo4j:neo4j: before 5.26.21
JinJava Bypass through ForTag leads to Arbitrary Java Execution
JinJava Bypass through ForTag leads to Arbitrary Java Execution
com.hubspot.jinjava:jinjava: 2.8.0 → 2.8.3
Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion
Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion
org.hibernate.reactive:hibernate-reactive-core: before 4.2.1
Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
org.keycloak:keycloak-services: all versions
Hibernate vulnerable to SQL Injection
Hibernate vulnerable to SQL Injection
org.hibernate:hibernate-core: ≥ 5.2.8
Logback allows an attacker to instantiate classes already present on the class path
Logback allows an attacker to instantiate classes already present on the class path
ch.qos.logback:logback-core: before 1.5.25
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
org.apache.solr:solr-core: 5.3.0 → 9.10.1
Apache Solr: Insufficient file-access checking in standalone core-creation requests
Apache Solr: Insufficient file-access checking in standalone core-creation requests
org.apache.solr:solr-core: 8.6.0 → 9.10.1
Keycloak services allows the issuance of access and refresh tokens for disabled users
Keycloak services allows the issuance of access and refresh tokens for disabled users
org.keycloak:keycloak-services: 26.5.0 → 26.5.2
risesoft-y9 Digital-Infrastructure has a SQL injection vulnerability
risesoft-y9 Digital-Infrastructure has a SQL injection vulnerability
net.risesoft:risenet-y9boot-support-platform-service: all versions
Vert.x Web static handler component cache can be manipulated to deny the access to static files
Vert.x Web static handler component cache can be manipulated to deny the access to static files
io.vertx:vertx-core: before 4.5.24
Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests
Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests
io.undertow:undertow-core: 2.3.0.Alpha1 → 2.3.21.Final
Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write
Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write
io.quarkus:quarkus-rest: before 3.20.5
Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
io.spinnaker.clouddriver:clouddriver-artifacts: before 2025.1.6
MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation
MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation
org.msgpack:msgpack-core: before 0.9.11
Vaadin vulnerable to Cross-site Scripting
Vaadin vulnerable to Cross-site Scripting
com.vaadin:vaadin-server: 7.0.0 → 7.7.50
Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
org.elasticsearch.plugin:x-pack-core: before 8.19.8
Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
org.elasticsearch.plugin:x-pack-security: before 8.19.9
Apache Log4j does not verify the TLS hostname in its Socket Appender
Apache Log4j does not verify the TLS hostname in its Socket Appender
org.apache.logging.log4j:log4j-core: 2.0-beta9 → 2.25.3
Amazon S3 Encryption Client for Java has a Key Commitment Issue
Amazon S3 Encryption Client for Java has a Key Commitment Issue
software.amazon.encryption.s3:amazon-s3-encryption-client-java: before 4.0.0
jose4j is vulnerable to DoS via compressed JWE content
jose4j is vulnerable to DoS via compressed JWE content
org.bitbucket.b_c:jose4j: before 0.9.6
Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder
Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder
io.netty:netty-codec-http: 4.2.0.Alpha1 → 4.2.8.Final
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
org.elasticsearch:elasticsearch: 7.0.0-alpha1 → 8.19.8
aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
io.airlift:aircompressor-v3: before 3.4
Jenkins is missing a permission check on password fields
Jenkins is missing a permission check on password fields
org.jenkins-ci.main:jenkins-core: 2.529 → 2.541
Jenkins has a Denial of service vulnerability in HTTP-based CLI
Jenkins has a Denial of service vulnerability in HTTP-based CLI
org.jenkins-ci.main:jenkins-core: 2.529 → 2.541
Jenkins's build authorization token is stored and displayed in plain text
Jenkins's build authorization token is stored and displayed in plain text
org.jenkins-ci.main:jenkins-core: 2.529 → 2.541
Jenkins's build authorization token is stored and displayed in plain text
Jenkins's build authorization token is stored and displayed in plain text
org.jenkins-ci.main:jenkins-core: 2.529 → 2.541
Jenkins has a CSRF vulnerability on the login form
Jenkins has a CSRF vulnerability on the login form
org.jenkins-ci.main:jenkins-core: 2.529 → 2.541
yawkat LZ4 Java has a possible information leak in Java safe decompressor
yawkat LZ4 Java has a possible information leak in Java safe decompressor
at.yawk.lz4:lz4-java: before 1.10.1
Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded
Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded
io.undertow:undertow-core: before 2.2.39.Final
Keycloak unable to restrict access to the admin console
Keycloak unable to restrict access to the admin console
org.keycloak:keycloak-quarkus-server: before 26.4.4
LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
at.yawk.lz4:lz4-java: before 1.8.1
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer: 20240325.1 → 20260101.1
OpenSearch is vulnerable to DoS via complex query_string inputs
OpenSearch is vulnerable to DoS via complex query_string inputs
org.opensearch:opensearch-common: 3.0.0 → 3.3.0
Eclipse Jersey has a Race Condition
Eclipse Jersey has a Race Condition
org.glassfish.jersey.core:jersey-client: 2.45 → 2.46
CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
org.cyclonedx:cyclonedx-core-java: 2.1.0 → 11.0.1
WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
org.wso2.carbon.mediation:org.wso2.carbon.localentry: all versions
Keycloak vulnerable to session takeovers due to reuse of session identifiers
Keycloak vulnerable to session takeovers due to reuse of session identifiers
org.keycloak:keycloak-services: before 26.0.0
Apache Tomcat Vulnerable to Relative Path Traversal
Apache Tomcat Vulnerable to Relative Path Traversal
org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.11
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.12
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.11
Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
org.bouncycastle:bc-fips: 2.1.0 → 2.1.2
Keycloak does not invalidate sessions when "Remember Me" is disabled
Keycloak does not invalidate sessions when "Remember Me" is disabled
org.keycloak:keycloak-services: 26.3.0 → 26.4.1
Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
io.vertx:vertx-web: before 4.5.22
Vert.x-Web Access Control Flaw in StaticHandler’s Hidden File Protection for Files Under Hidden Directories
Vert.x-Web Access Control Flaw in StaticHandler’s Hidden File Protection for Files Under Hidden Directories
io.vertx:vertx-web: before 4.5.22
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
org.springframework:spring-websocket: 6.2.0 → 6.2.12
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
io.netty:netty-codec-smtp: 4.2.0.Alpha1 → 4.2.7.Final
JDBC Driver for SQL Server has improper input validation issue
JDBC Driver for SQL Server has improper input validation issue
com.microsoft.sqlserver:mssql-jdbc: 8.3.0.jre11-preview → 10.2.4.jre11
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
org.elasticsearch:elasticsearch: 7.0.0 → 8.18.8
Keycloak Potential Variable Reference in Model Storage Services
Keycloak Potential Variable Reference in Model Storage Services
org.keycloak:keycloak-model-storage-services: all versions
QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing
QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing
ch.qos.logback:logback-core: 1.4.0 → 1.5.19
WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt: all versions
Apache IoTDB: DoS Vulnerability
Apache IoTDB: DoS Vulnerability
org.apache.iotdb:iotdb-core: 1.3.3 → 2.0.5
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
org.apache.zookeeper:zookeeper: 3.9.0 → 3.9.4
WSO2 Identity Server Apps allows content spoofing in logs
WSO2 Identity Server Apps allows content spoofing in logs
org.wso2.identity.apps:authentication-portal: before 2.4.4
jinjava has Sandbox Bypass via JavaType-Based Deserialization
jinjava has Sandbox Bypass via JavaType-Based Deserialization
com.hubspot.jinjava:jinjava: 2.8.0 → 2.8.1
Jenkins has a missing permission check, allowing users to obtain agent names
Jenkins has a missing permission check, allowing users to obtain agent names
org.jenkins-ci.main:jenkins-core: before 2.516.3
Jenkins is missing a permission check in the authenticated users' profile menu
Jenkins is missing a permission check in the authenticated users' profile menu
org.jenkins-ci.main:jenkins-core: before 2.516.3
Jenkins has a log message injection vulnerability
Jenkins has a log message injection vulnerability
org.jenkins-ci.main:jenkins-core: before 2.516.3
Spring Security annotation detection mechanism has authorization bypass
Spring Security annotation detection mechanism has authorization bypass
org.springframework.security:spring-security-core: 6.4.0 → 6.4.10
Spring Framework annotation detection mechanism may result in improper authorization
Spring Framework annotation detection mechanism may result in improper authorization
org.springframework:spring-core: ≥ 5.3.0
Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions
Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions
io.netty:netty-codec-http: before 4.1.125.Final
Vaadin Platform possible file bypass via upload validation on the server-side
Vaadin Platform possible file bypass via upload validation on the server-side
com.vaadin:vaadin: 14.0.0 → 14.13.1
Vaadin Framework possible file bypass via upload validation on the server-side
Vaadin Framework possible file bypass via upload validation on the server-side
com.vaadin:vaadin-server: 7.0.0 → 7.7.48
Netty's decoders vulnerable to DoS via zip bomb style attack
Netty's decoders vulnerable to DoS via zip bomb style attack
io.netty:netty-codec-compression: 4.2.0.Alpha1 → 4.2.5.Final
Undertow MadeYouReset HTTP/2 DDoS Vulnerability
Undertow MadeYouReset HTTP/2 DDoS Vulnerability
io.undertow:undertow-core: before 2.2.38.Final
Valtimo scripting engine can be used to gain access to sensitive data or resources
Valtimo scripting engine can be used to gain access to sensitive data or resources
com.ritense.valtimo:core: before 12.16.0.RELEASE
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
org.apache.tika:tika-parser-pdf-module: 1.13 → 3.2.2
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
org.eclipse.jetty.http2:http2-common: 9.3.0 → 9.4.58
Spring Framework MVC Applications Path Traversal Vulnerability
Spring Framework MVC Applications Path Traversal Vulnerability
org.springframework:spring-webmvc: 6.2.0 → 6.2.10
Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability
Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability
org.bouncycastle:bc-fips: 2.1.0 → 2.1.1
Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
org.bouncycastle:bcpkix-jdk15on: 1.44 → 1.79
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
io.netty:netty-codec-http2: 4.2.0.Alpha1 → 4.2.4.Final
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
org.bouncycastle:bcprov-jdk14: 1.0 → 1.78
Apache CXF: Untrusted JMS configuration can lead to RCE
Apache CXF: Untrusted JMS configuration can lead to RCE
org.apache.cxf:cxf-rt-transports-jms: before 3.6.8
XWiki allows Reflected XSS in two templates
XWiki allows Reflected XSS in two templates
org.xwiki.platform:xwiki-platform-web-templates: 4.2-milestone-3 → 16.4.8
Jakarta Mail vulnerable to SMTP Injection
Jakarta Mail vulnerable to SMTP Injection
org.eclipse.angus:smtp: before 2.0.4
Reactor Netty HTTP is vulnerable to credential leaks during chained redirects
Reactor Netty HTTP is vulnerable to credential leaks during chained redirects
io.projectreactor.netty:reactor-netty-http: 1.3.0-M1 → 1.3.0-M5
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
org.apache.cxf:cxf-core: before 3.5.11
XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
org.xwiki.rendering:xwiki-rendering-syntax-xhtml: 5.4.5 → 14.10
XWiki Rendering is vulnerable to RCE attacks when processing nested macros
XWiki Rendering is vulnerable to RCE attacks when processing nested macros
org.xwiki.rendering:xwiki-rendering-transformation-macro: 4.2-milestone-1 → 13.10.11
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
com.nimbusds:nimbus-jose-jwt: 9.38-rc1 → 10.0.2
Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
org.apache.commons:commons-lang3: 3.0 → 3.18.0
Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams
Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams
org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.9
Conductor vulnerable to OS command injection through unrestricted access to Java classes
Conductor vulnerable to OS command injection through unrestricted access to Java classes
org.conductoross:conductor-core: before 3.21.13
jackson-core can throw a StackoverflowError when processing deeply nested data
jackson-core can throw a StackoverflowError when processing deeply nested data
com.fasterxml.jackson.core:jackson-core: before 2.15.0
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
org.infinispan:infinispan-cli-client: all versions
Quarkus potentially leaks data when duplicating a duplicated context
Quarkus potentially leaks data when duplicating a duplicated context
io.quarkus:quarkus-vertx: before 3.15.6
sentry-android unmasked sensitive data in Android Session Replays for users of Jetpack Compose 1.8+
sentry-android unmasked sensitive data in Android Session Replays for users of Jetpack Compose 1.8+
io.sentry:sentry-android: before 8.14.0
Apache Tomcat - Security constraint bypass for pre/post-resources
Apache Tomcat - Security constraint bypass for pre/post-resources
org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.8
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
commons-fileupload:commons-fileupload: 1.0 → 1.6.0
Apache Tomcat - DoS in multipart upload
Apache Tomcat - DoS in multipart upload
org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.8
Spring Framework vulnerable to a reflected file download (RFD)
Spring Framework vulnerable to a reflected file download (RFD)
org.springframework:spring-web: 6.2.0 → 6.2.8
Solon Vulnerable to Directory Traversal
Solon Vulnerable to Directory Traversal
org.noear:solon-faas-luffy: 3.1.2 → 3.2.0
pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
org.postgresql:postgresql: 42.7.4 → 42.7.7
Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
org.apache.kafka:kafka-clients: 3.1.0 → 3.9.1
Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
com.fasterxml.jackson.core:jackson-core: 2.0.0 → 2.13.0
Para Inserts Sensitive Information into Log File for Facebook authentication
Para Inserts Sensitive Information into Log File for Facebook authentication
com.erudika:para-server: before 1.50.8
WSO2 products vulnerable to Cross-site Scripting
WSO2 products vulnerable to Cross-site Scripting
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.user.store.configuration.ui: before 7.5.12
WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint
WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util: 6.0.0 → 7.0.111
Para Server Logs Sensitive Information
Para Server Logs Sensitive Information
com.erudika:para-server: before 1.50.8
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
org.springframework.cloud:spring-cloud-gateway-server: 4.2.0 → 4.2.3
Apache Tomcat - CGI security constraint bypass
Apache Tomcat - CGI security constraint bypass
org.apache.tomcat:tomcat-catalina: 9.0.0.M1 → 9.0.105
Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users
Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users
com.ritense.valtimo:objecten-api: ≥ 11.0.0.RELEASE
Apache Commons Improper Access Control vulnerability
Apache Commons Improper Access Control vulnerability
commons-beanutils:commons-beanutils: 1.0 → 1.11.0
Eclipse JGit XML External Entity (XXE) Vulnerability
Eclipse JGit XML External Entity (XXE) Vulnerability
org.eclipse.jgit:org.eclipse.jgit: 7.2.0.202503040940-r → 7.2.1.202505142326-r
Spring Framework DataBinder Case Sensitive Match Exception
Spring Framework DataBinder Case Sensitive Match Exception
org.springframework:spring-context: 6.2.0 → 6.2.7
Apache Commons Configuration Uncontrolled Resource Consumption
Apache Commons Configuration Uncontrolled Resource Consumption
commons-configuration:commons-configuration: all versions
Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit
Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit
org.eclipse.jetty.http2:jetty-http2-common: 12.0.0 → 12.0.17
**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
org.eclipse.jetty:jetty-server: 9.4.0 → 9.4.57.v20241219
Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser
Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser
org.graylog2:graylog2-server: before 6.2.0
JRuby-OpenSSL has hostname verification disabled by default
JRuby-OpenSSL has hostname verification disabled by default
rubygems:jruby-openssl: 0.12.1 → 0.15.4
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
org.apache.activemq:activemq-openwire-legacy: before 5.16.8
Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata
Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata
org.apache.parquet:parquet-avro: before 1.15.2
HAL Cross Site Scripting (XSS) vulnerability of user input when storing it in a data store
HAL Cross Site Scripting (XSS) vulnerability of user input when storing it in a data store
org.jboss.hal:hal-console: before 3.7.11.Final
Keycloak hostname verification
Keycloak hostname verification
org.keycloak:keycloak-services: before 26.2.2
Keycloak vulnerable to two factor authentication bypass
Keycloak vulnerable to two factor authentication bypass
org.keycloak:keycloak-services: before 26.2.2
Solr script service doesn't take dropped programming right into account
Solr script service doesn't take dropped programming right into account
org.xwiki.platform:xwiki-platform-search-solr-api: 4.5.1 → 15.10.13
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
org.springframework.boot:spring-boot: all versions
Apache Tomcat Rewrite rule bypass
Apache Tomcat Rewrite rule bypass
org.apache.tomcat:tomcat-catalina: 9.0.76 → 9.0.104
Apache Tomcat Denial of Service via invalid HTTP priority header
Apache Tomcat Denial of Service via invalid HTTP priority header
org.apache.tomcat:tomcat-coyote: 9.0.76 → 9.0.104
Apache HttpClient disables domain checks
Apache HttpClient disables domain checks
org.apache.httpcomponents.client5:httpclient5: 5.4-alpha1 → 5.4.3
Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
org.apache.poi:poi-ooxml: before 5.4.0
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
org.elasticsearch:elasticsearch: 7.17.0 → 8.15.1
Jenkins Missing Permission Check
Jenkins Missing Permission Check
org.jenkins-ci.main:jenkins-core: 2.500 → 2.504
Jenkins Missing Permission Check
Jenkins Missing Permission Check
org.jenkins-ci.main:jenkins-core: 2.500 → 2.504
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
org.apache.parquet:parquet-avro: before 1.15.1
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
org.apache.activemq:artemis-server: 2.0.0 → 2.40.0
WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack
WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack
org.wildfly.security:wildfly-elytron: 1.17.0.Final → 2.2.9.Final
Spring Security Vulnerable to Authorization Bypass via Security Annotations
Spring Security Vulnerable to Authorization Bypass via Security Annotations
org.springframework.security:spring-security-core: 6.4.0 → 6.4.4
Spring Security Does Not Enforce Password Length
Spring Security Does Not Enforce Password Length
org.springframework.security:spring-security-crypto: 6.3.0 → 6.3.8
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
com.liferay.portal:release.dxp.bom: ≥ 2024.Q2.0
Wire has Uncontrolled Recursion on Nested Groups
Wire has Uncontrolled Recursion on Nested Groups
com.squareup.wire:wire-runtime: before 5.2.0
Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check
Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check
net.i2p.crypto:eddsa: all versions
Snowflake JDBC Driver client-side encryption key in DEBUG logs
Snowflake JDBC Driver client-side encryption key in DEBUG logs
net.snowflake:snowflake-jdbc: 3.0.13 → 3.23.1
SmallRye Fault Tolerance out-of-memory (OOM) issue
SmallRye Fault Tolerance out-of-memory (OOM) issue
io.smallrye:smallrye-fault-tolerance-core: 6.3.0 → 6.4.2
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
org.keycloak:keycloak-ldap-federation: 26.1.0 → 26.1.3
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.3
com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations
com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations
com.xwiki.confluencepro:application-confluence-migrator-pro-ui: 1.0 → 1.2.0
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
org.jenkins-ci.main:jenkins-core: before 2.492.2
Jenkins Open Redirect vulnerability
Jenkins Open Redirect vulnerability
org.jenkins-ci.main:jenkins-core: before 2.492.2
