Maven incidents

Recent Maven vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

HIGHMaven

Sakai Conversations has a Stored XSS Issue

Sakai Conversations has a Stored XSS Issue

org.sakaiproject.conversations:sakai-conversations-impl: ≥ 23.0

1 day ago
HIGHMaven

Sakai Profile Image Deletion has an IDOR

Sakai Profile Image Deletion has an IDOR

org.sakaiproject.profile2:profile2-api: 23.0 → 23.5

1 day ago
CRITICALMaven

GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers

GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers

org.geotools.jdbc:gt-jdbc-postgis: 35.0 → 35.1

4 days ago
HIGHMaven

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final

5 days ago
HIGHMaven

netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service

netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service

io.netty.incubator:netty-incubator-codec-ohttp: before 0.0.23.Final

5 days ago
HIGHMaven

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final

5 days ago
HIGHMaven

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl: before 0.0.23.Final

5 days ago
MEDIUMMaven

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final

5 days ago
HIGHMaven

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final

5 days ago
HIGHMaven

XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing

XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing

org.xwiki.platform:xwiki-platform-livedata-livetable: 13.4-rc-1 → 16.10.17

6 days ago
CRITICALMaven

GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates

GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates

org.geoserver:gs-main: before 2.27.0

6 days ago
MODERATEMaven

RabbitMQ Java client malformed body frame triggers raw command assembler exception

RabbitMQ Java client malformed body frame triggers raw command assembler exception

