Maven incidents
Recent Maven vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Sakai Conversations has a Stored XSS Issue
Sakai Conversations has a Stored XSS Issue
org.sakaiproject.conversations:sakai-conversations-impl: ≥ 23.0
Sakai Profile Image Deletion has an IDOR
Sakai Profile Image Deletion has an IDOR
org.sakaiproject.profile2:profile2-api: 23.0 → 23.5
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
org.geotools.jdbc:gt-jdbc-postgis: 35.0 → 35.1
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
io.netty.incubator:netty-incubator-codec-ohttp: before 0.0.23.Final
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl: before 0.0.23.Final
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
io.netty.incubator:netty-incubator-codec-bhttp: before 0.0.23.Final
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
org.xwiki.platform:xwiki-platform-livedata-livetable: 13.4-rc-1 → 16.10.17
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
org.geoserver:gs-main: before 2.27.0
RabbitMQ Java client malformed body frame triggers raw command assembler exception
RabbitMQ Java client malformed body frame triggers raw command assembler exception
com.rabbitmq:amqp-client: before 5.31.0
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
com.rabbitmq:amqp-client: before 5.33.1
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
com.rabbitmq:amqp-client: before 5.33.0
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
com.rabbitmq:amqp-client: before 5.33.0
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
io.kestra:kestra: before 1.3.24
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
com.rabbitmq:amqp-client: before 5.33.1
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
com.rabbitmq:amqp-client: before 5.33.0
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
io.netty:netty-codec-http: 4.2.0.Final → 4.2.17.Final
Netty: Memory Exhaustion in SctpMessageCompletionHandler
Netty: Memory Exhaustion in SctpMessageCompletionHandler
io.netty:netty-transport-sctp: 4.2.0.Final → 4.2.17.Final
OpenAM Insecure SSO Cookie Initialization
OpenAM Insecure SSO Cookie Initialization
org.openidentityplatform.openam:openam-core: before 16.1.1
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
com.mchange:mchange-commons-java: before 0.6.0
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
io.netty:netty-codec-redis: before 4.1.136.Final
jsoup: Cleaner may expose markup with custom raw-text elements
jsoup: Cleaner may expose markup with custom raw-text elements
org.jsoup:jsoup: 1.14.3 → 1.23.1
core-geonetwork has an Open Redirect Bypass
core-geonetwork has an Open Redirect Bypass
org.geonetwork-opensource:geonetwork: ≥ 3.12.0
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
io.netty:netty-codec-http2: 4.2.0 → 4.2.16.Final
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
org.apache.httpcomponents.client5:httpclient5: 5.0-alpha1 → 5.6.3
veraPDF Parser DoS via PostScript Type 1 Font Programs
veraPDF Parser DoS via PostScript Type 1 Font Programs
org.verapdf:parser: before 1.30.2
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
org.verapdf:validation-model: 1.17.35 → 1.30.2
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.28.0-alpha
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.27.0
veraPDF Parser DoS via PostScript CMap Streams
veraPDF Parser DoS via PostScript CMap Streams
org.verapdf:parser: before 1.30.2
veraPDF Validation XXE via Rich Text
veraPDF Validation XXE via Rich Text
org.verapdf:validation-model: 1.25.73 → 1.30.2
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
io.quarkus:quarkus-vertx-http: before 3.20.6.2
veraPDF Validation XXE via XFA
veraPDF Validation XXE via XFA
org.verapdf:validation-model: 1.17.35 → 1.30.2
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
com.cedarpolicy:cedar-java: before 2.3.6
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
org.openidentityplatform.openam:openam-core: before 16.1.2
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
org.http4s:blaze-http_2.13: before 0.23.18
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
io.netty:netty-codec-dns: 4.2.0.Final → 4.2.16.Final
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
org.http4s:http4s-blaze-server_2.13: before 0.23.18
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
org.openidentityplatform.opendj:opendj-server-legacy: before 5.1.2
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
org.http4s:http4s-blaze-server_2.13: before 0.23.18
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
io.netty:netty-codec-xml: 4.2.0.Final → 4.2.16.Final
fastjson has a remote code execution (RCE) vulnerability
fastjson has a remote code execution (RCE) vulnerability
com.alibaba:fastjson: ≥ 1.2.68
Netty: STOMP CONNECT Frame Header Injection in Netty
Netty: STOMP CONNECT Frame Header Injection in Netty
io.netty:netty-codec-stomp: 4.2.0.Final → 4.2.16.Final
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
