VulnSea

org.yamcs:yamcs-core vulnerabilities

CVEs whose affected-version data names the org.yamcs:yamcs-core package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-55559Critical· 9.8
4w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templat…

▾ Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.55%via NVD
CVE-2026-55565Critical· 9.9
4w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source c…

▾ Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.46%via NVD
CVE-2026-55566Medium· 4.3
4w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.27%via NVD
CVE-2026-55511Critical· 9.1PoC
4w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fil…

▾ Abyssalyamcs · org.yamcs:yamcs-coreEPSS 0.68%via NVD
CVE-2026-55521High· 8.8
4w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and T…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.36%via NVD
CVE-2026-55545Medium· 6.5
4w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.33%via NVD
CVE-2026-55547Medium· 4.3
4w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.jav…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.25%via NVD
CVE-2026-55549Medium· 6.5PoC
4w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping b…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.90%via NVD
CVE-2026-55552High· 7.5
4w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.43%via NVD
org.yamcs:yamcs-core vulnerabilities (CVEs) · VulnSea