com.rabbitmq:amqp-client: before 5.31.0

1 week ago
HIGHMaven

RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS

RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS

com.rabbitmq:amqp-client: before 5.33.1

1 week ago
MODERATEMaven

RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM

RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM

com.rabbitmq:amqp-client: before 5.33.0

1 week ago
LOWMaven

RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max

RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max

com.rabbitmq:amqp-client: before 5.33.0

1 week ago
HIGHMaven

Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection

Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection

io.kestra:kestra: before 1.3.24

1 week ago
HIGHMaven

RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation

RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation

com.rabbitmq:amqp-client: before 5.33.1

1 week ago
HIGHMaven

RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading

RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading

com.rabbitmq:amqp-client: before 5.33.0

1 week ago
HIGHMaven

Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite

Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite

io.netty:netty-codec-http: 4.2.0.Final → 4.2.17.Final

1 week ago
HIGHMaven

Netty: Memory Exhaustion in SctpMessageCompletionHandler

Netty: Memory Exhaustion in SctpMessageCompletionHandler

io.netty:netty-transport-sctp: 4.2.0.Final → 4.2.17.Final

1 week ago
HIGHMaven

OpenAM Insecure SSO Cookie Initialization

OpenAM Insecure SSO Cookie Initialization

org.openidentityplatform.openam:openam-core: before 16.1.1

1 week ago
CRITICALMaven

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

com.mchange:mchange-commons-java: before 0.6.0

1 week ago
MEDIUMMaven

Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state

Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state

io.netty:netty-codec-redis: before 4.1.136.Final

2 weeks ago
MEDIUMMaven

jsoup: Cleaner may expose markup with custom raw-text elements

jsoup: Cleaner may expose markup with custom raw-text elements

org.jsoup:jsoup: 1.14.3 → 1.23.1

2 weeks ago
MODERATEMaven

core-geonetwork has an Open Redirect Bypass

core-geonetwork has an Open Redirect Bypass

org.geonetwork-opensource:geonetwork: ≥ 3.12.0

3 weeks agoEPSS 0%
HIGHMaven

Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

io.netty:netty-codec-http2: 4.2.0 → 4.2.16.Final

3 weeks agoEPSS 0%
HIGHMaven

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

3 weeks agoEPSS 0%
MEDIUMMaven

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

org.apache.httpcomponents.client5:httpclient5: 5.0-alpha1 → 5.6.3

3 weeks ago
MODERATEMaven

veraPDF Parser DoS via PostScript Type 1 Font Programs

veraPDF Parser DoS via PostScript Type 1 Font Programs

org.verapdf:parser: before 1.30.2

3 weeks agoEPSS 0%
MEDIUMMaven

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

org.verapdf:validation-model: 1.17.35 → 1.30.2

3 weeks agoEPSS 0%
HIGHMaven

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.28.0-alpha

3 weeks agoEPSS 0%
MEDIUMMaven

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.27.0

3 weeks agoEPSS 0%
MODERATEMaven

veraPDF Parser DoS via PostScript CMap Streams

veraPDF Parser DoS via PostScript CMap Streams

org.verapdf:parser: before 1.30.2

3 weeks agoEPSS 0%
HIGHMaven

veraPDF Validation XXE via Rich Text

veraPDF Validation XXE via Rich Text

org.verapdf:validation-model: 1.25.73 → 1.30.2

3 weeks agoEPSS 0%
HIGHMaven

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

io.quarkus:quarkus-vertx-http: before 3.20.6.2

3 weeks agoEPSS 0%
HIGHMaven

veraPDF Validation XXE via XFA

veraPDF Validation XXE via XFA

org.verapdf:validation-model: 1.17.35 → 1.30.2

3 weeks agoEPSS 0%
HIGHMaven

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

4 weeks agoEPSS 0%
CRITICALMaven

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

com.cedarpolicy:cedar-java: before 2.3.6

4 weeks ago
CRITICALMaven

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

org.openidentityplatform.openam:openam-core: before 16.1.2

4 weeks ago
HIGHMaven

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

org.http4s:blaze-http_2.13: before 0.23.18

4 weeks ago
MEDIUMMaven

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

io.netty:netty-codec-dns: 4.2.0.Final → 4.2.16.Final

4 weeks ago
HIGHMaven

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

org.http4s:http4s-blaze-server_2.13: before 0.23.18

4 weeks ago
HIGHMaven

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

org.openidentityplatform.opendj:opendj-server-legacy: before 5.1.2

4 weeks ago
HIGHMaven

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

org.http4s:http4s-blaze-server_2.13: before 0.23.18

4 weeks ago
HIGHMaven

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

io.netty:netty-codec-xml: 4.2.0.Final → 4.2.16.Final

4 weeks ago
CRITICALMaven

fastjson has a remote code execution (RCE) vulnerability

fastjson has a remote code execution (RCE) vulnerability

com.alibaba:fastjson: ≥ 1.2.68

4 weeks ago
HIGHMaven

Netty: STOMP CONNECT Frame Header Injection in Netty

Netty: STOMP CONNECT Frame Header Injection in Netty

io.netty:netty-codec-stomp: 4.2.0.Final → 4.2.16.Final

4 weeks agoEPSS 0%
HIGHMaven

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

com.fasterxml.jackson.core:jackson-core: before 2.18.8

1 month ago
HIGHMaven

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.5

1 month agoEPSS 0%
HIGHMaven

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

com.arcadedb:arcadedb-engine: before 26.7.2

1 month agoEPSS 0%
HIGHMaven

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

com.arcadedb:arcadedb-engine: before 26.7.2

1 month agoEPSS 1%
HIGHMaven

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

com.arcadedb:arcadedb-server: before 26.7.2

1 month agoEPSS 0%
HIGHMaven

dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

com.datadoghq:dd-java-agent: before 1.62.0

1 month ago
MODERATEMaven

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization

org.apache.logging.log4j:log4j-api: 2.13.1 → 2.25.5

1 month ago
HIGHMaven

Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK

Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK

org.apache.httpcomponents.core5:httpcore5-h2: before 5.4.3

1 month ago
HIGHMaven

Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service

Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service

org.apache.httpcomponents.core5:httpcore5: before 5.4.3

1 month ago
HIGHMaven

JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution

JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution

org.jetbrains.kotlin:kotlin-gradle-plugin: before 2.4.20-Beta1

2 months ago
CRITICALMaven

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.18.8

2 months agoEPSS 1%
HIGHMaven

Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types

Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types

io.spinnaker.rosco:rosco-core: before 2025.3.3

2 months ago
HIGHMaven

JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

org.jline:jline-remote-telnet: before 4.2.1

2 months ago
HIGHMaven

JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

org.jline:jline-remote-telnet: before 4.2.1

2 months ago
HIGHMaven

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

io.netty:netty-codec-http3: 4.2.0.Final → 4.2.15.Final

2 months agoEPSS 0%
HIGHMaven

Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier

Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

2 months ago
HIGHMaven

Apache cxf-core: No restriction on attachment headers per message

Apache cxf-core: No restriction on attachment headers per message

org.apache.cxf:cxf-core: 4.2.0 → 4.2.2

2 months ago
CRITICALMaven

Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl

Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl

org.apache.cxf:cxf-integration-jca: 4.2.0 → 4.2.2

2 months ago
HIGHMaven

Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing

Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

2 months ago
CRITICALMaven

Apache CXF OAuth2 Missing JWT Audience and Issuer Validation in Access Token Validator

Apache CXF OAuth2 Missing JWT Audience and Issuer Validation in Access Token Validator

