VulnSea

Tagged “maven”

CVEs tagged maven, newest first.

321 CVEsRSS

CVE-2026-54513High· 8.1
3mo ago

jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)

A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the syst…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 1.2%via CSAF
CVE-2026-54514Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution (CVE-2026-54514)

A flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JS…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.37%via CSAF
CVE-2026-54515Medium· 5.3PoC
3mo ago

jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified (CVE-2026-54515)

A flaw was found in jackson-databind. This vulnerability occurs in the data-binding functionality where properties intended to be ignored are incorrectly restored and become writable again. An attacker could potentially exploit this by pro…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.44%via CSAF
CVE-2026-54516Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties (CVE-2026-54516)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security controls by exploiting an issue in how properties are handled when both @JsonProperty (for renaming) and @JsonIgnore (for ignoring) annota…

▾ SunlitRed Hat · Red Hat Satellite 6EPSS 0.45%via CSAF
CVE-2026-54517Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application (CVE-2026-54517)

A flaw was found in jackson-databind. A remote attacker can exploit this vulnerability due to an issue in how active-view (@JsonView) filters are applied. Specifically, setterless collections annotated with a restricted @JsonView can be po…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-48480Medium
3mo ago

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

▾ Sunlitnetty · io.netty.incubator:netty-incubator-codec-ohttpEPSS 0.27%via GHSA
CVE-2026-44913Medium· 7.2
3mo ago

Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL

Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL

▾ Sunlitapache · org.apache.nifi:nifi-cdc-mysql-processorsEPSS 0.65%via GHSA
CVE-2026-54665Medium· 5.3
3mo ago

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

▾ Sunlitapache · org.apache.nifi:nifi-jettyEPSS 0.33%via GHSA
CVE-2026-44911Low
3mo ago

Apache NiFi allows read-only users to submit component configuration verification request

Apache NiFi allows read-only users to submit component configuration verification request

▾ Sunlitapache · org.apache.nifi:nifi-web-apiEPSS 0.52%via GHSA
CVE-2026-44179Critical· 9.9
3mo ago

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

▾ Midnightxwiki · com.xwiki.pro:xwiki-pro-macrosvia GHSA
CVE-2026-44795High· 8.5
3mo ago

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

▾ Twilightspinnaker · io.spinnaker.rosco:rosco-coreEPSS 1.0%via GHSA
CVE-2026-56120Critical· 9.6
3mo ago

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

▾ Midnightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-55414Medium· 5.3
3mo ago

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

▾ Sunlitnl-portal · nl.nl-portal:formvia GHSA
CVE-2026-55772High· 8.8
3mo ago

CedarJava has type confusion vulnerability

CedarJava has type confusion vulnerability

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.48%via GHSA
CVE-2026-55773High· 8.8
3mo ago

CedarJava has policy injection vulnerability

CedarJava has policy injection vulnerability

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.52%via GHSA
GHSA-jrpc-7vxp-69p6Medium
3mo ago

http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`

http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`

▾ Sunlithttp4k · org.http4k:http4k-corevia GHSA
GHSA-m4w9-hjfw-vwj4High
3mo ago

http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`

http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`

▾ Twilighthttp4k · org.http4k:http4k-corevia GHSA
GHSA-pr33-38xx-6r26Medium
3mo ago

http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default

http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default

▾ Sunlithttp4k · org.http4k:http4k-corevia GHSA
GHSA-c7jm-38gq-h67hMedium
3mo ago

http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments

http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments

▾ Sunlithttp4k · org.http4k:http4k-security-digestvia GHSA
GHSA-h3m5-97jq-qjrfCritical· 9.6
3mo ago

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

▾ Midnightopenremote · io.openremote:openremote-managervia GHSA
GHSA-2c85-rfcc-g74jHigh
3mo ago

Karate Mock Server RCE via embedded expression evaluation of request-derived data

Karate Mock Server RCE via embedded expression evaluation of request-derived data

▾ Twilightkaratelabs · io.karatelabs:karate-corevia GHSA
GHSA-2r2c-cx56-8933High· 7.5
3mo ago

JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

▾ Twilightjline · org.jline:jline-remote-telnetvia GHSA
GHSA-47qp-hqvx-6r3fHigh· 7.5
3mo ago

JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

▾ Twilightjline · org.jline:jline-remote-telnetvia GHSA
CVE-2026-54683Medium· 6.5
3mo ago

NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)

NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)

▾ Sunlitnl-portal · nl.nl-portal:documenten-apivia GHSA
CVE-2026-11752Medium
3mo ago

Armeria: External Control of File Name or Path in xDS SDS DataSource

Armeria: External Control of File Name or Path in xDS SDS DataSource

▾ Sunlitlinecorp · com.linecorp.armeria:armeria-xdsEPSS 0.32%via GHSA
CVE-2026-32966Critical· 9.8
3mo ago

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

▾ Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.66%via GHSA
CVE-2026-32967Critical· 9.1
3mo ago

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

▾ Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.55%via GHSA
CVE-2026-41280Medium· 4.9
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.54%via GHSA
CVE-2026-42357Medium· 6.5
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.49%via GHSA
CVE-2026-47340Medium· 6.5
3mo ago

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.55%via GHSA
CVEs tagged “maven” — page 9 · VulnSea