VulnSea

Tagged “maven”

CVEs tagged maven, newest first.

321 CVEsRSS

GHSA-7ppr-r889-mcf2High· 7.5
2mo ago

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

▾ Twilighthttp4s · org.http4s:http4s-blaze-server_2.13via GHSA
GHSA-fp43-vj7g-pg92High· 7.5
2mo ago

OmniFaces: Forged combined-resource IDs and related output/push boundaries

OmniFaces: Forged combined-resource IDs and related output/push boundaries

▾ Twilightomnifaces · org.omnifaces:omnifacesvia GHSA
GHSA-mfg7-5gfp-c4w3Medium· 5.3
2mo ago

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

▾ Sunlitnetty · io.netty:netty-codec-dnsvia GHSA
GHSA-v74w-7mr3-4qg3High· 7.5
2mo ago

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

▾ Twilightnetty · io.netty:netty-codec-xmlvia GHSA
CVE-2026-55223Medium
2mo ago

c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets

c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets

▾ Sunlitmchange · com.mchange:c3p0EPSS 0.48%via GHSA
CVE-2026-6790Medium· 5.3
2mo ago

Eclipse Jetty: HTTP Authority/Host mismatch

Eclipse Jetty: HTTP Authority/Host mismatch

▾ Sunliteclipse · org.eclipse.jetty:jetty-serverEPSS 0.31%via GHSA
CVE-2026-8384Medium· 5.3
2mo ago

Eclipse Jetty: Path parameter traversal

Eclipse Jetty: Path parameter traversal

▾ Sunliteclipse · org.eclipse.jetty:jetty-utilEPSS 0.33%via GHSA
CVE-2024-7708High· 7.5
2mo ago

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

▾ Twilighteclipse · org.eclipse.jetty:jetty-serverEPSS 0.44%via GHSA
CVE-2026-56821High· 7.4
2mo ago

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

▾ Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.22%via GHSA
CVE-2026-56822High· 7.4
2mo ago

Netty: TOCTOU in OcspServerCertificateValidator

Netty: TOCTOU in OcspServerCertificateValidator

▾ Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.17%via GHSA
CVE-2026-59898Medium
2mo ago

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

▾ Sunlitnetty · io.netty:netty-codec-httpEPSS 0.44%via GHSA
CVE-2026-59900Medium
2mo ago

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

▾ Sunlitnetty · io.netty:netty-codec-http2EPSS 0.40%via GHSA
CVE-2026-59919Medium· 5.5
2mo ago

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

▾ Sunlitnetty · io.netty:netty-codec-haproxyEPSS 0.17%via GHSA
CVE-2026-59920Medium· 6.5
2mo ago

Netty: STOMP CONNECT Frame Header Injection in Netty

Netty: STOMP CONNECT Frame Header Injection in Netty

▾ Sunlitnetty · io.netty:netty-codec-stompEPSS 0.41%via GHSA
CVE-2026-59921Medium· 5.7
2mo ago

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

▾ Sunlitnetty · io.netty:netty-codec-httpEPSS 0.46%via GHSA
CVE-2026-56819High· 7.5PoC
2mo ago

io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819)

A flaw was found in Netty, a network application framework. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP/2 DATA frames to applications that use Netty and have HTTP/2 content decompress…

▾ MidnightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.66%via CSAF
CVE-2026-55851High· 7.5
2mo ago

io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851)

A flaw was found in Netty's codec-haproxy module. A remote attacker could exploit a vulnerability in the HAProxyMessageDecoder by sending a specially crafted PROXY protocol v2 message. This leads to unbounded buffer accumulation, causing a…

▾ TwilightRed Hat · OpenShift ServerlessEPSS 0.63%via CSAF
CVE-2026-56745High· 7.5
2mo ago

netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745)

A flaw was found in Netty. A remote attacker can exploit a vulnerability in the `SpdyHttpDecoder` handler of Netty's SPDY-to-HTTP codec. When processing a client-initiated `SYN_STREAM` frame, the decoder fails to release allocated memory i…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.63%via CSAF
CVE-2026-56746High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746)

A flaw was found in Netty, a network application framework. A remote attacker can bypass security controls in the `CorsHandler` component by sending a specially crafted request with a null origin header. This bypasses the intended access r…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.41%via CSAF
CVE-2026-56816High· 7.5
2mo ago

io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 (CVE-2026-56816)

A flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.64%via CSAF
CVE-2026-56817High· 7.5
2mo ago

io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability (CVE-2026-56817)

A flaw was found in Netty, a network application framework. A remote attacker could exploit this vulnerability by sending specially crafted XML data containing a DOCTYPE declaration to a vulnerable XmlDecoder within the Netty channel pipel…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.69%via CSAF
CVE-2026-56820High· 7.4
2mo ago

io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack (CVE-2026-56820)

A flaw was found in Netty. The `OcspClient` component fails to validate that the Certificate ID in an Online Certificate Status Protocol (OCSP) response matches the requested Certificate ID. This vulnerability allows a remote attacker to b…

▾ TwilightRed Hat · Red Hat Data Grid 8.6.3EPSS 0.31%via CSAF
GHSA-r7wm-3cxj-wff9High
2mo ago

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

▾ Twilightfasterxml · com.fasterxml.jackson.core:jackson-corevia GHSA
GHSA-mhm7-754m-9p8wMedium· 6.5
2mo ago

jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`

jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`

▾ Sunlitfasterxml · com.fasterxml.jackson.core:jackson-databindvia GHSA
CVE-2026-54291High
2mo ago

PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms

PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms

▾ Twilightpostgresql · org.postgresql:postgresqlEPSS 0.24%via GHSA
CVE-2026-55831High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831)

A flaw was found in Netty, a network application framework. A remote attacker, by sending a specially crafted SPDY/3.1 SETTINGS frame, could cause the SPDY SETTINGS decoder to create a large number of map entries. This excessive processing…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.66%via CSAF
CVE-2026-55833High· 7.5
2mo ago

netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification (CVE-2026-55833)

A flaw was found in Netty, a network application framework. A remote attacker could exploit a vulnerability in the SPDY header decoding process. By sending a specially crafted, small compressed header block, the attacker can cause it to ex…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.66%via CSAF
CVE-2026-11400High· 8.0
2mo ago

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

▾ Twilightamazon · software.amazon.jdbc:aws-advanced-jdbc-wrapperEPSS 0.30%via GHSA
CVE-2026-44891High· 7.5
2mo ago

io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder (CVE-2026-44891)

A flaw was found in Netty, a network application framework, specifically within the StompSubframeDecoder component. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a large number of small headers. …

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.73%via CSAF
CVE-2026-10050Critical· 9.1
2mo ago

jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision (CVE-2026-10050)

A flaw was found in Eclipse Jetty, a widely used web server and servlet container. This vulnerability affects its HTTP Digest authentication mechanism, which is used to verify user identities. The issue arises because Jetty's hash computat…

▾ MidnightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.63%via CSAF
CVEs tagged “maven” — page 6 · VulnSea