Tagged “maven”
CVEs tagged maven, newest first.
321 CVEsRSS
CVE-2026-49268HighPoCApache Shiro: LDAP DN Injection in DefaultLdapRealm
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
CVE-2026-55405High· 7.6LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
CVE-2026-55760High· 7.5handlebars.java FileTemplateLoader Path Traversal
handlebars.java FileTemplateLoader Path Traversal
CVE-2026-55470High· 7.5HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
CVE-2026-55471CriticalHAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
CVE-2026-48748High· 7.5Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
CVE-2026-50009Medium· 4.8Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
CVE-2026-45536Medium· 4.0netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message han…
A flaw was found in Netty, a network application framework. A local attacker could exploit a vulnerability in the `netty_unix_socket_recvFd` function when handling `SCM_RIGHTS` messages in `Epoll` or `KQueue DomainSocketChannel` with `Doma…
CVE-2026-45673Medium· 6.8netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs (CVE-2026-45673)
A flaw was found in Netty's DNS resolver component. This vulnerability arises from the use of a predictable pseudo-random number generator (PRNG) for DNS transaction IDs and a static User Datagram Protocol (UDP) source port. This combinati…
CVE-2026-46340High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments…
CVE-2026-47244Medium· 5.3netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams (CVE-2026-47244)
A flaw was found in Netty, a network application framework. A remote attacker can exploit this vulnerability by sending a large number of HTTP/2 stream requests to a Netty HTTP/2 server. If the server does not explicitly limit concurrent s…
CVE-2026-48006High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipe…
CVE-2025-52465High· 7.2GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
CVE-2025-58175Medium· 6.5GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
GHSA-9wcp-79g5-5c3cHigh· 8.1Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators
Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators
GHSA-j9gf-vw2f-9hrwHigh· 8.1Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
GHSA-ch3q-cw5r-f4hgMediumConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
GHSA-vc8p-8pxg-rfwgMediumConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
CVE-2026-50011High· 7.5PoCNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…
CVE-2026-50020Medium· 5.3netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder (CVE-2026-50020)
A flaw was found in Netty. The HttpObjectDecoder component, which processes incoming HTTP requests, incorrectly skips certain control characters and whitespace before reading the first request line. This behavior, which goes beyond standar…
CVE-2026-50560Medium· 5.3netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling (CVE-2026-50560)
A flaw was found in Netty, a network application framework. A remote attacker can exploit a vulnerability in the HTTP/2 (Hypertext Transfer Protocol version 2) maximum header size handling. By sending a specific SETTINGS_MAX_HEADER_LIST_SI…
CVE-2026-48059High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when…
CVE-2026-48043Medium· 5.3⚖ disputedNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompre…
CVE-2026-47691High· 8.7Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Ca…
CVE-2026-45674High· 8.7PoCNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…
CVE-2026-44250High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nes…
CVE-2026-44890High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple …
CVE-2026-48040Mediumnetty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
CVE-2025-27511High· 7.2GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
CVE-2026-41731High· 8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization