VulnSea

Tagged “maven”

CVEs tagged maven, newest first.

276 CVEsRSS

CVE-2026-85058High· 7.5
3d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths…

Twilightmoquette · io.moquette:moquette-brokerEPSS 0.27%via NVD
CVE-2025-53837Critical· 9.9
3d ago

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile o…

Midnightxwiki · xwiki-renderingEPSS 0.64%via NVD
CVE-2026-54147Medium· 6.5
3d ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response wit…

Sunlithttp4k · http4kEPSS 0.20%via NVD
CVE-2026-54148High· 8.1
3d ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the …

Twilighthttp4k · http4kEPSS 0.33%via NVD
CVE-2026-77615High· 8.7
4d ago

Paella Player is a set of libraries to create a multi stream video player

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability i…

Twilightopencastproject · org.opencastproject:opencast-engage-paella-player-7EPSS 0.39%via NVD
CVE-2026-85716Low· 3.7
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM…

SunlitAsyncHttpClient · async-http-clientEPSS 0.32%via NVD
CVE-2026-85720Medium· 5.9
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose p…

Sunlitasynchttpclient · org.asynchttpclient:async-http-clientEPSS 0.25%via NVD
CVE-2026-85721High· 7.5PoC
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelM…

Midnightasynchttpclient · org.asynchttpclient:async-http-clientEPSS 0.35%via NVD
CVE-2026-85717Medium· 6.8
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redire…

SunlitAsyncHttpClient · async-http-clientEPSS 0.33%via NVD
CVE-2026-54617Critical· 9.8
4d ago

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274…

MidnightGravitLauncher · LauncherEPSS 0.68%via NVD
CVE-2026-86071Low· 3.7
5d ago

Junrar is an open source Java RAR archive library

Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when processing a cr…

Sunlitjunrar · junrarEPSS 0.30%via NVD
CVE-2026-63126High· 7.5PoC
5d ago

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary b…

Midnightsquare · wireEPSS 0.68%via NVD
CVE-2026-75516High· 8.7
5d ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune ne…

Twilightrabbitmq · rabbitmq-java-clientEPSS 0.53%via NVD
CVE-2026-81875High· 7.5PoC
5d ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker…

Midnighthapifhir · org.hl7.fhir.coreEPSS 0.63%via NVD
CVE-2026-81876High· 7.5
5d ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter an infinit…

Twilighthapifhir · org.hl7.fhir.coreEPSS 0.63%via NVD
CVE-2026-69215Medium· 6.8
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie.…

Sunlithttp4s · org.http4s:http4s-client_2.12EPSS 0.43%via NVD
CVE-2026-69218High· 7.5
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 HEADERS or PUSH_PROMISE frame without END_HEADERS, H2Connection buffers the header block and subsequent CONTINUATION fragments w…

Twilighthttp4s · http4sEPSS 0.46%via NVD
CVE-2026-69206Medium· 5.9
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastNc plus one instead of the highest nonce-count value it has accepted. When a legitimate client sends noncontiguous nc…

Sunlithttp4s · http4sEPSS 0.33%via NVD
CVE-2026-88975High· 7.5
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An u…

Twilighthttp4s · http4sEPSS 0.62%via NVD
CVE-2026-69205High· 8.7
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a case-sensitive substring test for the Transfer-Encoding value and decodes header bytes with the platform default charset. Values …

Twilighthttp4s · org.http4s:http4s-ember-core_3EPSS 0.40%via NVD
CVE-2026-69203High· 7.5
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled through withHttp2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS for peer-created streams. One unauthenticated connectio…

Twilighthttp4s · org.http4s:http4s-ember-core_2.12EPSS 0.46%via NVD
CVE-2026-69202High· 7.5
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control window is replenished according to bytes received from the network rather than bytes consumed by the application, while each strea…

Twilighthttp4s · org.http4s:http4s-ember-core_2.12EPSS 0.44%via NVD
CVE-2026-69216Medium· 5.4
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of requiring one or more hexadecimal digits followed by the r…

Sunlithttp4s · http4sEPSS 0.24%via NVD
CVE-2026-69214Medium· 6.8
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejec…

Sunlithttp4s · http4sEPSS 0.26%via NVD
CVE-2026-69213High· 7.5
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can c…

Twilighthttp4s · http4sEPSS 0.36%via NVD
CVE-2026-69208High· 7.5
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the first stale nonce because its stale-nonce comparison is inverted. On an applic…

Twilighthttp4s · http4sEPSS 0.41%via NVD
CVE-2026-69204Critical· 9.2
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing r…

Midnighthttp4s · http4sEPSS 0.33%via NVD
CVE-2026-69201Medium· 5.9
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments exactly equal to an empty string, a dot, or two dots. A request contai…

Sunlithttp4s · org.http4s:http4s-server_2.12EPSS 0.63%via NVD
CVE-2026-55864High· 7.8
6d ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without destination validati…

Twilightgeonetwork · core-geonetworkEPSS 0.59%via NVD
CVE-2026-54050Medium· 6.5PoC
6d ago

Sakai is a Collaboration and Learning Environment (CLE)

Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.r…

Twilightsakaiproject · sakaiEPSS 0.31%via NVD
CVEs tagged “maven” · VulnSea