com.fasterxml.jackson.core:jackson-core: before 2.18.8
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
com.fasterxml.jackson.core:jackson-databind: 2.21.0 → 2.21.5
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
com.arcadedb:arcadedb-engine: before 26.7.2
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
com.arcadedb:arcadedb-engine: before 26.7.2
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
com.arcadedb:arcadedb-server: before 26.7.2
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
com.datadoghq:dd-java-agent: before 1.62.0
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
org.apache.logging.log4j:log4j-api: 2.13.1 → 2.25.5
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
org.apache.httpcomponents.core5:httpcore5-h2: before 5.4.3
Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service
Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service
org.apache.httpcomponents.core5:httpcore5: before 5.4.3
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution
org.jetbrains.kotlin:kotlin-gradle-plugin: before 2.4.20-Beta1
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
com.fasterxml.jackson.core:jackson-databind: 2.10.0 → 2.18.8
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types
io.spinnaker.rosco:rosco-core: before 2025.3.3
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
org.jline:jline-remote-telnet: before 4.2.1
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
org.jline:jline-remote-telnet: before 4.2.1
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
io.netty:netty-codec-http3: 4.2.0.Final → 4.2.15.Final
Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier
Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache cxf-core: No restriction on attachment headers per message
Apache cxf-core: No restriction on attachment headers per message
org.apache.cxf:cxf-core: 4.2.0 → 4.2.2
Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
org.apache.cxf:cxf-integration-jca: 4.2.0 → 4.2.2
Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing
Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache CXF OAuth2 Missing JWT Audience and Issuer Validation in Access Token Validator
Apache CXF OAuth2 Missing JWT Audience and Issuer Validation in Access Token Validator
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
org.apache.cxf:cxf-rt-rs-security-jose-jaxrs: 4.2.0 → 4.2.2
Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection
Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory
Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory
org.apache.cxf:cxf-rt-transports-jms: 4.2.0 → 4.2.2
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control
Apache CXF OAuth2 has Inverted IP Binding Check that Defeats Security Control
org.apache.cxf:cxf-rt-rs-security-oauth2: 4.2.0 → 4.2.2
Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource
Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource
org.springframework.ws:spring-xml: 5.0.0 → 5.0.2
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
org.springframework.integration:spring-integration-file: 7.0.0 → 7.0.5
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
org.keycloak:keycloak-rest-admin-ui-ext: before 26.7.0
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1
Spring Web Services: X.509 authentication bypasses Spring Security account checks
Spring Web Services: X.509 authentication bypasses Spring Security account checks
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
io.netty:netty-codec-redis: 4.2.0.Final → 4.2.15.Final
Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Boot: Predictable Temp Directory in Artemis Auto-configuration
Spring Boot: Predictable Temp Directory in Artemis Auto-configuration
org.springframework.boot:spring-boot-autoconfigure: 4.0.0 → 4.0.7
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
org.springframework.boot:spring-boot-starter-mail: 4.0.0 → 4.0.7
Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations
org.springframework.ws:spring-ws-core: 5.0.0 → 5.0.2
Spring for GraphQL: Cross-Site WebSocket Hijacking
Spring for GraphQL: Cross-Site WebSocket Hijacking
org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4
Spring for GraphQL: Unsafe Deserialization
Spring for GraphQL: Unsafe Deserialization
org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4
Spring for GraphQL: Annotation Detection Vulnerability
Spring for GraphQL: Annotation Detection Vulnerability
org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4
Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default
Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Web Services: SOAP security faults leak Spring Security account state
Spring Web Services: SOAP security faults leak Spring Security account state
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Web Services: WSS4J validation does not use configured replay cache
Spring Web Services: WSS4J validation does not use configured replay cache
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