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

2 months ago
MEDIUMMaven

Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry

Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry

org.apache.cxf:cxf-rt-rs-security-jose-jaxrs: 4.2.0 → 4.2.2

2 months ago
MEDIUMMaven

Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection

Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

2 months ago
CRITICALMaven

Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory

Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory

org.apache.cxf:cxf-rt-transports-jms: 4.2.0 → 4.2.2

2 months ago
MEDIUMMaven

Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService

Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

2 months ago
CRITICALMaven

Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control

Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control

org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2

2 months ago
HIGHMaven

Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource

Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource

org.springframework.ws:spring-xml: 5.0.0 → 5.0.2

2 months ago
HIGHMaven

Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem

Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem

org.springframework.integration:spring-integration-file: 7.0.0 → 7.0.5

2 months ago
HIGHMaven

Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks

Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks

org.keycloak:keycloak-rest-admin-ui-ext: before 26.7.0

2 months ago
HIGHMaven

Spring Web Flow has Data Binding Vulnerability with Unified EL Parser

Spring Web Flow has Data Binding Vulnerability with Unified EL Parser

org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1

2 months ago
MEDIUMMaven

Spring Web Services: X.509 authentication bypasses Spring Security account checks

Spring Web Services: X.509 authentication bypasses Spring Security account checks

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

2 months ago
HIGHMaven

Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final

2 months ago
MEDIUMMaven

Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default

Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

2 months ago
MEDIUMMaven

Spring Boot: Predictable Temp Directory in Artemis Auto-configuration

Spring Boot: Predictable Temp Directory in Artemis Auto-configuration

org.springframework.boot:spring-boot-autoconfigure: 4.0.0 → 4.0.7

2 months ago
MEDIUMMaven

Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification

Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification

org.springframework.boot:spring-boot-starter-mail: 4.0.0 → 4.0.7

2 months ago
HIGHMaven

Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML

Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML

org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1

2 months ago
HIGHMaven

Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations

Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations

org.springframework.ws:spring-ws-core: 5.0.0 → 5.0.2

2 months ago
HIGHMaven

Spring for GraphQL: Cross-Site WebSocket Hijacking

Spring for GraphQL: Cross-Site WebSocket Hijacking

org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4

2 months ago
CRITICALMaven

Spring for GraphQL: Unsafe Deserialization

Spring for GraphQL: Unsafe Deserialization

org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4

2 months ago
HIGHMaven

Spring for GraphQL: Annotation Detection Vulnerability

Spring for GraphQL: Annotation Detection Vulnerability

org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4

2 months ago
HIGHMaven

Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default

Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

2 months ago
MEDIUMMaven

Spring Web Services: SOAP security faults leak Spring Security account state

Spring Web Services: SOAP security faults leak Spring Security account state

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

2 months ago
MEDIUMMaven

Spring Web Services: WSS4J validation does not use configured replay cache

Spring Web Services: WSS4J validation does not use configured replay cache

org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2

2 months ago
HIGHMaven

Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.15.Final

2 months agoEPSS 1%
MEDIUMMaven

netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

io.netty:netty-codec-http2: before 4.1.135.Final

2 months agoEPSS 1%
MEDIUMMaven

Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL

Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL

org.jenkins-ci.main:jenkins-core: before 2.555.3

2 months ago
HIGHMaven

Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys

Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

2 months ago
HIGHMaven

Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries

Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries

org.springframework.data:spring-data-keyvalue: 4.0.0 → 4.0.6

2 months ago
CRITICALMaven

Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation

Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation

org.jenkins-ci.main:jenkins-core: before 2.555.3

2 months ago
MEDIUMMaven

Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL

Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL

org.jenkins-ci.main:jenkins-core: 2.556 → 2.568

2 months ago
MEDIUMMaven

Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"

Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"

org.jenkins-ci.main:jenkins-core: before 2.555.3

2 months ago
MEDIUMMaven

Jenkins: Missing permission check allows unauthorized cancellation of queue items

Jenkins: Missing permission check allows unauthorized cancellation of queue items

org.jenkins-ci.main:jenkins-core: before 2.555.3

2 months ago
MEDIUMMaven

Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache

Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache

org.springframework.security:spring-security-web: 7.0.0 → 7.0.6

2 months ago
MEDIUMMaven

Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations

Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations

org.jenkins-ci.main:jenkins-core: before 2.555.3

2 months ago
HIGHMaven

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests

org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6

2 months ago
MEDIUMMaven

Spring Data REST potentially exposes persistence-layer internals to HTTP clients

Spring Data REST potentially exposes persistence-layer internals to HTTP clients

org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6

2 months ago
HIGHMaven

Spring Data Commons: Denial of Service via excessive memory allocation in projection binding

Spring Data Commons: Denial of Service via excessive memory allocation in projection binding

