Tagged “maven”
CVEs tagged maven, newest first.
321 CVEsRSS
CVE-2026-59949Medium· 6.5yawkat LZ4 Java provides LZ4 compression for Java
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.n…
CVE-2026-59903Medium· 6.5PoCNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…
CVE-2026-59902High· 7.5Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedByt…
CVE-2026-55153High· 7.1mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
CVE-2026-49989LowCrateDB is a distributed SQL database
CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s…
CVE-2026-48791Low· 2.0sigstore-java is a sigstore java client for interacting with sigstore infrastructure
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verifi…
CVE-2026-73247High· 8.6Kestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the s…
CVE-2026-73245Medium· 6.5Kestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /a…
CVE-2026-8798HighBouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound
Bouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound
CVE-2026-13505High· 7.5org.bouncycastle/bc-fips: Bouncy Castle for Java FIPS: Sensitive key material remains in memory due to delayed zeroisation (CVE-2026-13505)
A flaw was found in Bouncy Castle for Java FIPS (BC-FJA). Sensitive cryptographic key material, intended to be securely erased from memory (zeroised) upon garbage collection, may persist longer than expected. This occurs because the zerois…
CVE-2026-56818Medium· 6.5Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…
CVE-2026-71497Medium· 4.7jsoup is a Java library for working with real-world HTML
jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a dif…
CVE-2026-13506High· 7.5In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri…
CVE-2026-8763High· 7.4In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.…
CVE-2026-53573MediumGeoNetwork is a catalog application to manage spatially referenced resources
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits…
CVE-2026-54712Medium· 5.3OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
CVE-2026-54704Medium· 6.5OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
CVE-2026-54079HighveraPDF Validation XXE via XFA
veraPDF Validation XXE via XFA
CVE-2026-54078HighveraPDF Validation XXE via Rich Text
veraPDF Validation XXE via Rich Text
CVE-2026-54082Medium· 6.5veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
CVE-2026-54080MediumveraPDF Parser DoS via PostScript CMap Streams
veraPDF Parser DoS via PostScript CMap Streams
CVE-2026-54081MediumveraPDF Parser DoS via PostScript Type 1 Font Programs
veraPDF Parser DoS via PostScript Type 1 Font Programs
CVE-2026-54609High· 8.6QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVE-2026-55771High· 8.8Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
CVE-2026-43910High· 8.2java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
CVE-2023-37465Medium· 6.5org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
GHSA-68r5-9hpg-7qw9Critical· 9.4OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
GHSA-p279-2cqp-84jgCritical· 9.6OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
GHSA-mhvj-jhpq-885vHigh· 7.4blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
GHSA-46q4-43ph-c6frHigh· 7.4blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)