VulnSea

Tagged “maven”

CVEs tagged maven, newest first.

321 CVEsRSS

CVE-2026-41726Medium· 6.5
3mo ago

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

▾ Sunlitspringframework · org.springframework.kafka:spring-kafkaEPSS 0.42%via GHSA
CVE-2026-47838Medium· 6.8
3mo ago

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

▾ Sunlitspringframework · org.springframework.security:spring-security-webEPSS 0.19%via GHSA
CVE-2025-53114High· 7.5
3mo ago

Acknowledgement extension out of memory

Acknowledgement extension out of memory

▾ Twilightcometd · org.cometd.java:cometd-java-server-commonEPSS 0.68%via GHSA
CVE-2026-40984High· 7.5
3mo ago

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.1…

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.1…

▾ TwilightSpring · micrometer-coreEPSS 1.1%via NVD
CVE-2026-40983High· 7.5
3mo ago

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

▾ TwilightSpring · MicrometerEPSS 0.85%via NVD
CVE-2026-41855High· 8.1
3mo ago

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…

▾ Twilightspringframework · org.springframework:spring-jmsEPSS 0.48%via NVD
CVE-2026-44892High· 7.5
3mo ago

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

▾ Twilightnetty · io.netty:netty-codec-http3EPSS 0.49%via GHSA
CVE-2026-44894High· 7.5
3mo ago

Netty's Default QUIC token handler accepts any client-supplied token

Netty's Default QUIC token handler accepts any client-supplied token

▾ Twilightnetty · io.netty:netty-codec-classes-quicEPSS 0.19%via GHSA
CVE-2026-44503High
4mo ago

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

▾ Twilightmicrosoft · com.microsoft.kiota:microsoft-kiota-abstractionsEPSS 0.84%via OSV
CVE-2026-42027Critical· 9.8⚖ disputed
4mo ago

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, String) method loa…

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, String) method loa…

▾ Midnightapache · opennlpEPSS 1.3%via NVD
CVE-2025-14813High· 7.5
5mo ago

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects B…

▾ TwilightLegion of the Bouncy Castle Inc. · bcprovEPSS 0.32%via NVD
CVE-2025-37731Medium· 6.8
9mo ago

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

▾ Sunlitelasticsearch · org.elasticsearch.plugin:x-pack-securityEPSS 0.19%via GHSA
CVE-2025-67505High· 8.4
9mo ago

Okta Java Management SDK facilitates interactions with the Okta management API

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response h…

▾ Twilightokta · java_management_sdkEPSS 0.21%via NVD
CVE-2024-52980Medium· 6.5
1y ago

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

▾ Sunlitelasticsearch · org.elasticsearch:elasticsearch-grokEPSS 0.54%via GHSA
CVE-2024-49771Medium· 5.3
1y ago

MPXJ has a Potential Path Traversal Vulnerability

MPXJ has a Potential Path Traversal Vulnerability

▾ Sunlitsf · net.sf.mpxj:mpxjEPSS 0.48%via OSV
CVE-2023-41329Low· 3.9
3y ago

Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes

Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes

▾ Sunlitwiremock · org.wiremock:wiremock-standaloneEPSS 0.63%via OSV
CVE-2023-32732Medium· 5.3
3y ago

gRPC connection termination issue

gRPC connection termination issue

▾ Sunlitgrpc · io.grpc:grpc-protobufEPSS 0.53%via OSV
CVE-2023-1428High· 7.5
3y ago

gRPC Reachable Assertion issue

gRPC Reachable Assertion issue

▾ Twilightgrpc · io.grpc:grpc-protobufEPSS 0.41%via OSV
CVE-2023-32731High· 7.4
3y ago

Connection confusion in gRPC

Connection confusion in gRPC

▾ Twilightgrpc · io.grpc:grpc-protobufEPSS 0.50%via OSV
CVE-2023-34620High· 7.5
3y ago

hjson stack exhaustion vulnerability

hjson stack exhaustion vulnerability

▾ Twilighthjson · org.hjson:hjsonEPSS 0.78%via OSV
CVE-2020-8897High· 8.1
4y ago

Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustness

Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustness

▾ Twilightamazonaws · com.amazonaws:aws-encryption-sdk-javaEPSS 0.40%via OSV
CVEs tagged “maven” — page 11 · VulnSea