io.netty:netty-codec-haproxy: 4.2.0.Final → 4.2.15.Final
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
io.netty:netty-codec-http2: before 4.1.135.Final
Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL
Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL
org.jenkins-ci.main:jenkins-core: before 2.555.3
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries
Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries
org.springframework.data:spring-data-keyvalue: 4.0.0 → 4.0.6
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation
org.jenkins-ci.main:jenkins-core: before 2.555.3
Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL
Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL
org.jenkins-ci.main:jenkins-core: 2.556 → 2.568
Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"
Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"
org.jenkins-ci.main:jenkins-core: before 2.555.3
Jenkins: Missing permission check allows unauthorized cancellation of queue items
Jenkins: Missing permission check allows unauthorized cancellation of queue items
org.jenkins-ci.main:jenkins-core: before 2.555.3
Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache
Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache
org.springframework.security:spring-security-web: 7.0.0 → 7.0.6
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations
org.jenkins-ci.main:jenkins-core: before 2.555.3
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Data REST potentially exposes persistence-layer internals to HTTP clients
Spring Data REST potentially exposes persistence-layer internals to HTTP clients
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation
Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation
org.springframework.kafka:spring-kafka: 4.0.0 → 4.0.6
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4
Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository
Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference
org.springframework.data:spring-data-relational: 4.0.0 → 4.0.6
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter
Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter
org.springframework.security:spring-security-oauth2-authorization-server: 7.0.0 → 7.0.6
Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection
Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection
org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6
Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)
Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Spring Data REST has Improper Access Control in its JSON Patch Implementation
Spring Data REST has Improper Access Control in its JSON Patch Implementation
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization
Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization
org.springframework.pulsar:spring-pulsar: 2.0.0 → 2.0.6
Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference
Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference
org.springframework.restdocs:spring-restdocs-webtestclient: 4.0.0 → 4.0.1
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods
org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6
Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters
Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean
Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean
org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4
Jenkins exposes other users' timezone and view names to users with Overall/Read permission
Jenkins exposes other users' timezone and view names to users with Overall/Read permission
org.jenkins-ci.main:jenkins-core: before 2.555.3
Spring Framework Predictable Session ID in WebSocket Module
Spring Framework Predictable Session ID in WebSocket Module
org.springframework:spring-websocket: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Multipart Requests in WebFlux
Spring Framework Denial of Service via Multipart Requests in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.8
Spring LDAP has Authentication Bypass with Empty Password
Spring LDAP has Authentication Bypass with Empty Password
org.springframework.ldap:spring-ldap-core: 4.0.0 → 4.0.4
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Unbounded Cache in SpEL
Spring Framework Denial of Service via Unbounded Cache in SpEL
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Cross-site Scripting via JavaScriptUtils
Spring Framework Cross-site Scripting via JavaScriptUtils
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Spring Framework Algorithmic Denial of Service via SpEL Expressions
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Denial of Service via AntPathMatcher
Spring Framework Denial of Service via AntPathMatcher
org.springframework:spring-core: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
org.springframework:spring-expression: all versions
Spring Framework Open Redirect in Spring MVC and WebFlux