Jenkins cross-site request forgery (CSRF) vulnerability
Jenkins cross-site request forgery (CSRF) vulnerability
org.jenkins-ci.main:jenkins-core: 2.493 → 2.500
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
org.jenkins-ci.main:jenkins-core: 2.493 → 2.500
Emissary May Use a Broken or Risky Cryptographic Algorithm
Emissary May Use a Broken or Risky Cryptographic Algorithm
gov.nsa.emissary:emissary: before 8.24.0
Pebble has Arbitrary Local File Inclusion (LFI) Vulnerability via `include` macro
Pebble has Arbitrary Local File Inclusion (LFI) Vulnerability via `include` macro
io.pebbletemplates:pebble: all versions
io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout
io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout
io.quarkus:quarkus-resteasy: 3.16.0.CR1 → 3.19.1
Keycloak allows cross-site scripting (XSS)
Keycloak allows cross-site scripting (XSS)
org.keycloak:keycloak-core: all versions
Apache Ignite: Possible RCE when deserializing incoming messages by the server node
Apache Ignite: Possible RCE when deserializing incoming messages by the server node
org.apache.ignite:ignite-core: 2.6.0 → 2.17.0
Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance
Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance
io.quarkus:quarkus-rest: 3.16.0.CR1 → 3.18.2
Denial of Service attack on windows app using Netty
Denial of Service attack on windows app using Netty
io.netty:netty-common: before 4.1.118.Final
SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
io.netty:netty-handler: 4.1.91.Final → 4.1.118.Final
Netplex Json-smart Uncontrolled Recursion vulnerability
Netplex Json-smart Uncontrolled Recursion vulnerability
net.minidev:json-smart: 2.5.0 → 2.5.2
Snowflake JDBC uses insecure temporary credential cache file permissions
Snowflake JDBC uses insecure temporary credential cache file permissions
net.snowflake:snowflake-jdbc: 3.6.8 → 3.22.0
Deep Java Library path traversal issue
Deep Java Library path traversal issue
ai.djl:api: before 0.31.1
Snowflake JDBC allows an untrusted search path on Windows
Snowflake JDBC allows an untrusted search path on Windows
net.snowflake:snowflake-jdbc: 3.2.3 → 3.22.0
Infinispan vulnerable to Insertion of Sensitive Information into Log File
Infinispan vulnerable to Insertion of Sensitive Information into Log File
org.infinispan:infinispan-parent: all versions
Apache Solr Relative Path Traversal vulnerability
Apache Solr Relative Path Traversal vulnerability
org.apache.solr:solr-core: 6.6 → 9.8.0
Apache Solr vulnerable to Execution with Unnecessary Privileges
Apache Solr vulnerable to Execution with Unnecessary Privileges
org.apache.solr:solr-core: before 9.8.0
Apache CXF: Denial of Service vulnerability with temporary files
Apache CXF: Denial of Service vulnerability with temporary files
org.apache.cxf:cxf-core: before 3.5.10
HAL Console has a Cross Site Scripting (XSS) vulnerability of user input
HAL Console has a Cross Site Scripting (XSS) vulnerability of user input
org.jboss.hal:hal-console: before 3.7.7.Final
Denial of Service in Keycloak Server via Security Headers
Denial of Service in Keycloak Server via Security Headers
org.keycloak:keycloak-quarkus-server: before 26.0.8
Keycloak allows unrestricted admin use of system and environment variables
Keycloak allows unrestricted admin use of system and environment variables
org.keycloak:keycloak-quarkus-server: before 26.0.8
Apache MINA Deserialization RCE Vulnerability
Apache MINA Deserialization RCE Vulnerability
org.apache.mina:mina-core: 2.2.0 → 2.2.4
Cross Site Scripting (XSS) vulnerability while uploading content to a new deployment
Cross Site Scripting (XSS) vulnerability while uploading content to a new deployment
org.jboss.hal:hal-console: before 3.7.7.Final
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.2
QOS.CH logback-core Expression Language Injection vulnerability
QOS.CH logback-core Expression Language Injection vulnerability
ch.qos.logback:logback-core: 1.4.0 → 1.5.13
QOS.CH logback-core Server-Side Request Forgery vulnerability
QOS.CH logback-core Server-Side Request Forgery vulnerability
ch.qos.logback:logback-core: 1.4.0 → 1.5.13
Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
org.apache.kafka:kafka_2.13: 0.10.2.0 → 3.7.2
Elasticsearch Incorrect Authorization vulnerability
Elasticsearch Incorrect Authorization vulnerability
org.elasticsearch:elasticsearch: 8.16.0 → 8.16.2
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.2
Welcome and About GeoServer pages communicate version and revision information
Welcome and About GeoServer pages communicate version and revision information
org.geoserver.web:gs-web-app: 2.0.0 → 2.25.1
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
io.quarkus.http:quarkus-http-core: before 5.3.4
Spring LDAP data exposure vulnerability
Spring LDAP data exposure vulnerability
org.springframework.ldap:spring-ldap-core: 3.0.0 → 3.2.8
Spring Framework has Authorization Bypass for Case Sensitive Comparisons
Spring Framework has Authorization Bypass for Case Sensitive Comparisons
org.springframework.security:spring-security-core: before 5.7.14
AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
org.asynchttpclient:async-http-client: 2.1.0 → 2.12.4
Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
org.keycloak:keycloak-quarkus-server: all versions
Keycloak Build Process Exposes Sensitive Data
Keycloak Build Process Exposes Sensitive Data
org.keycloak:keycloak-quarkus-server: before 24.0.9
Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
org.keycloak:keycloak-quarkus-server: before 26.0.6
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
org.keycloak:keycloak-core: before 26.0.6
org.keycloak:keycloak-services has Inefficient Regular Expression Complexity
org.keycloak:keycloak-services has Inefficient Regular Expression Complexity
org.keycloak:keycloak-services: before 24.0.9
Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
org.apache.kafka:kafka-clients: 2.3.0 → 3.7.1
Missing permission check in Jenkins Script Security Plugin
Missing permission check in Jenkins Script Security Plugin
org.jenkins-ci.plugins:script-security: before 1368.vb
Denial of Service attack on windows app using netty
Denial of Service attack on windows app using netty
io.netty:netty-common: before 4.1.115.Final
XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
com.thoughtworks.xstream:xstream: before 1.4.21
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.0-M21
Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
org.apache.zookeeper:zookeeper: 3.9.0 → 3.9.3
Snowflake JDBC Security Advisory
Snowflake JDBC Security Advisory
net.snowflake:snowflake-jdbc: 3.2.6 → 3.20.0
Apache NiFi Cross-site Scripting vulnerability
Apache NiFi Cross-site Scripting vulnerability
org.apache.nifi:nifi-web-ui: 1.10.0 → 1.28.0
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
org.springframework.security:spring-security-web: 5.0.0 → 5.7.13
Spring Framework DataBinder Case Sensitive Match Exception
Spring Framework DataBinder Case Sensitive Match Exception
org.springframework:spring-context: 6.1.0 → 6.1.14
Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect
Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect
org.keycloak:keycloak-services: before 22.0.13
Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak
Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak
org.keycloak:keycloak-saml-core: before 22.0.13
Eclipse Jetty has a denial of service vulnerability on DosFilter
Eclipse Jetty has a denial of service vulnerability on DosFilter
org.eclipse.jetty.ee10:jetty-ee10-servlets: 12.0.0 → 12.0.3
Eclipse Jetty URI parsing of invalid authority
Eclipse Jetty URI parsing of invalid authority
org.eclipse.jetty:jetty-http: 7.0.0 → 12.0.12
Keycloak has session fixation in Elytron SAML adapters
Keycloak has session fixation in Elytron SAML adapters
org.keycloak:keycloak-services: before 22.0.12
Keycloaks's One Time Passcode (OTP) is valid longer than expiration timeSeverity
Keycloaks's One Time Passcode (OTP) is valid longer than expiration timeSeverity
org.keycloak:keycloak-core: before 24.0.7
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
org.eclipse.jetty:jetty-server: 12.0.0 → 12.0.9
HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
org.jboss.resteasy:resteasy-netty4-cdi: all versions
JSON-lib mishandles an unbalanced comment string
JSON-lib mishandles an unbalanced comment string
org.kordamp.json:json-lib-core: before 3.1.0
Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
org.apache.avro:avro: before 1.11.4
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
commons-io:commons-io: 2.0 → 2.14.0
Jenkins exposes multi-line secrets through error messages
Jenkins exposes multi-line secrets through error messages
org.jenkins-ci.main:jenkins-core: before 2.462.3
Jenkins item creation restriction bypass vulnerability
Jenkins item creation restriction bypass vulnerability
org.jenkins-ci.main:jenkins-core: before 2.462.3
Apache Hadoop: Temporary File Local Information Disclosure
Apache Hadoop: Temporary File Local Information Disclosure
org.apache.hadoop:hadoop-common: before 3.4.0
Spring Framework DoS via conditional HTTP request
Spring Framework DoS via conditional HTTP request
org.springframework:spring-web: before 5.3.38
SOFA Hessian Remote Command Execution (RCE) Vulnerability
SOFA Hessian Remote Command Execution (RCE) Vulnerability
com.alipay.sofa:hessian: before 3.5.5
protobuf-java has potential Denial of Service issue
protobuf-java has potential Denial of Service issue
com.google.protobuf:protobuf-java: before 3.25.5
druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability
druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability
org.apache.druid.extensions:druid-pac4j: 0.18.0 → 30.0.1
Keycloak Services has a potential bypass of brute force protection
Keycloak Services has a potential bypass of brute force protection
org.keycloak:keycloak-services: before 22.0.12
OpenDaylight Authentication, Authorization and Accounting (AAA) peer impersonation vulnerability
OpenDaylight Authentication, Authorization and Accounting (AAA) peer impersonation vulnerability
org.opendaylight.aaa:aaa-artifacts: all versions
Path traversal vulnerability in functional web frameworks
Path traversal vulnerability in functional web frameworks
org.springframework:spring-webmvc: 6.1.0 → 6.1.13
Keycloak Denial of Service vulnerability
Keycloak Denial of Service vulnerability
org.keycloak:keycloak-core: before 24.0.0
Keycloak Open Redirect vulnerability
Keycloak Open Redirect vulnerability
org.keycloak:keycloak-core: before 24.0.7