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

2 months ago
HIGHMaven

Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation

Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation

org.springframework.kafka:spring-kafka: 4.0.0 → 4.0.6

2 months ago
MEDIUMMaven

Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads

Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads

org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6

2 months ago
MEDIUMMaven

Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue

Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue

org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4

2 months ago
HIGHMaven

Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository

Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository

org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6

2 months ago
MEDIUMMaven

Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference

Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference

org.springframework.data:spring-data-relational: 4.0.0 → 4.0.6

2 months ago
MEDIUMMaven

Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations

Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations

org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6

2 months ago
MEDIUMMaven

Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter

Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter

org.springframework.security:spring-security-oauth2-authorization-server: 7.0.0 → 7.0.6

2 months ago
CRITICALMaven

Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection

Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection

org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6

2 months ago
HIGHMaven

Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)

Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)

org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6

2 months ago
HIGHMaven

Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)

Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

2 months ago
HIGHMaven

Spring Data REST has Improper Access Control in its JSON Patch Implementation

Spring Data REST has Improper Access Control in its JSON Patch Implementation

org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6

2 months ago
CRITICALMaven

Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization

Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization

org.springframework.pulsar:spring-pulsar: 2.0.0 → 2.0.6

2 months ago
HIGHMaven

Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference

Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference

org.springframework.restdocs:spring-restdocs-webtestclient: 4.0.0 → 4.0.1

2 months ago
HIGHMaven

Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods

Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods

org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6

2 months ago
HIGHMaven

Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters

Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters

org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6

2 months ago
MEDIUMMaven

Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean

Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean

org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4

2 months ago
MEDIUMMaven

Jenkins exposes other users' timezone and view names to users with Overall/Read permission

Jenkins exposes other users' timezone and view names to users with Overall/Read permission

org.jenkins-ci.main:jenkins-core: before 2.555.3

2 months ago
HIGHMaven

Spring Framework Predictable Session ID in WebSocket Module

Spring Framework Predictable Session ID in WebSocket Module

org.springframework:spring-websocket: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Multipart Requests in WebFlux

Spring Framework Denial of Service via Multipart Requests in WebFlux

org.springframework:spring-webflux: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Spring LDAP has Authentication Bypass with Empty Password

Spring LDAP has Authentication Bypass with Empty Password

org.springframework.ldap:spring-ldap-core: 4.0.0 → 4.0.4

2 months agoEPSS 0%
MEDIUMMaven

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

2 months agoEPSS 0%
MEDIUMMaven

Spring Framework Denial of Service via Unbounded Cache in SpEL

Spring Framework Denial of Service via Unbounded Cache in SpEL

org.springframework:spring-expression: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Spring Framework Cross-site Scripting via JavaScriptUtils

Spring Framework Cross-site Scripting via JavaScriptUtils

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Spring Framework Algorithmic Denial of Service via SpEL Expressions

Spring Framework Algorithmic Denial of Service via SpEL Expressions

org.springframework:spring-expression: 7.0.0 → 7.0.8

2 months agoEPSS 0%
MEDIUMMaven

Spring Framework Denial of Service via AntPathMatcher

Spring Framework Denial of Service via AntPathMatcher

org.springframework:spring-core: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

org.springframework:spring-expression: all versions

2 months agoEPSS 0%
MEDIUMMaven

Spring Framework Open Redirect in Spring MVC and WebFlux

Spring Framework Open Redirect in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Spring Framework Cross-site Scripting via JSP Form Tags

Spring Framework Cross-site Scripting via JSP Form Tags

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

2 months agoEPSS 0%
MEDIUMMaven

Spring Framework Arbitrary Method Invocation in SpEL Expressions

Spring Framework Arbitrary Method Invocation in SpEL Expressions

org.springframework:spring-expression: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4

2 months agoEPSS 0%
HIGHMaven

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Micrometer HTTP server instrumentations DoS

Micrometer HTTP server instrumentations DoS

io.micrometer:micrometer-core: 1.16.0 → 1.16.6

2 months ago
MEDIUMMaven

Spring Framework Server-Side Request Forgery via UriComponentsBuilder

Spring Framework Server-Side Request Forgery via UriComponentsBuilder

org.springframework:spring-web: 7.0.0 → 7.0.8

2 months ago
MEDIUMMaven

Spring Framework Escalation via Session Fixation in WebFlux

Spring Framework Escalation via Session Fixation in WebFlux

org.springframework:spring-webflux: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Micrometer gRPC server instrumentation DoS