Spring Framework Open Redirect in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Cross-site Scripting via JSP Form Tags
Spring Framework Cross-site Scripting via JSP Form Tags
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Arbitrary Method Invocation in SpEL Expressions
Spring Framework Arbitrary Method Invocation in SpEL Expressions
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Micrometer HTTP server instrumentations DoS
Micrometer HTTP server instrumentations DoS
io.micrometer:micrometer-core: 1.16.0 → 1.16.6
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
org.springframework:spring-web: 7.0.0 → 7.0.8
Spring Framework Escalation via Session Fixation in WebFlux
Spring Framework Escalation via Session Fixation in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.8
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Micrometer gRPC server instrumentation DoS
Micrometer gRPC server instrumentation DoS
io.micrometer:micrometer-core: 1.16.0 → 1.16.6
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
org.springframework:spring-webflux: all versions
Spring HATEOAS heap exhaustion through unbounded internal caching
Spring HATEOAS heap exhaustion through unbounded internal caching
org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
io.projectreactor.netty:reactor-netty: 1.3.0 → 1.3.6
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
org.springframework.retry:spring-retry: 2.0.0 → 2.0.13
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final
Netty has Insufficient Bailiwick Validation for NS Records
Netty has Insufficient Bailiwick Validation for NS Records
io.netty:netty-resolver-dns: 4.2.0.Final → 4.2.15.Final
Keycloak has an Improper Verification of Cryptographic Signature issue
Keycloak has an Improper Verification of Cryptographic Signature issue
org.keycloak:keycloak-services: all versions
Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition
Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition
org.keycloak:keycloak-server: before 26.6.4
Keycloak has an Authentication Bypass by Primary Weakness
Keycloak has an Authentication Bypass by Primary Weakness
org.keycloak:keycloak-services: all versions
Keycloak Services has Improper Validation of Consistency within Input
Keycloak Services has Improper Validation of Consistency within Input
org.keycloak:keycloak-services: ≥ 26.5.0
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
com.squareup.wire:wire-runtime-jvm: before 6.3.0
Apache Wicket has a Path Traversal issue
Apache Wicket has a Path Traversal issue
org.apache.wicket:wicket-core: ≥ 8.0.0-M1
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
com.arcadedb:arcadedb-server: 21.10.1 → 26.4.2
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
org.apache.opennlp:opennlp-tools: 2.0.0 → 2.5.9
Quarkus has Authentication/Authorization bypasses
Quarkus has Authentication/Authorization bypasses
io.quarkus:quarkus-vertx-http: before 3.20.6.1
Jenkins GitHub Plugin has an XSS vulnerability
Jenkins GitHub Plugin has an XSS vulnerability
com.coravy.hudson.plugins.github:github: before 1.46.0.1
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
org.eclipse.jetty:jetty-http: 12.1.0 → 12.1.7
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
org.apache.tomcat:tomcat-tribes: 9.0.13 → 9.0.117
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
io.opentelemetry.javaagent:opentelemetry-javaagent: before 2.26.1
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
org.xwiki.contrib.blog:application-blog-ui: 9.15 → 9.15.7
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
tools.jackson.core:jackson-core: 3.0.0 → 3.1.0
carbon-apimgt does not properly restrict uploaded files
carbon-apimgt does not properly restrict uploaded files
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1: before 9.32.167
Eclipse Jersey has a Race Condition
Eclipse Jersey has a Race Condition
org.glassfish.jersey.core:jersey-client: 2.45 → 2.46
Keycloak Potential Variable Reference in Model Storage Services
Keycloak Potential Variable Reference in Model Storage Services
org.keycloak:keycloak-model-storage-services: all versions
jinjava has Sandbox Bypass via JavaType-Based Deserialization
jinjava has Sandbox Bypass via JavaType-Based Deserialization
com.hubspot.jinjava:jinjava: 2.8.0 → 2.8.1
Keycloak vulnerable to two factor authentication bypass
Keycloak vulnerable to two factor authentication bypass
org.keycloak:keycloak-services: before 26.2.2
Keycloak hostname verification
Keycloak hostname verification
org.keycloak:keycloak-services: before 26.2.2
Jenkins Missing Permission Check
Jenkins Missing Permission Check
org.jenkins-ci.main:jenkins-core: 2.500 → 2.504
Jenkins Missing Permission Check
Jenkins Missing Permission Check
org.jenkins-ci.main:jenkins-core: 2.500 → 2.504
Spring Security Vulnerable to Authorization Bypass via Security Annotations
Spring Security Vulnerable to Authorization Bypass via Security Annotations
org.springframework.security:spring-security-core: 6.4.0 → 6.4.4