Spring Framework vulnerable to Denial of Service
Spring Framework vulnerable to Denial of Service
org.springframework:spring-expression: before 5.3.39
Apache MINA SSHD: integrity check bypass
Apache MINA SSHD: integrity check bypass
org.apache.sshd:sshd-common: before 2.12.0
CometVisu Backend for openHAB affected by SSRF/XSS
CometVisu Backend for openHAB affected by SSRF/XSS
org.openhab.ui.bundles:org.openhab.ui.cometvisu: 3.4.0.M4 → 4.2.1
Jenkins does not perform a permission check in an HTTP endpoint
Jenkins does not perform a permission check in an HTTP endpoint
org.jenkins-ci.main:jenkins-core: before 2.452.4
Jenkins Remoting library arbitrary file read vulnerability
Jenkins Remoting library arbitrary file read vulnerability
org.jenkins-ci.main:remoting: before 3206.3208
Path traversal in Reposilite javadoc file expansion (arbitrary file creation/overwrite) (`GHSL-2024-073`)
Path traversal in Reposilite javadoc file expansion (arbitrary file creation/overwrite) (`GHSL-2024-073`)
com.reposilite:reposilite-backend: 3.3.0 → 3.5.12
Reposilite artifacts vulnerable to Stored Cross-site Scripting
Reposilite artifacts vulnerable to Stored Cross-site Scripting
com.reposilite:reposilite-backend: 3.3.0 → 3.5.12
Elasticsearch stores private key on disk unencrypted
Elasticsearch stores private key on disk unencrypted
org.elasticsearch:elasticsearch: 8.0.0-alpha1 → 8.13.0
GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service
GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service
com.graphql-java:graphql-java: before 19.11
OpenAM FreeMarker template injection
OpenAM FreeMarker template injection
org.openidentityplatform.openam:openam-oauth2: before 15.0.4
DNSJava DNSSEC Bypass
DNSJava DNSSEC Bypass
dnsjava:dnsjava: before 3.6.0
DNSJava affected by KeyTrap - NSEC3 closest encloser proof can exhaust CPU resources
DNSJava affected by KeyTrap - NSEC3 closest encloser proof can exhaust CPU resources
dnsjava:dnsjava: 3.5.0 → 3.6.0
DNSJava vulnerable to KeyTrap - Denial-of-Service Algorithmic Complexity Attacks
DNSJava vulnerable to KeyTrap - Denial-of-Service Algorithmic Complexity Attacks
dnsjava:dnsjava: 3.5.0 → 3.6.0
Absent Input Validation in BinaryHttpParser
Absent Input Validation in BinaryHttpParser
io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.13.Final
The OpenSearch reporting plugin improperly controls tenancy access to reporting resources
The OpenSearch reporting plugin improperly controls tenancy access to reporting resources
org.opensearch.plugin:opensearch-reports-scheduler: before 2.14.0.0
OpenSearch Observability does not properly restrict access to private tenant resources
OpenSearch Observability does not properly restrict access to private tenant resources
org.opensearch.plugin:opensearch-observability: before 2.14.0.0
Apache NiFi vulnerable to Cross-site Scripting
Apache NiFi vulnerable to Cross-site Scripting
org.apache.nifi:nifi-web-ui: 1.10.0 → 1.27.0
Apache Tomcat - Denial of Service
Apache Tomcat - Denial of Service
org.apache.tomcat.embed:tomcat-embed-core: 11.0.0-M1 → 11.0.0-M21
GeoServer's Server Status shows sensitive environmental variables and Java properties
GeoServer's Server Status shows sensitive environmental variables and Java properties
org.geoserver.web:gs-web-app: 2.10.0 → 2.24.4
Exposure of secrets through system log in Jenkins Structs Plugin
Exposure of secrets through system log in Jenkins Structs Plugin
org.jenkins-ci.plugins:structs: before 338.v848422169819
DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document
DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document
org.dspace:dspace-server-webapp: 7.0 → 7.6.2
Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java
Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java
org.cyclonedx:cyclonedx-core-java: 2.1.0 → 9.0.4
XWiki programming rights may be inherited by inclusion
XWiki programming rights may be inherited by inclusion
org.xwiki.platform:xwiki-platform-rendering-macro-include: before 15.0-rc-1
Keycloak leaks configured LDAP bind credentials through the Keycloak admin console
Keycloak leaks configured LDAP bind credentials through the Keycloak admin console
org.keycloak:keycloak-ldap-federation: 25.0.0 → 25.0.1
ClassGraph XML External Entity Reference
ClassGraph XML External Entity Reference
io.github.classgraph:classgraph: before 4.8.112
XWiki Platform allows remote code execution from user account
XWiki Platform allows remote code execution from user account
org.xwiki.platform:xwiki-platform-oldcore: 13.4.7 → 14.10.21
DeepJavaLibrary API absolute path traversal
DeepJavaLibrary API absolute path traversal
ai.djl:api: 0.1.0 → 0.28.0
CrateDB has a Client initialized Session-Renegotiation DoS
CrateDB has a Client initialized Session-Renegotiation DoS
io.crate:crate: before 5.7.2
Elasticsearch StackOverflow vulnerability
Elasticsearch StackOverflow vulnerability
org.elasticsearch:elasticsearch: 8.13.1 → 8.14.0
Keycloak's admin API allows low privilege users to use administrative functions
Keycloak's admin API allows low privilege users to use administrative functions
org.keycloak:keycloak-services: before 24.0.5
Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
org.keycloak:keycloak-services: before 24.0.5
BoringSSLAEADContext in Netty Repeats Nonces
BoringSSLAEADContext in Netty Repeats Nonces
io.netty.incubator:netty-incubator-codec-ohttp: 0.0.3.Final → 0.0.11.Final
iq80 Snappy out-of-bounds read when uncompressing data, leading to JVM crash
iq80 Snappy out-of-bounds read when uncompressing data, leading to JVM crash
org.iq80.snappy:snappy: before 0.5
Decompressors can crash the JVM and leak memory content in Aircompressor
Decompressors can crash the JVM and leak memory content in Aircompressor
io.airlift:aircompressor: before 0.27
OpenAPI Generator Online - Arbitrary File Read/Delete
OpenAPI Generator Online - Arbitrary File Read/Delete
org.openapitools:openapi-generator-online: before 7.6.0
Amazon JDBC Driver for Redshift SQL Injection via line comment generation
Amazon JDBC Driver for Redshift SQL Injection via line comment generation
com.amazon.redshift:redshift-jdbc42: before 2.1.0.28
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
org.bouncycastle:bcprov-jdk18on: before 1.78
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
org.bouncycastle:bctls-fips: before 1.0.19
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
org.bouncycastle:bcprov-jdk18on: 1.73 → 1.78
Neo4j Cypher component mishandles IMMUTABLE privileges
Neo4j Cypher component mishandles IMMUTABLE privileges
org.neo4j:neo4j-cypher: 5.0.0 → 5.19.0
Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
org.bouncycastle:bcprov-jdk18on: 1.61 → 1.78
Jenkins Script Security Plugin sandbox bypass vulnerability
Jenkins Script Security Plugin sandbox bypass vulnerability
org.jenkins-ci.plugins:script-security: before 1336.vf33a
Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
org.jenkins-ci.plugins:script-security: before 1336.vf33a
OpenMetadata vulnerable to a SpEL Injection in `PUT /api/v1/events/subscriptions` (`GHSL-2023-251`)
OpenMetadata vulnerable to a SpEL Injection in `PUT /api/v1/events/subscriptions` (`GHSL-2023-251`)
org.open-metadata:openmetadata-service: before 1.2.4
OpenMetadata vulnerable to a SpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` (`GHSL-2023-236`)
OpenMetadata vulnerable to a SpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` (`GHSL-2023-236`)
org.open-metadata:openmetadata-service: before 1.2.4
OpenMetadata vulnerable to SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)
OpenMetadata vulnerable to SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)
org.open-metadata:openmetadata-service: before 1.3.1
Ant Media Server vulnerable to a local privilege escalation
Ant Media Server vulnerable to a local privilege escalation
io.antmedia:ant-media-server: 2.6.0 → 2.9.0
Keycloak Authorization Bypass vulnerability
Keycloak Authorization Bypass vulnerability
org.keycloak:keycloak-services: before 22.0.10
Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flow
Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flow
org.keycloak:keycloak-services: before 22.0.10
Keycloak path traversal vulnerability in redirection validation
Keycloak path traversal vulnerability in redirection validation
org.keycloak:keycloak-services: before 22.0.10
Keycloak vulnerable to session hijacking via re-authentication
Keycloak vulnerable to session hijacking via re-authentication
org.keycloak:keycloak-services: before 22.0.10
Keycloak path traversal vulnerability in the redirect validation
Keycloak path traversal vulnerability in the redirect validation
org.keycloak:keycloak-services: before 22.0.10
Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS
Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS
org.keycloak:keycloak-services: before 22.0.10
Keycloak vulnerable to impersonation via logout token exchange
Keycloak vulnerable to impersonation via logout token exchange
org.keycloak:keycloak-services: before 22.0.10
Keycloak secondary factor bypass in step-up authentication
Keycloak secondary factor bypass in step-up authentication
org.keycloak:keycloak-services: before 22.0.10
Spring Framework URL Parsing with Host Validation
Spring Framework URL Parsing with Host Validation
org.springframework:spring-web: before 5.3.34
Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode
Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode
org.apache.kafka:kafka-metadata: 3.5.0 → 3.6.2
XWiki Platform: Remote code execution through space title and Solr space facet
XWiki Platform: Remote code execution through space title and Solr space facet
org.xwiki.platform:xwiki-platform-search-solr-ui: 7.2-rc-1 → 14.10.20
WildFly Elytron: OIDC app attempting to access the second tenant, the user should be prompted to log
WildFly Elytron: OIDC app attempting to access the second tenant, the user should be prompted to log
org.wildfly.security:wildfly-elytron-http-oidc: before 2.2.5.Final
XWiki Platform remote code execution from account via custom skins support
XWiki Platform remote code execution from account via custom skins support
org.xwiki.platform:xwiki-platform-oldcore: 6.4-milestone-1 → 14.10.19
XWiki Platform CSRF in the job scheduler
XWiki Platform CSRF in the job scheduler
org.xwiki.platform:xwiki-platform-scheduler-ui: 3.1 → 14.10.19
XWiki Platform: Privilege escalation (PR) from user registration through PDFClass
XWiki Platform: Privilege escalation (PR) from user registration through PDFClass
org.xwiki.platform:xwiki-platform-oldcore: 3.0.1 → 14.10.20
XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution
XWiki Commons missing escaping of `{` in Velocity escapetool allows remote code execution
org.xwiki.commons:xwiki-commons-velocity: 3.0.1 → 14.10.19
XWiki Platform CSRF remote code execution through the realtime HTML Converter API
XWiki Platform CSRF remote code execution through the realtime HTML Converter API
org.xwiki.platform:xwiki-platform-realtime-ui: 13.9-rc-1 → 14.10.19
XWiki Platform CSRF remote code execution through scheduler job's document reference
XWiki Platform CSRF remote code execution through scheduler job's document reference
org.xwiki.platform:xwiki-platform-scheduler-ui: 3.1 → 14.10.19
XWiki Platform: Remote code execution from account via SearchSuggestSourceSheet
XWiki Platform: Remote code execution from account via SearchSuggestSourceSheet
org.xwiki.platform:xwiki-platform-search-ui: 5.2-milestone-2 → 14.10.20
XWiki Platform: Remote code execution from edit in multilingual wikis via translations
XWiki Platform: Remote code execution from edit in multilingual wikis via translations
org.xwiki.platform:xwiki-platform-localization-source-wiki: 4.3-milestone-2 → 14.10.20
XWiki Platform remote code execution from account through UIExtension parameters
XWiki Platform remote code execution from account through UIExtension parameters
org.xwiki.platform:xwiki-platform-uiextension-api: before 14.10.19
XWiki Platform: Remote code execution as guest via DatabaseSearch
XWiki Platform: Remote code execution as guest via DatabaseSearch
org.xwiki.platform:xwiki-platform-search-ui: 2.4-milestone-1 → 14.10.20
XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted
XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted
org.xwiki.platform:xwiki-platform-oldcore: 5.0-rc-1 → 14.10.19
WildFly Elytron: SSRF security issue
WildFly Elytron: SSRF security issue
org.wildfly.security:wildfly-elytron-realm-token: all versions
quarkus-core leaks local environment variables from Quarkus namespace during application's build
quarkus-core leaks local environment variables from Quarkus namespace during application's build
io.quarkus:quarkus-core: 3.9.0.CR1 → 3.9.2
Elasticsearch Uncontrolled Resource Consumption vulnerability
Elasticsearch Uncontrolled Resource Consumption vulnerability
org.elasticsearch:elasticsearch: 7.0.0 → 7.17.19
Elasticsearch Incorrect Authorization vulnerability
Elasticsearch Incorrect Authorization vulnerability
org.elasticsearch:elasticsearch: 8.10.0 → 8.13.0
Netty's HttpPostRequestDecoder can OOM
Netty's HttpPostRequestDecoder can OOM
io.netty:netty-codec-http: before 4.1.108.Final
XNIO denial of service vulnerability
XNIO denial of service vulnerability
org.jboss.xnio:xnio-api: before 3.8.14.Final
Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
org.apache.commons:commons-configuration2: 2.0 → 2.10.1
Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
org.apache.commons:commons-configuration2: 2.0 → 2.10.1
GeoServer's Simple SVG Renderer vulnerable to Stored Cross-Site Scripting (XSS)
GeoServer's Simple SVG Renderer vulnerable to Stored Cross-Site Scripting (XSS)
org.geoserver:gs-wms: before 2.23.4
GeoServer's MapML HTML Page vulnerable to Stored Cross-Site Scripting (XSS)
GeoServer's MapML HTML Page vulnerable to Stored Cross-Site Scripting (XSS)
org.geoserver.extension:gs-mapml: before 2.23.4
GeoServer's GWC Demos Page vulnerable to Stored Cross-Site Scripting (XSS)
GeoServer's GWC Demos Page vulnerable to Stored Cross-Site Scripting (XSS)
org.geoserver:gs-gwc: 2.24.0 → 2.24.1
GeoServer Arbitrary file renaming vulnerability in REST Coverage/Data Store API
GeoServer Arbitrary file renaming vulnerability in REST Coverage/Data Store API
org.geoserver:gs-restconfig: before 2.23.5
GeoServer's Style Publisher vulnerable to Stored Cross-Site Scripting (XSS)
GeoServer's Style Publisher vulnerable to Stored Cross-Site Scripting (XSS)
org.geoserver:gs-main: before 2.23.3
GeoServer's GWC Seed Form vulnerable to Stored Cross-Site Scripting (XSS)
GeoServer's GWC Seed Form vulnerable to Stored Cross-Site Scripting (XSS)
org.geoserver:gs-gwc-rest: before 2.23.2
GeoServer's WMS OpenLayers Format vulnerable to Stored Cross-Site Scripting (XSS)
GeoServer's WMS OpenLayers Format vulnerable to Stored Cross-Site Scripting (XSS)
org.geoserver:gs-wms: before 2.23.3
Erroneous authentication pass in Spring Security
Erroneous authentication pass in Spring Security
org.springframework.security:spring-security-core: before 5.7.12
Spring Framework URL Parsing with Host Validation Vulnerability
Spring Framework URL Parsing with Host Validation Vulnerability
org.springframework:spring-web: 6.1.0 → 6.1.5
Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling
Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling
org.apache.zookeeper:zookeeper: 3.8.0 → 3.8.4
SSRF vulnerability using the Aegis DataBinding in Apache CXF
SSRF vulnerability using the Aegis DataBinding in Apache CXF
org.apache.cxf:cxf-rt-databinding-aegis: before 3.5.8
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.0-M17
In Quarkus, git credentials could be inadvertently published
In Quarkus, git credentials could be inadvertently published
io.quarkus:quarkus-kubernetes-deployment: before 3.7.3
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
org.apache.tomcat:tomcat-websocket: 11.0.0-M1 → 11.0.0-M17
Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
Reading specially crafted serializable objects from an untrusted source may cause an infinite loop and denial of service
org.clojure:clojure: 1.7.0 → 1.11.2
jose4j denial of service via specifically crafted JWE
jose4j denial of service via specifically crafted JWE
org.bitbucket.b_c:jose4j: before 0.9.4
Apache James MIME4J improper input validation vulnerability
Apache James MIME4J improper input validation vulnerability
org.apache.james:apache-mime4j-core: before 0.8.10
Connection leaking on idle timeout when TCP congested
Connection leaking on idle timeout when TCP congested
org.eclipse.jetty.http2:http2-common: 9.3.0 → 9.4.54
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
org.springframework:spring-web: 6.1.0 → 6.1.4
Cross-site Scripting Vulnerability in Statement Browser
Cross-site Scripting Vulnerability in Statement Browser
com.yetanalytics:lrs: before 1.2.17
XWiki extension license information is public, exposing instance id and license holder details
XWiki extension license information is public, exposing instance id and license holder details
com.xwiki.licensing:application-licensing-licensor-ui: 1.0 → 1.24.2
org.postgresql:postgresql vulnerable to SQL Injection via line comment generation
org.postgresql:postgresql vulnerable to SQL Injection via line comment generation
org.postgresql:postgresql: before 42.2.28
Liferay Portal defaults to a low work factor for the default password hashing algorithm
Liferay Portal defaults to a low work factor for the default password hashing algorithm
com.liferay.portal:release.dxp.bom: 7.3.0 → 7.3.10.u4
Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)
Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)
com.liferay.portal:release.portal.bom: before 7.4.3.13
Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
org.apache.commons:commons-compress: 1.3 → 1.26.0
Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file
Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file
org.apache.commons:commons-compress: 1.21 → 1.26.0
Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project
Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project
org.openjfx:javafx-media: before 17.0.10
Absolute path traversal vulnerability in digdag server
Absolute path traversal vulnerability in digdag server
io.digdag:digdag-server: before 0.10.5.1
OpenRefine JDBC Attack Vulnerability
OpenRefine JDBC Attack Vulnerability
org.openrefine:database: before 3.7.8
Denial of Service in Connect2id Nimbus JOSE+JWT
Denial of Service in Connect2id Nimbus JOSE+JWT
com.nimbusds:nimbus-jose-jwt: before 9.37.2
Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
org.apache.solr:solr-solrj-streaming: 9.0.0 → 9.4.1
Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
org.apache.solr:solr-core: 6.0.0 → 8.11.3
Micronaut management endpoints vulnerable to drive-by localhost attack
Micronaut management endpoints vulnerable to drive-by localhost attack
io.micronaut:micronaut-http-server: before 3.8.3
Graylog session fixation vulnerability through cookie injection
Graylog session fixation vulnerability through cookie injection
org.graylog2:graylog2-server: 4.3.0 → 5.1.11
Graylog vulnerable to instantiation of arbitrary classes triggered by API request
Graylog vulnerable to instantiation of arbitrary classes triggered by API request
org.graylog2:graylog2-server: 2.0.0 → 5.1.11
Malicious input can provoke XSS when preserving comments
Malicious input can provoke XSS when preserving comments
org.owasp.antisamy:antisamy: before 1.7.5
CrateDB database has an arbitrary file read vulnerability
CrateDB database has an arbitrary file read vulnerability
io.crate:crate: before 5.3.9
Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
org.jenkins-ci.main:jenkins-core: 1.606 → 2.426.3
Path traversal vulnerability in Jenkins Matrix Project Plugin
Path traversal vulnerability in Jenkins Matrix Project Plugin
org.jenkins-ci.plugins:matrix-project: before 822.824.v14451b
Cross-site WebSocket hijacking vulnerability in the Jenkins CLI
Cross-site WebSocket hijacking vulnerability in the Jenkins CLI
org.jenkins-ci.main:jenkins-core: 2.217 → 2.426.3
keycloak-core: open redirect via "form_post.jwt" JARM response mode
keycloak-core: open redirect via "form_post.jwt" JARM response mode
org.keycloak:keycloak-core: before 23.0.4
Remote Command Execution in SOFARPC
Remote Command Execution in SOFARPC
com.alipay.sofa:rpc-sofa-boot-starter: before 5.12.0
Spring Framework server Web DoS Vulnerability
Spring Framework server Web DoS Vulnerability
org.springframework:spring-core: 6.1.2 → 6.1.3
XWiki Remote Code Execution Vulnerability via User Registration
XWiki Remote Code Execution Vulnerability via User Registration
org.xwiki.platform:xwiki-platform-administration-ui: 2.2 → 14.10.17
XWiki vulnerable to Denial of Service attack through attachments
XWiki vulnerable to Denial of Service attack through attachments
org.xwiki.platform:xwiki-platform-distribution-war: 14.10 → 14.10.18
XWiki has no right protection on rollback action
XWiki has no right protection on rollback action
org.xwiki.platform:xwiki-platform-oldcore: 1.0 → 14.10.17
Ion Java StackOverflow vulnerability
Ion Java StackOverflow vulnerability
com.amazon.ion:ion-java: before 1.10.5
Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
org.infinispan:infinispan-server-rest: 15.0.0.Dev01 → 15.0.0.Dev04
Infinispan REST Server's bulk read endpoints do not properly evaluate user permissions
Infinispan REST Server's bulk read endpoints do not properly evaluate user permissions
org.infinispan:infinispan-server-rest: 15.0.0.Dev01 → 15.0.0.Dev04
Infinispan circular object references causes out of memory errors
Infinispan circular object references causes out of memory errors
org.infinispan.protostream:protostream: before 4.6.2.Final
Infinispan caches credentials in clear text
Infinispan caches credentials in clear text
org.infinispan:infinispan-core: 15.0.0.Dev01 → 15.0.0.Dev07
json-path Out-of-bounds Write vulnerability
json-path Out-of-bounds Write vulnerability
com.jayway.jsonpath:json-path: 2.2.0 → 2.9.0
Grails data binding causes JVM crash and/or other denial of service
Grails data binding causes JVM crash and/or other denial of service
org.grails:grails-databinding: 6.0.0 → 6.1.0
Velocity execution without script right through tree macro
Velocity execution without script right through tree macro
org.xwiki.platform:xwiki-platform-index-tree-macro: 8.3-rc-1 → 14.10.7
Remote code execution/programming rights with configuration section from any user account
Remote code execution/programming rights with configuration section from any user account
org.xwiki.platform:xwiki-platform-administration-ui: 2.3 → 14.10.15
Solr search discloses email addresses of users
Solr search discloses email addresses of users
org.xwiki.platform:xwiki-platform-search-solr-api: before 14.10.15
Remote code execution from account through SearchAdmin
Remote code execution from account through SearchAdmin
org.xwiki.platform:xwiki-platform-search-ui: 4.5-rc-1 → 14.10.15
Solr search discloses password hashes of all users
Solr search discloses password hashes of all users
org.xwiki.platform:xwiki-platform-search-solr-api: 7.2-milestone-2 → 14.10.15
Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability
Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability
org.sonatype.nexus.ci:nexus-jenkins-plugin: before 3.18.1-01
Jenkins Nexus Platform Plugin missing permission check
Jenkins Nexus Platform Plugin missing permission check
org.sonatype.nexus.ci:nexus-jenkins-plugin: before 3.18.1-01
Jenkins Nexus Platform Plugin missing permission check
Jenkins Nexus Platform Plugin missing permission check
org.sonatype.nexus.ci:nexus-jenkins-plugin: before 3.18.1-01
Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability
Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability
org.sonatype.nexus.ci:nexus-jenkins-plugin: before 3.18.1-01
Data leak of password hash through change requests
Data leak of password hash through change requests
org.xwiki.contrib.changerequest:application-changerequest-default: 0.1 → 1.10
Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data
ch.qos.logback:logback-core: 1.4.13 → 1.4.14
HtmlUnit vulnerable to Remote Code Execution (RCE) via XSTL
HtmlUnit vulnerable to Remote Code Execution (RCE) via XSTL
org.htmlunit:htmlunit: before 3.9.0
Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download
Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download
io.github.microcks:microcks: before 1.17.1
logback serialization vulnerability
logback serialization vulnerability
ch.qos.logback:logback-classic: 1.3.0 → 1.3.12
Reactor Netty HTTP Server denial of service vulnerability
Reactor Netty HTTP Server denial of service vulnerability
io.projectreactor.netty:reactor-netty-core: 1.1.0 → 1.1.13
Apache Tomcat Improper Input Validation vulnerability
Apache Tomcat Improper Input Validation vulnerability
org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.0-M11
Bouncy Castle Denial of Service (DoS)
Bouncy Castle Denial of Service (DoS)
org.bouncycastle:bcprov-ext-jdk16: before 1.73
Whole content of all documents of all wikis exposed to anybody with view right on Solr suggest service
Whole content of all documents of all wikis exposed to anybody with view right on Solr suggest service
org.xwiki.platform:xwiki-platform-search-solr-query: 6.3-milestone-2 → 14.10.15
Apache Derby: LDAP injection vulnerability in authenticator
Apache Derby: LDAP injection vulnerability in authenticator
org.apache.derby:derby: ≥ 10.1.1.0
Cookies are sent to external images in rendered diff (and server side request forgery)
Cookies are sent to external images in rendered diff (and server side request forgery)
org.xwiki.platform:xwiki-platform-diff-xml: 11.10.1 → 14.10.15
Cross-Site Request Forgery with QueryOnXWiki allows arbitrary database queries
Cross-Site Request Forgery with QueryOnXWiki allows arbitrary database queries
org.xwiki.contrib:xwiki-application-admintools: before 4.5.1
Authenticated Rundeck users can view or delete jobs they do not have authorization for.
Authenticated Rundeck users can view or delete jobs they do not have authorization for.
org.rundeck:rundeck: 4.12.0 → 4.17.3
Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain
Quarkus does not properly sanitize artifacts created from its use of the Gradle plugin, allowing certain build system information to remain
io.quarkus:quarkus-project: ≥ 3.0.0.CR1
In Reactor Netty HTTP Server a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack
In Reactor Netty HTTP Server a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack
io.projectreactor.netty:reactor-netty-http: 1.1.0 → 1.1.13
Java: DoS Vulnerability in JSON-JAVA
Java: DoS Vulnerability in JSON-JAVA
org.json:json: before 20231013
XWiki Platform vulnerable to remote code execution through the section parameter in Administration as guest
XWiki Platform vulnerable to remote code execution through the section parameter in Administration as guest
org.xwiki.platform:xwiki-platform-administration-ui: before 14.10.14
XWiki Platform privilege escalation from script right to programming right through title displayer
XWiki Platform privilege escalation from script right to programming right through title displayer
org.xwiki.platform:xwiki-platform-display-api: 3.2-milestone-3 → 14.10.7
Elasticsearch vulnerable to Uncontrolled Resource Consumption
Elasticsearch vulnerable to Uncontrolled Resource Consumption
org.elasticsearch:elasticsearch: before 7.17.13
jose4j uses weak cryptographic algorithm
jose4j uses weak cryptographic algorithm
org.bitbucket.b_c:jose4j: before 0.9.3
org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converter
org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converter
org.xwiki.platform:xwiki-platform-office-importer: 3.5-milestone-1 → 14.10.8
XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro
XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro
org.xwiki.rendering:xwiki-rendering-macro-footnotes: before 14.10.6
org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Move
org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Move
org.xwiki.platform:xwiki-platform-attachment-api: 14.0-rc-1 → 14.4.8
XWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabled
XWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabled
org.xwiki.platform:xwiki-platform-web-templates: 12.0-rc-1 → 14.10.12
Privilege escalation (PR)/remote code execution from account through Menu.UIExtensionSheet
Privilege escalation (PR)/remote code execution from account through Menu.UIExtensionSheet
org.xwiki.platform:xwiki-platform-menu: 5.1-rc-1 → 14.10.8
WPS Server Side Request Forgery vulnerability
WPS Server Side Request Forgery vulnerability
org.geoserver.extension:gs-wps-core: before 2.22.5
RabbitMQ Java client's Lack of Message Size Limitation leads to Remote DoS Attack
RabbitMQ Java client's Lack of Message Size Limitation leads to Remote DoS Attack
com.rabbitmq:amqp-client: before 5.18.0
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
org.apache.santuario:xmlsec: 2.3.0 → 2.3.4
MySQL Connectors takeover vulnerability
MySQL Connectors takeover vulnerability
com.mysql:mysql-connector-j: before 8.2.0
OpenSearch Issue with tenant read-only permissions
OpenSearch Issue with tenant read-only permissions
org.opensearch.plugin:opensearch-security: 2.0.0.0 → 2.11.0.0
WebAuthn4J Spring Security Improper signature counter value handling
WebAuthn4J Spring Security Improper signature counter value handling
com.webauthn4j:webauthn4j-spring-security-core: before 0.9.1.RELEASE
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
org.apache.zookeeper:zookeeper: before 3.7.2
Denial of service vulnerability on creating a Launch with too many recursively nested elements in reportportal
Denial of service vulnerability on creating a Launch with too many recursively nested elements in reportportal
com.epam.reportportal:service-api: before 5.10.0
io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack
io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack
io.netty:netty-codec-http2: before 4.1.100.Final
HTTP/2 HPACK integer overflow and buffer allocation
HTTP/2 HPACK integer overflow and buffer allocation
org.eclipse.jetty.http2:http2-hpack: 10.0.0 → 10.0.16
mXSS in AntiSamy
mXSS in AntiSamy
org.owasp.antisamy:antisamy: before 1.7.4
io.micronaut.security:micronaut-security-oauth2 has invalid IdTokenClaimsValidator logic on aud
io.micronaut.security:micronaut-security-oauth2 has invalid IdTokenClaimsValidator logic on aud
io.micronaut.security:micronaut-security-oauth2: 3.11.0 → 3.11.1
Apache Avro Java SDK vulnerable to Improper Input Validation
Apache Avro Java SDK vulnerable to Improper Input Validation
org.apache.avro:avro: before 1.11.3
snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact
snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact
org.xerial.snappy:snappy-java: before 1.1.10.4
Arbitrary File Overwrite in Eclipse JGit
Arbitrary File Overwrite in Eclipse JGit
org.eclipse.jgit:org.eclipse.jgit: 6.0.0.202111291000-r → 6.6.1.202309021850-r
Jetty's OpenId Revoked authentication allows one request
Jetty's OpenId Revoked authentication allows one request
org.eclipse.jetty:jetty-openid: 9.4.21 → 9.4.52.v20230823
Jetty accepts "+" prefixed value in Content-Length
Jetty accepts "+" prefixed value in Content-Length
org.eclipse.jetty:jetty-http: 9.0.0 → 9.4.52
Jetty vulnerable to errant command quoting in CGI Servlet
Jetty vulnerable to errant command quoting in CGI Servlet
org.eclipse.jetty:jetty-servlets: 9.0.0 → 9.4.52
Apache Commons Compress denial of service vulnerability
Apache Commons Compress denial of service vulnerability
org.apache.commons:commons-compress: 1.22 → 1.24.0
OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