Micrometer gRPC server instrumentation DoS

io.micrometer:micrometer-core: 1.16.0 → 1.16.6

2 months ago
MEDIUMMaven

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

org.springframework:spring-webflux: all versions

2 months agoEPSS 0%
HIGHMaven

Spring HATEOAS heap exhaustion through unbounded internal caching

Spring HATEOAS heap exhaustion through unbounded internal caching

org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4

2 months agoEPSS 0%
MEDIUMMaven

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

io.projectreactor.netty:reactor-netty: 1.3.0 → 1.3.6

2 months agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

2 months agoEPSS 0%
HIGHMaven

Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service

Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service

org.springframework.retry:spring-retry: 2.0.0 → 2.0.13

2 months agoEPSS 0%
HIGHMaven

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final

2 months agoEPSS 0%
HIGHMaven

Netty has Insufficient Bailiwick Validation for NS Records

Netty has Insufficient Bailiwick Validation for NS Records

io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final

2 months agoEPSS 0%
HIGHMaven

Keycloak has an Improper Verification of Cryptographic Signature issue

Keycloak has an Improper Verification of Cryptographic Signature issue

org.keycloak:keycloak-services: all versions

2 months ago
HIGHMaven

Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition

Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition

org.keycloak:keycloak-server: before 26.6.4

2 months ago
MEDIUMMaven

Keycloak has an Authentication Bypass by Primary Weakness

Keycloak has an Authentication Bypass by Primary Weakness

org.keycloak:keycloak-services: all versions

2 months ago
MEDIUMMaven

Keycloak Services has Improper Validation of Consistency within Input

Keycloak Services has Improper Validation of Consistency within Input

org.keycloak:keycloak-services: ≥ 26.5.0

3 months ago
HIGHMaven

Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service

Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service

com.squareup.wire:wire-runtime-jvm: before 6.3.0

3 months ago
MEDIUMMaven

Apache Wicket has a Path Traversal issue

Apache Wicket has a Path Traversal issue

org.apache.wicket:wicket-core: ≥ 8.0.0-M1

3 months ago
CRITICALMaven

ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases

ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases

com.arcadedb:arcadedb-server: 21.10.1 → 26.4.2

3 months agoEPSS 0%
CRITICALMaven

Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest

Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest

org.apache.opennlp:opennlp-tools: 2.0.0 → 2.5.9

3 months ago
HIGHMaven

Quarkus has Authentication/Authorization bypasses

Quarkus has Authentication/Authorization bypasses

io.quarkus:quarkus-vertx-http: before 3.20.6.1

3 months ago
CRITICALMaven

Jenkins GitHub Plugin has an XSS vulnerability

Jenkins GitHub Plugin has an XSS vulnerability

com.coravy.hudson.plugins.github:github: before 1.46.0.1

3 months ago
HIGHMaven

Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

org.eclipse.jetty:jetty-http: 12.1.0 → 12.1.7

4 months ago
HIGHMaven

Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File

Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File

org.apache.tomcat:tomcat-tribes: 9.0.13 → 9.0.117

4 months ago
CRITICALMaven

OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution

OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution

io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.26.1

5 months agoEPSS 1%
CRITICALMaven

XWiki Blog Application home page vulnerable to Stored XSS via Post Title

XWiki Blog Application home page vulnerable to Stored XSS via Post Title

org.xwiki.contrib.blog:application-blog-ui: 9.15 → 9.15.7

5 months ago
MODERATEMaven

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

tools.jackson.core:jackson-core: 3.0.0 → 3.1.0

5 months ago
CRITICALMaven

carbon-apimgt does not properly restrict uploaded files

carbon-apimgt does not properly restrict uploaded files

org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1: before 9.32.167

6 months ago
CRITICALMaven

Eclipse Jersey has a Race Condition

Eclipse Jersey has a Race Condition

org.glassfish.jersey.core:jersey-client: 2.45 → 2.46

9 months ago
HIGHMaven

Keycloak Potential Variable Reference in Model Storage Services

Keycloak Potential Variable Reference in Model Storage Services

org.keycloak:keycloak-model-storage-services: all versions

10 months ago
CRITICALMaven

jinjava has Sandbox Bypass via JavaType-Based Deserialization

