VulnSea

Tagged “maven”

CVEs tagged maven, newest first.

321 CVEsRSS

CVE-2026-59949Medium· 6.5
1mo ago

yawkat LZ4 Java provides LZ4 compression for Java

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.n…

▾ Sunlityawk · at.yawk.lz4:lz4-javaEPSS 0.47%via NVD
CVE-2026-59903Medium· 6.5PoC
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…

▾ Twilightnetty · nettyEPSS 0.25%via NVD
CVE-2026-59902High· 7.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedByt…

▾ Twilightnetty · nettyEPSS 0.67%via NVD
CVE-2026-55153High· 7.1
1mo ago

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

▾ Twilightmchange · com.mchange:mchange-commons-javaEPSS 0.59%via GHSA
CVE-2026-49989Low
1mo ago

CrateDB is a distributed SQL database

CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s…

▾ Sunlitcrate · io.crate:crateEPSS 0.47%via NVD
CVE-2026-48791Low· 2.0
1mo ago

sigstore-java is a sigstore java client for interacting with sigstore infrastructure

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verifi…

▾ Sunlitsigstore · dev.sigstore:sigstore-javaEPSS 0.07%via NVD
CVE-2026-73247High· 8.6
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the s…

▾ Twilightkestra · io.kestra:coreEPSS 0.41%via NVD
CVE-2026-73245Medium· 6.5
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /a…

▾ Sunlitkestra · io.kestra:kestraEPSS 0.33%via NVD
CVE-2026-8798High
1mo ago

Bouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound

Bouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound

▾ Twilightbouncycastle · org.bouncycastle:bc-fipsEPSS 0.43%via GHSA
CVE-2026-13505High· 7.5
1mo ago

org.bouncycastle/bc-fips: Bouncy Castle for Java FIPS: Sensitive key material remains in memory due to delayed zeroisation (CVE-2026-13505)

A flaw was found in Bouncy Castle for Java FIPS (BC-FJA). Sensitive cryptographic key material, intended to be securely erased from memory (zeroised) upon garbage collection, may persist longer than expected. This occurs because the zerois…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform Expansion PackEPSS 0.25%via CSAF
CVE-2026-56818Medium· 6.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…

▾ Sunlitnetty · nettyEPSS 0.47%via NVD
CVE-2026-71497Medium· 4.7
1mo ago

jsoup is a Java library for working with real-world HTML

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a dif…

▾ Sunlitjsoup · org.jsoup:jsoupEPSS 0.30%via NVD
CVE-2026-13506High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri…

▾ Twilightbouncycastle · bc-javaEPSS 0.44%via NVD
CVE-2026-8763High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.…

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.45%via NVD
CVE-2026-53573Medium
1mo ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits…

▾ Sunlitgeonetwork-opensource · org.geonetwork-opensource:geonetworkEPSS 0.65%via NVD
CVE-2026-54712Medium· 5.3
2mo ago

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

▾ Sunlitopentelemetry · io.opentelemetry.javaagent:opentelemetry-javaagentEPSS 0.46%via GHSA
CVE-2026-54704Medium· 6.5
2mo ago

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

▾ Sunlitopentelemetry · io.opentelemetry.javaagent:opentelemetry-javaagentEPSS 0.38%via GHSA
CVE-2026-54079High
2mo ago

veraPDF Validation XXE via XFA

veraPDF Validation XXE via XFA

▾ Twilightverapdf · org.verapdf:validation-modelEPSS 0.56%via GHSA
CVE-2026-54078High
2mo ago

veraPDF Validation XXE via Rich Text

veraPDF Validation XXE via Rich Text

▾ Twilightverapdf · org.verapdf:validation-modelEPSS 0.56%via GHSA
CVE-2026-54082Medium· 6.5
2mo ago

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

▾ Sunlitverapdf · org.verapdf:validation-modelEPSS 0.40%via GHSA
CVE-2026-54080Medium
2mo ago

veraPDF Parser DoS via PostScript CMap Streams

veraPDF Parser DoS via PostScript CMap Streams

▾ Sunlitverapdf · org.verapdf:parserEPSS 0.52%via GHSA
CVE-2026-54081Medium
2mo ago

veraPDF Parser DoS via PostScript Type 1 Font Programs

veraPDF Parser DoS via PostScript Type 1 Font Programs

▾ Sunlitverapdf · org.verapdf:parserEPSS 0.52%via GHSA
CVE-2026-54609High· 8.6
2mo ago

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

▾ Twilightquietterminal · com.quietterminal:qti-neonEPSS 0.46%via GHSA
CVE-2026-55771High· 8.8
2mo ago

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.57%via GHSA
CVE-2026-43910High· 8.2
2mo ago

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

▾ Twilightappium · io.appium:java-clientEPSS 0.43%via GHSA
CVE-2023-37465Medium· 6.5
2mo ago

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

▾ Sunlitxwiki · org.xwiki.contrib:discussions-servervia GHSA
GHSA-68r5-9hpg-7qw9Critical· 9.4
2mo ago

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

▾ Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-dsml-servletvia GHSA
GHSA-p279-2cqp-84jgCritical· 9.6
2mo ago

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

▾ Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-server-legacyvia GHSA
GHSA-mhvj-jhpq-885vHigh· 7.4
2mo ago

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

▾ Twilighthttp4s · org.http4s:http4s-blaze-server_2.13via GHSA
GHSA-46q4-43ph-c6frHigh· 7.4
2mo ago

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

▾ Twilighthttp4s · org.http4s:blaze-http_2.13via GHSA
CVEs tagged “maven” — page 5 · VulnSea