org.openrefine:database: before 3.7.5
OpenRefine Remote Code execution in project import with mysql jdbc url attack
OpenRefine Remote Code execution in project import with mysql jdbc url attack
org.openrefine:database: before 3.7.5
Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes
Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes
org.wiremock:wiremock-standalone: before 3.0.3
Velocity execution without script right through VelocityCode and VelocityWiki property
Velocity execution without script right through VelocityCode and VelocityWiki property
org.xwiki.platform:xwiki-platform-oldcore: 7.2 → 14.10.10
DDFFileParser is vulnerable to XXE Attacks
DDFFileParser is vulnerable to XXE Attacks
org.eclipse.leshan:leshan-core: before 1.5.0
Apache Tomcat Open Redirect vulnerability
Apache Tomcat Open Redirect vulnerability
org.apache.tomcat:tomcat: 11.0.0-M1 → 11.0.0-M11
XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action
XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action
org.xwiki.platform:xwiki-platform-oldcore: 3.2-milestone-3 → 14.10.9
XWiki Platform privilege escalation (PR) from account through AWM content fields
XWiki Platform privilege escalation (PR) from account through AWM content fields
org.xwiki.platform:xwiki-platform-appwithinminutes-ui: 4.3-milestone-2 → 14.10.5
Apache Ivy External Entity Reference vulnerability
Apache Ivy External Entity Reference vulnerability
org.apache.ivy:ivy: before 2.5.2
XWiki Platform privilege escalation (PR)/RCE from account through Invitation subject/message
XWiki Platform privilege escalation (PR)/RCE from account through Invitation subject/message
org.xwiki.platform:xwiki-platform-invitation-ui: 2.5-m-1 → 14.4.8
Jenkins Delphix Plugin vulnerable to exposure of system-scoped credentials
Jenkins Delphix Plugin vulnerable to exposure of system-scoped credentials
org.jenkins-ci.plugins:delphix: before 3.0.3
Jenkins Delphix Plugin missing permission check
Jenkins Delphix Plugin missing permission check
org.jenkins-ci.plugins:delphix: before 3.0.3
Deserialization vulnerability in Helix workflow and REST
Deserialization vulnerability in Helix workflow and REST
org.apache.helix:helix-core: before 1.3.0
Incorrect control flow in Jenkins Gradle Plugin breaks credentials masking in the build log
Incorrect control flow in Jenkins Gradle Plugin breaks credentials masking in the build log
org.jenkins-ci.plugins:gradle: before 2.8.1
Arbitrary File Creation in AbstractUnArchiver
Arbitrary File Creation in AbstractUnArchiver
org.codehaus.plexus:plexus-archiver: before 4.8.0
Paths contain matrix variables bypass decorators
Paths contain matrix variables bypass decorators
com.linecorp.armeria:armeria: before 1.24.3
OpenAM vulnerable to user impersonation using SAMLv1.x SSO process
OpenAM vulnerable to user impersonation using SAMLv1.x SSO process
org.openidentityplatform.openam:openam-federation-library: before 14.7.3
OpenRefine vulnerable to zip slip in project import
OpenRefine vulnerable to zip slip in project import
org.openrefine:main: before 3.7.4
Okio Signed to Unsigned Conversion Error vulnerability
Okio Signed to Unsigned Conversion Error vulnerability
com.squareup.okio:okio: 2.0.0-RC1 → 3.4.0
Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
org.eclipse.jetty:jetty-xml: 10.0.0-alpha0 → 10.0.16
XWiki Platform vulnerable to cross-site request forgery (CSRF) via the REST API
XWiki Platform vulnerable to cross-site request forgery (CSRF) via the REST API
org.xwiki.platform:xwiki-platform-rest-server: 1.8 → 14.10.8
Apache MINA SSHD information disclosure vulnerability
Apache MINA SSHD information disclosure vulnerability
org.apache.sshd:sshd-common: 2.1.0 → 2.9.3
Graylog user session is still usable after logout
Graylog user session is still usable after logout
org.graylog2:graylog2-server: 1.0 → 5.0.9
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
org.apache.cassandra:cassandra-all: 4.1.0 → 4.1.2
Apache InLong has Weak Password Requirements in Apache InLong
Apache InLong has Weak Password Requirements in Apache InLong
org.apache.inlong:manager-pojo: 1.1.0 → 1.47.0
gRPC connection termination issue
gRPC connection termination issue
io.grpc:grpc-protobuf: 1.53.0 → 1.53.1
Graylog server has partial path traversal vulnerability in Support Bundle feature
Graylog server has partial path traversal vulnerability in Support Bundle feature
org.graylog2:graylog2-server: 5.1.0 → 5.1.3
gRPC Reachable Assertion issue
gRPC Reachable Assertion issue
io.grpc:grpc-protobuf: 1.51.0 → 1.53.0
Bouncy Castle For Java LDAP injection vulnerability
Bouncy Castle For Java LDAP injection vulnerability
org.bouncycastle:bcprov-jdk18on: before 1.74
Connection confusion in gRPC
Connection confusion in gRPC
io.grpc:grpc-protobuf: 1.53.0 → 1.53.1
org.xwiki.commons:xwiki-commons-xml's HTML sanitizer allows form elements in restricted
org.xwiki.commons:xwiki-commons-xml's HTML sanitizer allows form elements in restricted
org.xwiki.commons:xwiki-commons-xml: 14.6-rc-1 → 14.10.6
XWiki Platform vulnerable to persistent Cross-site Scripting through CKEditor Configuration pages
XWiki Platform vulnerable to persistent Cross-site Scripting through CKEditor Configuration pages
org.xwiki.platform:xwiki-platform-ckeditor-ui: 14.6-rc-1 → 14.10.6
Remote Code Execution for 2.4.1 and earlier
Remote Code Execution for 2.4.1 and earlier
net.opentsdb:opentsdb: before 2.4.2
XWiki Platform vulnerable to reflected cross-site scripting via delattachment action
XWiki Platform vulnerable to reflected cross-site scripting via delattachment action
org.xwiki.platform:xwiki-platform-oldcore: 3.2-milestone-3 → 14.10.6
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template
org.xwiki.platform:xwiki-platform-flamingo-skin-resources: 9.4-rc-1 → 14.10.5
FastAsyncWorldEdit vulnerable to Uncontrolled Resource Consumption
FastAsyncWorldEdit vulnerable to Uncontrolled Resource Consumption
com.fastasyncworldedit:FastAsyncWorldEdit-Core: before 2.6.3
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template
org.xwiki.platform:xwiki-platform-web-templates: 3.4-milestone-1 → 14.10.5
XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template
XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template
org.xwiki.platform:xwiki-platform-web-templates: 2.5-milestone-2 → 14.10.5
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template
org.xwiki.platform:xwiki-platform-flamingo-skin-resources: 6.0-rc-1 → 14.10.6
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication page
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication page
org.xwiki.platform:xwiki-platform-appwithinminutes-ui: 6.2-milestone-1 → 14.10.5
XWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResults
XWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResults
org.xwiki.platform:xwiki-platform-like-ui: 12.9-rc-1 → 14.4.8
XWiki Platform's tags on non-viewable pages can be revealed to users
XWiki Platform's tags on non-viewable pages can be revealed to users
org.xwiki.platform:xwiki-platform-tag-api: 5.0-milestone-1 → 14.4.8
XWiki Platform vulnerable to cross-site scripting via xcontinue parameter in previewactions template
XWiki Platform vulnerable to cross-site scripting via xcontinue parameter in previewactions template
org.xwiki.platform:xwiki-platform-flamingo-skin-resources: 6.1-rc-1 → 14.10.5
XWiki Platform may retrieve email addresses of all users
XWiki Platform may retrieve email addresses of all users
org.xwiki.platform:xwiki-platform-livetable-ui: 3.5-milestone-1 → 14.4.8
XWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parameters
XWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parameters
org.xwiki.platform:xwiki-platform-appwithinminutes-ui: 5.4.4 → 14.4.8
XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application
XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation application
org.xwiki.platform:xwiki-platform-invitation-ui: 2.4-m-2 → 14.4.8
netty-handler SniHandler 16MB allocation
netty-handler SniHandler 16MB allocation
io.netty:netty-handler: before 4.1.94.Final
snappy-java's Integer Overflow vulnerability in shuffle leads to DoS
snappy-java's Integer Overflow vulnerability in shuffle leads to DoS
org.xerial.snappy:snappy-java: before 1.1.10.1
snappy-java's unchecked chunk length leads to DoS
snappy-java's unchecked chunk length leads to DoS
org.xerial.snappy:snappy-java: before 1.1.10.1
snappy-java's Integer Overflow vulnerability in compress leads to DoS
snappy-java's Integer Overflow vulnerability in compress leads to DoS
org.xerial.snappy:snappy-java: before 1.1.10.1
Guava vulnerable to insecure use of temporary directory
Guava vulnerable to insecure use of temporary directory
com.google.guava:guava: 1.0 → 32.0.0-android
hjson stack exhaustion vulnerability
hjson stack exhaustion vulnerability
org.hjson:hjson: before 3.0.1
GeoServer RCE due to improper control of generation of code in jai-ext`Jiffle` map algebra language
GeoServer RCE due to improper control of generation of code in jai-ext`Jiffle` map algebra language
org.geoserver:gs-wms: before 2.18.6
DataEase API interface has IDOR vulnerability
DataEase API interface has IDOR vulnerability
io.dataease:dataease-plugin-common: before 1.18.7
Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
org.xerial:sqlite-jdbc: 3.6.14.1 → 3.41.2.2
org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability
org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability
org.xwiki.platform:xwiki-platform-oldcore: before 14.10.4
Privilege escalation (PR)/RCE from account through class sheet
Privilege escalation (PR)/RCE from account through class sheet
org.xwiki.platform:xwiki-platform-test-ui: 3.3-milestone-3 → 14.10.4
Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xml
Improper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xml
org.xwiki.commons:xwiki-commons-xml: 14.6-rc-1 → 14.10.4
Chosen Ciphertext Attack in Jose4j
Chosen Ciphertext Attack in Jose4j
org.bitbucket.b_c:jose4j: before 0.9.3
org.xwiki.platform:xwiki-platform-attachment-ui vulnerable to Code Injection
org.xwiki.platform:xwiki-platform-attachment-ui vulnerable to Code Injection
org.xwiki.platform:xwiki-platform-attachment-ui: 3.0-rc-1 → 13.10.11
XWiki App Within Minutes app grants space admin rights that allows cross-site scripting
XWiki App Within Minutes app grants space admin rights that allows cross-site scripting
org.xwiki.platform:xwiki-platform-appwithinminutes: 4.0-milestone-2 → 4.2-milestone-1
XWiki Platform vulnerable to code injection in display method used in user profiles