jinjava has Sandbox Bypass via JavaType-Based Deserialization

com.hubspot.jinjava:jinjava: 2.8.0 → 2.8.1

11 months agoEPSS 2%
MEDIUMMaven

Keycloak vulnerable to two factor authentication bypass

Keycloak vulnerable to two factor authentication bypass

org.keycloak:keycloak-services: before 26.2.2

1 year ago
HIGHMaven

Keycloak hostname verification

Keycloak hostname verification

org.keycloak:keycloak-services: before 26.2.2

1 year ago
MEDIUMMaven

Jenkins Missing Permission Check

Jenkins Missing Permission Check

org.jenkins-ci.main:jenkins-core: 2.500 → 2.504

1 year ago
MEDIUMMaven

Jenkins Missing Permission Check

Jenkins Missing Permission Check

org.jenkins-ci.main:jenkins-core: 2.500 → 2.504

1 year ago
MEDIUMMaven

Spring Security Vulnerable to Authorization Bypass via Security Annotations

Spring Security Vulnerable to Authorization Bypass via Security Annotations

org.springframework.security:spring-security-core: 6.4.0 → 6.4.4

1 year ago
MEDIUMMaven

Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak

Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak

org.keycloak:keycloak-ldap-federation: 26.1.0 → 26.1.3

1 year ago
MEDIUMMaven

Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission

Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission

org.jenkins-ci.main:jenkins-core: before 2.492.2

1 year ago
MEDIUMMaven

Jenkins cross-site request forgery (CSRF) vulnerability

Jenkins cross-site request forgery (CSRF) vulnerability

org.jenkins-ci.main:jenkins-core: 2.493 → 2.500

1 year ago
MEDIUMMaven

Jenkins Open Redirect vulnerability

Jenkins Open Redirect vulnerability

org.jenkins-ci.main:jenkins-core: before 2.492.2

1 year ago
MEDIUMMaven

Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission

Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission

org.jenkins-ci.main:jenkins-core: 2.493 → 2.500

1 year ago
MEDIUMMaven

Missing permission check in Jenkins Script Security Plugin

Missing permission check in Jenkins Script Security Plugin

org.jenkins-ci.plugins:script-security: before 1368.vb

1 year ago
HIGHMaven

Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability

Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability

org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.0-M21

1 year ago
HIGHMaven

XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

com.thoughtworks.xstream:xstream: before 1.4.21

1 year ago
CRITICALMaven

Keycloak has session fixation in Elytron SAML adapters

Keycloak has session fixation in Elytron SAML adapters

org.keycloak:keycloak-services: before 22.0.12

1 year ago
MEDIUMMaven

JSON-lib mishandles an unbalanced comment string

JSON-lib mishandles an unbalanced comment string

org.kordamp.json:json-lib-core: before 3.1.0

1 year ago
MEDIUMMaven

Jenkins item creation restriction bypass vulnerability

Jenkins item creation restriction bypass vulnerability

org.jenkins-ci.main:jenkins-core: before 2.462.3

1 year ago
MEDIUMMaven

Jenkins exposes multi-line secrets through error messages

Jenkins exposes multi-line secrets through error messages

org.jenkins-ci.main:jenkins-core: before 2.462.3

1 year ago
HIGHMaven

Apache MINA SSHD: integrity check bypass

Apache MINA SSHD: integrity check bypass

org.apache.sshd:sshd-common: before 2.12.0

2 years ago
HIGHMaven

CometVisu Backend for openHAB affected by SSRF/XSS

CometVisu Backend for openHAB affected by SSRF/XSS

org.openhab.ui.bundles:org.openhab.ui.cometvisu: 3.4.0.M4 → 4.2.1

2 years ago
CRITICALMaven

Jenkins Remoting library arbitrary file read vulnerability

Jenkins Remoting library arbitrary file read vulnerability

org.jenkins-ci.main:remoting: before 3206.3208

2 years ago
MEDIUMMaven

Jenkins does not perform a permission check in an HTTP endpoint

Jenkins does not perform a permission check in an HTTP endpoint

org.jenkins-ci.main:jenkins-core: before 2.452.4

2 years ago
HIGHMaven

GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service

GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service

com.graphql-java:graphql-java: before 19.11

2 years ago
MEDIUMMaven

Exposure of secrets through system log in Jenkins Structs Plugin

Exposure of secrets through system log in Jenkins Structs Plugin

org.jenkins-ci.plugins:structs: before 338.v848422169819

2 years ago
HIGHMaven

Keycloak's admin API allows low privilege users to use administrative functions

Keycloak's admin API allows low privilege users to use administrative functions

org.keycloak:keycloak-services: before 24.0.5

2 years ago
HIGHMaven

Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)

Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)

org.keycloak:keycloak-services: before 24.0.5

2 years ago
HIGHMaven

Neo4j Cypher component mishandles IMMUTABLE privileges

Neo4j Cypher component mishandles IMMUTABLE privileges

org.neo4j:neo4j-cypher: 5.0.0 → 5.19.0

2 years ago
CRITICALMaven

Jenkins Script Security Plugin sandbox bypass vulnerability

Jenkins Script Security Plugin sandbox bypass vulnerability

org.jenkins-ci.plugins:script-security: before 1336.vf33a

2 years ago
CRITICALMaven

Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies

Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies

org.jenkins-ci.plugins:script-security: before 1336.vf33a

2 years ago
HIGHMaven

Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode

Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode

org.apache.kafka:kafka-metadata: 3.5.0 → 3.6.2

2 years ago
CRITICALMaven

quarkus-core leaks local environment variables from Quarkus namespace during application's build

quarkus-core leaks local environment variables from Quarkus namespace during application's build

io.quarkus:quarkus-core: 3.9.0.CR1 → 3.9.2

2 years ago
HIGHMaven

Elasticsearch Incorrect Authorization vulnerability

Elasticsearch Incorrect Authorization vulnerability

org.elasticsearch:elasticsearch: 8.10.0 → 8.13.0

2 years ago
MEDIUMMaven

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat

org.apache.tomcat:tomcat-websocket: 11.0.0-M1 → 11.0.0-M17

2 years ago
HIGHMaven

Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests

Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests

org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.0-M17

2 years ago
MEDIUMMaven

Path traversal vulnerability in Jenkins Matrix Project Plugin

Path traversal vulnerability in Jenkins Matrix Project Plugin

org.jenkins-ci.plugins:matrix-project: before 822.824.v14451b

2 years ago
CRITICALMaven

Cross-site WebSocket hijacking vulnerability in the Jenkins CLI

Cross-site WebSocket hijacking vulnerability in the Jenkins CLI

org.jenkins-ci.main:jenkins-core: 2.217 → 2.426.3

2 years ago
CRITICALMaven

Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE

Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE

org.jenkins-ci.main:jenkins-core: 1.606 → 2.426.3

2 years ago
HIGHMaven

Spring Framework server Web DoS Vulnerability

Spring Framework server Web DoS Vulnerability

org.springframework:spring-core: 6.1.2 → 6.1.3

2 years ago
HIGHMaven

Reactor Netty HTTP Server denial of service vulnerability

Reactor Netty HTTP Server denial of service vulnerability

io.projectreactor.netty:reactor-netty-core: 1.1.0 → 1.1.13

2 years ago
HIGHMaven

Apache Tomcat Improper Input Validation vulnerability

Apache Tomcat Improper Input Validation vulnerability

org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.0-M11

2 years ago
CRITICALMaven

Apache Cassandra: Privilege escalation when enabling FQL/Audit logs

Apache Cassandra: Privilege escalation when enabling FQL/Audit logs

org.apache.cassandra:cassandra-all: 4.1.0 → 4.1.2

3 years ago
HIGHMaven

json-smart Uncontrolled Recursion vulnerability

json-smart Uncontrolled Recursion vulnerability

net.minidev:json-smart: before 2.4.9

3 years agoEPSS 1%
CRITICALMaven

Cross-site Scripting vulnerability in Jenkins

Cross-site Scripting vulnerability in Jenkins

org.jenkins-ci.main:jenkins-core: 2.376 → 2.394

3 years ago
CRITICALMaven

Incorrect Authorization in Jenkins Core

Incorrect Authorization in Jenkins Core

org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1

3 years ago
MEDIUMMaven

Incorrect Permission Preservation in Jenkins Core

Incorrect Permission Preservation in Jenkins Core

org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1

3 years ago
MEDIUMMaven

Information disclosure through error stack traces related to agents

Information disclosure through error stack traces related to agents

org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1

3 years ago
MEDIUMMaven

Incorrect Authorization in Jenkins Core

Incorrect Authorization in Jenkins Core

org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1

3 years ago
HIGHMaven

Apache Commons FileUpload denial of service vulnerability

Apache Commons FileUpload denial of service vulnerability

commons-fileupload:commons-fileupload: before 1.5

3 years ago
MEDIUMMaven

HAProxyMessageDecoder Stack Exhaustion DoS

HAProxyMessageDecoder Stack Exhaustion DoS

io.netty:netty-codec-haproxy: before 4.1.86.Final

3 years ago
HIGHMaven

Local Information Disclosure Vulnerability in io.netty:netty-codec-http

Local Information Disclosure Vulnerability in io.netty:netty-codec-http

io.netty:netty-codec-http: before 4.1.77.Final

4 years ago
HIGHMaven

Observable Discrepancy in Apache Kafka

Observable Discrepancy in Apache Kafka

org.apache.kafka:kafka_2.11: ≥ 2.0.0

4 years ago
HIGHMaven

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

org.apache.tomcat.embed:tomcat-embed-core: 10.0.0-M1 → 10.0.2

5 years ago
HIGHMaven

Information Disclosure in Apache Tomcat

Information Disclosure in Apache Tomcat

org.apache.tomcat.embed:tomcat-embed-core: 10.0.0-M1 → 10.0.0-M10

5 years ago
CRITICALMaven

Potential remote code execution in Apache Tomcat

Potential remote code execution in Apache Tomcat

org.apache.tomcat.embed:tomcat-embed-core: 10.0.0-M1 → 10.0.2