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
org.keycloak:keycloak-ldap-federation: 26.1.0 → 26.1.3
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
org.jenkins-ci.main:jenkins-core: before 2.492.2
Jenkins cross-site request forgery (CSRF) vulnerability
Jenkins cross-site request forgery (CSRF) vulnerability
org.jenkins-ci.main:jenkins-core: 2.493 → 2.500
Jenkins Open Redirect vulnerability
Jenkins Open Redirect vulnerability
org.jenkins-ci.main:jenkins-core: before 2.492.2
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
org.jenkins-ci.main:jenkins-core: 2.493 → 2.500
Missing permission check in Jenkins Script Security Plugin
Missing permission check in Jenkins Script Security Plugin
org.jenkins-ci.plugins:script-security: before 1368.vb
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.0-M21
XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
com.thoughtworks.xstream:xstream: before 1.4.21
Keycloak has session fixation in Elytron SAML adapters
Keycloak has session fixation in Elytron SAML adapters
org.keycloak:keycloak-services: before 22.0.12
JSON-lib mishandles an unbalanced comment string
JSON-lib mishandles an unbalanced comment string
org.kordamp.json:json-lib-core: before 3.1.0
Jenkins item creation restriction bypass vulnerability
Jenkins item creation restriction bypass vulnerability
org.jenkins-ci.main:jenkins-core: before 2.462.3
Jenkins exposes multi-line secrets through error messages
Jenkins exposes multi-line secrets through error messages
org.jenkins-ci.main:jenkins-core: before 2.462.3
Apache MINA SSHD: integrity check bypass
Apache MINA SSHD: integrity check bypass
org.apache.sshd:sshd-common: before 2.12.0
CometVisu Backend for openHAB affected by SSRF/XSS
CometVisu Backend for openHAB affected by SSRF/XSS
org.openhab.ui.bundles:org.openhab.ui.cometvisu: 3.4.0.M4 → 4.2.1
Jenkins Remoting library arbitrary file read vulnerability
Jenkins Remoting library arbitrary file read vulnerability
org.jenkins-ci.main:remoting: before 3206.3208
Jenkins does not perform a permission check in an HTTP endpoint
Jenkins does not perform a permission check in an HTTP endpoint
org.jenkins-ci.main:jenkins-core: before 2.452.4
GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service
GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service
com.graphql-java:graphql-java: before 19.11
Exposure of secrets through system log in Jenkins Structs Plugin
Exposure of secrets through system log in Jenkins Structs Plugin
org.jenkins-ci.plugins:structs: before 338.v848422169819
Keycloak's admin API allows low privilege users to use administrative functions
Keycloak's admin API allows low privilege users to use administrative functions
org.keycloak:keycloak-services: before 24.0.5
Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
org.keycloak:keycloak-services: before 24.0.5
Neo4j Cypher component mishandles IMMUTABLE privileges
Neo4j Cypher component mishandles IMMUTABLE privileges
org.neo4j:neo4j-cypher: 5.0.0 → 5.19.0
Jenkins Script Security Plugin sandbox bypass vulnerability
Jenkins Script Security Plugin sandbox bypass vulnerability
org.jenkins-ci.plugins:script-security: before 1336.vf33a
Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
org.jenkins-ci.plugins:script-security: before 1336.vf33a
Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode
Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode
org.apache.kafka:kafka-metadata: 3.5.0 → 3.6.2
quarkus-core leaks local environment variables from Quarkus namespace during application's build
quarkus-core leaks local environment variables from Quarkus namespace during application's build
io.quarkus:quarkus-core: 3.9.0.CR1 → 3.9.2
Elasticsearch Incorrect Authorization vulnerability
Elasticsearch Incorrect Authorization vulnerability
org.elasticsearch:elasticsearch: 8.10.0 → 8.13.0
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
org.apache.tomcat:tomcat-websocket: 11.0.0-M1 → 11.0.0-M17
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.0-M17
Path traversal vulnerability in Jenkins Matrix Project Plugin
Path traversal vulnerability in Jenkins Matrix Project Plugin
org.jenkins-ci.plugins:matrix-project: before 822.824.v14451b
Cross-site WebSocket hijacking vulnerability in the Jenkins CLI
Cross-site WebSocket hijacking vulnerability in the Jenkins CLI
org.jenkins-ci.main:jenkins-core: 2.217 → 2.426.3
Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
org.jenkins-ci.main:jenkins-core: 1.606 → 2.426.3
Spring Framework server Web DoS Vulnerability
Spring Framework server Web DoS Vulnerability
org.springframework:spring-core: 6.1.2 → 6.1.3
Reactor Netty HTTP Server denial of service vulnerability
Reactor Netty HTTP Server denial of service vulnerability
io.projectreactor.netty:reactor-netty-core: 1.1.0 → 1.1.13
Apache Tomcat Improper Input Validation vulnerability
Apache Tomcat Improper Input Validation vulnerability
org.apache.tomcat:tomcat-catalina: 11.0.0-M1 → 11.0.0-M11
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