XWiki Platform vulnerable to code injection in display method used in user profiles
org.xwiki.platform:xwiki-platform-oldcore: 3.3-milestone-1 → 13.10.11
XWiki Platform vulnerable to code injection from view right on XWiki.ClassSheet
XWiki Platform vulnerable to code injection from view right on XWiki.ClassSheet
org.xwiki.platform:xwiki-platform-xclass-ui: 7.0-rc-1 → 14.4.8
Cross-site Scripting in org.xwiki.commons:xwiki-commons-xml
Cross-site Scripting in org.xwiki.commons:xwiki-commons-xml
org.xwiki.commons:xwiki-commons-xml: 4.2-milestone-1 → 14.10
XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector
XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector
org.xwiki.platform:xwiki-platform-attachment-ui: 2.0-rc-2 → 13.10.11
XWiki Platform vulnerable to code injection from account/view through VFS Tree macro
XWiki Platform vulnerable to code injection from account/view through VFS Tree macro
org.xwiki.platform:xwiki-platform-vfs-ui: 7.4-milestone-2 → 13.10.11
Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewer
Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewer
org.xwiki.platform:xwiki-platform-office-viewer: 2.5-milestone-2 → 13.10.11
XWiki Platform vulnerable to privilege escalation from view right using Invitation.InvitationCommon
XWiki Platform vulnerable to privilege escalation from view right using Invitation.InvitationCommon
org.xwiki.platform:xwiki-platform-invitation-ui: 2.5-m-1 → 13.10.11
OutOfMemoryError for large multipart without filename in Eclipse Jetty
OutOfMemoryError for large multipart without filename in Eclipse Jetty
org.eclipse.jetty:jetty-server: before 9.4.51.v20230217
Code injection via unescaped translations in xwiki-platform
Code injection via unescaped translations in xwiki-platform
org.xwiki.platform:xwiki-platform-administration-ui: 4.3-milestone-2 → 14.10.2
Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
org.eclipse.jetty:jetty-server: before 9.4.51.v20230217
Snowflake JDBC vulnerable to command injection via SSO URL authentication
Snowflake JDBC vulnerable to command injection via SSO URL authentication
net.snowflake:snowflake-jdbc: before 3.13.29
org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors
org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors
org.xwiki.platform:xwiki-platform-oldcore: 14.5 → 14.10
org.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macro
org.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macro
org.xwiki.platform:xwiki-platform-rendering-xwiki: before 14.8-rc-1
org.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalation
org.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalation
org.xwiki.platform:xwiki-platform-flamingo-theme-ui: 12.6.6 → 13.10.11
org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki: 5.3-milestone-2 → 13.10.11
Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macro
Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macro
org.xwiki.platform:xwiki-platform-flamingo-skin-resources: 1.9-milestone-2 → 13.10.10
org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents
org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents
org.xwiki.platform:xwiki-platform-oldcore: 1.2-milestone-1 → 13.10.11
org.xwiki.commons:xwiki-commons-xml Cross-site Scripting vulnerability
org.xwiki.commons:xwiki-commons-xml Cross-site Scripting vulnerability
org.xwiki.commons:xwiki-commons-xml: 4.2-milestone-1 → 14.6-rc-1
org.xwiki.platform:xwiki-platform-logging-ui Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-logging-ui Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-logging-ui: 4.2-milestone-3 → 13.10.11
Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm
Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm
org.xwiki.platform:xwiki-platform-web-templates: 13.9-rc-1 → 13.10.8
org.xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-panels-ui: 1.1-M2 → 13.10.11
org.xwiki.platform:xwiki-platform-notifications-ui Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-notifications-ui Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-notifications-ui: 13.2-rc-1 → 13.10.11
xwiki-platform-administration-ui vulnerable to privilege escalation
xwiki-platform-administration-ui vulnerable to privilege escalation
org.xwiki.platform:xwiki-platform-administration-ui: 1.5M2 → 13.10.11
Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter
Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter
io.goobi.viewer:viewer-core: before 23.03
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments
io.goobi.viewer:viewer-core: before 23.03
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames
io.goobi.viewer:viewer-core: before 23.03
Apache James server's JMX management service vulnerable to privilege escalation by local user
Apache James server's JMX management service vulnerable to privilege escalation by local user
org.apache.james:javax-mail-extension: before 3.7.4
Apiman vulnerable to permissions bypass due to missing check on API key URL
Apiman vulnerable to permissions bypass due to missing check on API key URL
io.apiman:apiman-manager-api-rest-impl: before 3.1.0.Final
json-smart Uncontrolled Recursion vulnerability
json-smart Uncontrolled Recursion vulnerability
net.minidev:json-smart: before 2.4.9
Jettison vulnerable to infinite recursion
Jettison vulnerable to infinite recursion
org.codehaus.jettison:jettison: before 1.5.4
jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.12.6
Incorrect Permission Preservation in Jenkins Core
Incorrect Permission Preservation in Jenkins Core
org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1
Incorrect Authorization in Jenkins Core
Incorrect Authorization in Jenkins Core
org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1
Information disclosure through error stack traces related to agents
Information disclosure through error stack traces related to agents
org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1
Cross-site Scripting vulnerability in Jenkins
Cross-site Scripting vulnerability in Jenkins
org.jenkins-ci.main:jenkins-core: 2.376 → 2.394
Incorrect Authorization in Jenkins Core
Incorrect Authorization in Jenkins Core
org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1
org.xwiki.platform:xwiki-platform-panels-ui vulnerable to Eval Injection
org.xwiki.platform:xwiki-platform-panels-ui vulnerable to Eval Injection
org.xwiki.platform:xwiki-platform-panels-ui: 6.3-milestone-2 → 13.10.11
XWiki Platform packages Expose Sensitive Information to an Unauthorized Actor
XWiki Platform packages Expose Sensitive Information to an Unauthorized Actor
org.xwiki.platform:xwiki-platform-livetable-ui: 3.2-m3 → 13.4.4
xwiki vulnerable to Improper Handling of Exceptional Conditions
xwiki vulnerable to Improper Handling of Exceptional Conditions
org.xwiki.platform:xwiki-platform-rendering-parser: 6.0 → 13.10.10
Unprivileged XWiki Platform users can make arbitrary select queries using DatabaseListProperty and suggest.vm
Unprivileged XWiki Platform users can make arbitrary select queries using DatabaseListProperty and suggest.vm
org.xwiki.platform:xwiki-platform-web: 1.3-rc-1 → 13.10.11
XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profile
XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profile
org.xwiki.platform:xwiki-platform-icon-ui: 6.2-milestone-1 → 13.10.10
org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
org.xwiki.platform:xwiki-platform-flamingo-theme-ui: 6.2.4 → 13.10.10
xwiki contains Incorrect Authorization
xwiki contains Incorrect Authorization
org.xwiki.platform:xwiki-platform-rendering-macro-context: 3.0-milestone-1 → 13.10.10
XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data
XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Data
org.xwiki.platform:xwiki-platform-livedata-macro: 12.10 → 13.10.10
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
org.xwiki.platform:xwiki-platform-oldcore: 13.10 → 13.10.11
Keycloak vulnerable to user impersonation via stolen UUID code
Keycloak vulnerable to user impersonation via stolen UUID code
org.keycloak:keycloak-services: before 21.0.1
GeoServer OGC Filter SQL Injection Vulnerabilities
GeoServer OGC Filter SQL Injection Vulnerabilities
org.geoserver.community:gs-jdbcconfig: before 2.21.4
Apache Commons FileUpload denial of service vulnerability
Apache Commons FileUpload denial of service vulnerability
commons-fileupload:commons-fileupload: before 1.5
XML External Entity (XXE) vulnerability in apoc.import.graphml
XML External Entity (XXE) vulnerability in apoc.import.graphml
org.neo4j.procedure:apoc-core: 5.0.0 → 5.5.0
StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route
StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route
io.vertx:vertx-web: 4.0.0 → 4.3.8
Field-level security issue with .keyword fields in OpenSearch
Field-level security issue with .keyword fields in OpenSearch
org.opensearch.plugin:opensearch-security: before 1.3.8
Wildfly-elytron possibly vulnerable to timing attacks via use of unsafe comparator
Wildfly-elytron possibly vulnerable to timing attacks via use of unsafe comparator
org.wildfly.security:wildfly-elytron: before 1.15.15.Final
XWiki CKEditor.HTMLConverter vulnerable to Remote Code Execution via Cross-Site Request Forgery
XWiki CKEditor.HTMLConverter vulnerable to Remote Code Execution via Cross-Site Request Forgery
org.xwiki.contrib:application-ckeditor-ui: before 1.64.3
Apache James server allows an attacker with local access to access private user data in transit
Apache James server allows an attacker with local access to access private user data in transit
org.apache.james:james-server: all versions
json stack overflow vulnerability
json stack overflow vulnerability
cn.hutool:hutool-json: before 5.8.25
Jettison Out-of-bounds Write vulnerability
Jettison Out-of-bounds Write vulnerability
org.codehaus.jettison:jettison: before 1.5.2
Jettison Out-of-bounds Write vulnerability
Jettison Out-of-bounds Write vulnerability
org.codehaus.jettison:jettison: before 1.5.2
HAProxyMessageDecoder Stack Exhaustion DoS
HAProxyMessageDecoder Stack Exhaustion DoS
io.netty:netty-codec-haproxy: before 4.1.86.Final
SnakeYaml Constructor Deserialization Remote Code Execution
SnakeYaml Constructor Deserialization Remote Code Execution
org.yaml:snakeyaml: before 2.0
Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
com.google.protobuf:protobuf-java: 3.0.0 → 3.16.3
Protobuf Java vulnerable to Uncontrolled Resource Consumption
Protobuf Java vulnerable to Uncontrolled Resource Consumption
com.google.protobuf:protobuf-java: 3.0.0 → 3.16.3
Tooling for Maven
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.