5 years ago
HIGHMaven

XML External Entity (XXE) Injection in Jackson Databind

XML External Entity (XXE) Injection in Jackson Databind

com.fasterxml.jackson.core:jackson-databind: 2.6.0 → 2.6.7.4

5 years ago
CRITICALMaven

Deserialization of untrusted data in Jackson Databind

Deserialization of untrusted data in Jackson Databind

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.5

6 years ago
CRITICALMaven

Deserialization of untrusted data in Jackson Databind

Deserialization of untrusted data in Jackson Databind

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.5

6 years ago
CRITICALMaven

Deserialization of untrusted data in Jackson Databind

Deserialization of untrusted data in Jackson Databind

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.5

6 years ago
CRITICALMaven

Deserialization of untrusted data in Jackson Databind

Deserialization of untrusted data in Jackson Databind

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.5

6 years ago
CRITICALMaven

Deserialization of Untrusted Data

Deserialization of Untrusted Data

com.fasterxml.jackson.core:jackson-databind: 2.7.0 → 2.7.9.4

6 years ago
CRITICALMaven

Improper Privilege Management in Tomcat

Improper Privilege Management in Tomcat

org.apache.tomcat.embed:tomcat-embed-core: 9.0.0 → 9.0.31

6 years ago
CRITICALMaven

jackson-databind mishandles the interaction between serialization gadgets and typing

jackson-databind mishandles the interaction between serialization gadgets and typing

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4

6 years ago
CRITICALMaven

jackson-databind mishandles the interaction between serialization gadgets and typing

jackson-databind mishandles the interaction between serialization gadgets and typing

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4

6 years ago
CRITICALMaven

jackson-databind mishandles the interaction between serialization gadgets and typing

jackson-databind mishandles the interaction between serialization gadgets and typing

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4

6 years ago
CRITICALMaven

jackson-databind mishandles the interaction between serialization gadgets and typing

jackson-databind mishandles the interaction between serialization gadgets and typing

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4

6 years ago
CRITICALMaven

jackson-databind mishandles the interaction between serialization gadgets and typing

jackson-databind mishandles the interaction between serialization gadgets and typing

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4

6 years ago
HIGHMaven

Polymorphic deserialization of malicious object in jackson-databind

Polymorphic deserialization of malicious object in jackson-databind

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10

6 years ago
CRITICALMaven

jackson-databind mishandles the interaction between serialization gadgets and typing

jackson-databind mishandles the interaction between serialization gadgets and typing

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4

6 years ago
CRITICALMaven

jackson-databind mishandles the interaction between serialization gadgets and typing

jackson-databind mishandles the interaction between serialization gadgets and typing

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4

6 years ago
CRITICALMaven

jackson-databind mishandles the interaction between serialization gadgets and typing

jackson-databind mishandles the interaction between serialization gadgets and typing

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4

6 years ago
CRITICALMaven

jackson-databind mishandles the interaction between serialization gadgets and typing

jackson-databind mishandles the interaction between serialization gadgets and typing

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4

6 years ago
MEDIUMMaven

Potential HTTP request smuggling in Apache Tomcat

Potential HTTP request smuggling in Apache Tomcat

org.apache.tomcat.embed:tomcat-embed-core: before 7.0.100

6 years ago
CRITICALMaven

In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack

In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack

org.apache.tomcat.embed:tomcat-embed-core: before 7.0.99

6 years ago
CRITICALMaven

Insufficiently Protected Credentials in Apache Tomcat

Insufficiently Protected Credentials in Apache Tomcat

org.apache.tomcat.embed:tomcat-embed-core: before 7.0.99

6 years ago
CRITICALMaven

Server-Side Request Forgery (SSRF) in jackson-databind

Server-Side Request Forgery (SSRF) in jackson-databind

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.7

7 years ago
CRITICALMaven

XML External Entity Reference (XXE) in jackson-databind

XML External Entity Reference (XXE) in jackson-databind

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.7

7 years ago
CRITICALMaven

Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization

Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization

com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.8

7 years ago
CRITICALMaven

Deserialization of Untrusted Data in jackson-databind

Deserialization of Untrusted Data in jackson-databind

com.fasterxml.jackson.core:jackson-databind: 2.7.0 → 2.7.9.5

7 years ago

Tooling for Maven

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GohexNuGetPackagistPyPIRubyGemscrates.ionpm