CVE-2026-84218High· 7.5▾ Twilightjolokia-service-jsr160 Incomplete target JMX Service URL deny list handling for user-controlled input
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.9%
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a target.url value from a Jolokia POST request and passes it to JMXServiceURL and JMXConnectorFactory for establishing the remote JMX connection. The existing denylist only rejects URLs matching service:jmx:rmi:///jndi/ldap:.*, which can be bypassed using alternative valid JMX service URL forms, including ldaps:// schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid JMXServiceURL objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.
org.jolokia:jolokia-service-jsr160 < 2.6.2Upgrade to a patched release:
org.jolokia:jolokia-service-jsr160 2.6.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54512High· 8.1jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
CVE-2026-54513High· 8.1jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
CVE-2025-67748High· 7.8Fickling is a Python pickling decompiler and static analyzer
CVE-2026-106556High· 7.7Backstage is an open framework for building developer portals
CVE-2026-33396Critical· 9.9OneUptime is an open-source monitoring and observability platform
CVE-2026-106445Critical· 9.2Handlebars provides the power necessary to let users build semantic templates