org.apache.cassandra:cassandra-all: 4.1.0 → 4.1.2
json-smart Uncontrolled Recursion vulnerability
json-smart Uncontrolled Recursion vulnerability
net.minidev:json-smart: before 2.4.9
Cross-site Scripting vulnerability in Jenkins
Cross-site Scripting vulnerability in Jenkins
org.jenkins-ci.main:jenkins-core: 2.376 → 2.394
Incorrect Authorization in Jenkins Core
Incorrect Authorization in Jenkins Core
org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1
Incorrect Permission Preservation in Jenkins Core
Incorrect Permission Preservation in Jenkins Core
org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1
Information disclosure through error stack traces related to agents
Information disclosure through error stack traces related to agents
org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1
Incorrect Authorization in Jenkins Core
Incorrect Authorization in Jenkins Core
org.jenkins-ci.main:jenkins-core: 2.376 → 2.387.1
Apache Commons FileUpload denial of service vulnerability
Apache Commons FileUpload denial of service vulnerability
commons-fileupload:commons-fileupload: before 1.5
HAProxyMessageDecoder Stack Exhaustion DoS
HAProxyMessageDecoder Stack Exhaustion DoS
io.netty:netty-codec-haproxy: before 4.1.86.Final
Local Information Disclosure Vulnerability in io.netty:netty-codec-http
Local Information Disclosure Vulnerability in io.netty:netty-codec-http
io.netty:netty-codec-http: before 4.1.77.Final
Observable Discrepancy in Apache Kafka
Observable Discrepancy in Apache Kafka
org.apache.kafka:kafka_2.11: ≥ 2.0.0
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
org.apache.tomcat.embed:tomcat-embed-core: 10.0.0-M1 → 10.0.2
Information Disclosure in Apache Tomcat
Information Disclosure in Apache Tomcat
org.apache.tomcat.embed:tomcat-embed-core: 10.0.0-M1 → 10.0.0-M10
Potential remote code execution in Apache Tomcat
Potential remote code execution in Apache Tomcat
org.apache.tomcat.embed:tomcat-embed-core: 10.0.0-M1 → 10.0.2
XML External Entity (XXE) Injection in Jackson Databind
XML External Entity (XXE) Injection in Jackson Databind
com.fasterxml.jackson.core:jackson-databind: 2.6.0 → 2.6.7.4
Deserialization of untrusted data in Jackson Databind
Deserialization of untrusted data in Jackson Databind
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.5
Deserialization of untrusted data in Jackson Databind
Deserialization of untrusted data in Jackson Databind
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.5
Deserialization of untrusted data in Jackson Databind
Deserialization of untrusted data in Jackson Databind
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.5
Deserialization of untrusted data in Jackson Databind
Deserialization of untrusted data in Jackson Databind
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.5
Deserialization of Untrusted Data
Deserialization of Untrusted Data
com.fasterxml.jackson.core:jackson-databind: 2.7.0 → 2.7.9.4
Improper Privilege Management in Tomcat
Improper Privilege Management in Tomcat
org.apache.tomcat.embed:tomcat-embed-core: 9.0.0 → 9.0.31
jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4
jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4
jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4
jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4
jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4
Polymorphic deserialization of malicious object in jackson-databind
Polymorphic deserialization of malicious object in jackson-databind
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10
jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4
jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4
jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4
jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.10.4
Potential HTTP request smuggling in Apache Tomcat
Potential HTTP request smuggling in Apache Tomcat
org.apache.tomcat.embed:tomcat-embed-core: before 7.0.100
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
org.apache.tomcat.embed:tomcat-embed-core: before 7.0.99
Insufficiently Protected Credentials in Apache Tomcat
Insufficiently Protected Credentials in Apache Tomcat
org.apache.tomcat.embed:tomcat-embed-core: before 7.0.99
Server-Side Request Forgery (SSRF) in jackson-databind
Server-Side Request Forgery (SSRF) in jackson-databind
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.7
XML External Entity Reference (XXE) in jackson-databind
XML External Entity Reference (XXE) in jackson-databind
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.7
Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization
Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization
com.fasterxml.jackson.core:jackson-databind: 2.9.0 → 2.9.8
Deserialization of Untrusted Data in jackson-databind
Deserialization of Untrusted Data in jackson-databind
com.fasterxml.jackson.core:jackson-databind: 2.7.0 → 2.7.9.5
Tooling for Maven
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.