CVE-2026-55771High· 8.8▾ TwilightCedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 28.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.6%
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. Under certain circumstances, it could lead to incorrect equality comparisons.
EntityIdentifier.equals() has inverted null/self branches
The EntityIdentifier.equals() method has inverted logic for null and self-reference checks, returning true for null comparisons and false for self-comparisons. This does not affect Cedar authorization decisions (computed in Rust from JSON), but could affect integrators who perform their own equality checks on entity identifiers.
< 4.9
It has been addressed in CedarJava version 4.9 and above. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Avoid relying on EntityIdentifier.equals() for security-sensitive comparisons until upgraded to version 4.9.
If you have any questions or comments about this advisory, Cedar asks that you contact us directly via email to [email protected]. Please do not create a public GitHub issue.
com.cedarpolicy:cedar-java < 2.3.6com.cedarpolicy:cedar-java >= 3.1.2, < 3.4.1com.cedarpolicy:cedar-java >= 4.0.0, < 4.9.0Upgrade to a patched release:
com.cedarpolicy:cedar-java 2.3.6com.cedarpolicy:cedar-java 3.4.1com.cedarpolicy:cedar-java 4.9.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55772High· 8.8CedarJava has type confusion vulnerability
CVE-2026-55773High· 8.8CedarJava has policy injection vulnerability
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2026-33940High· 8.1Handlebars provides the power necessary to let users build semantic templates
CVE-2026-33937Critical· 9.8Handlebars provides the power necessary to let users build semantic templates
CVE-2025-13786High· 7.3A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665