Tagged “maven”
CVEs tagged maven, newest first.
321 CVEsRSS
CVE-2026-54513High· 8.1jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the syst…
CVE-2026-54514Medium· 5.3jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution (CVE-2026-54514)
A flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JS…
CVE-2026-54515Medium· 5.3PoCjackson-databind: jackson-databind: Ignored properties can be unexpectedly modified (CVE-2026-54515)
A flaw was found in jackson-databind. This vulnerability occurs in the data-binding functionality where properties intended to be ignored are incorrectly restored and become writable again. An attacker could potentially exploit this by pro…
CVE-2026-54516Medium· 5.3jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties (CVE-2026-54516)
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security controls by exploiting an issue in how properties are handled when both @JsonProperty (for renaming) and @JsonIgnore (for ignoring) annota…
CVE-2026-54517Medium· 5.3jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application (CVE-2026-54517)
A flaw was found in jackson-databind. A remote attacker can exploit this vulnerability due to an issue in how active-view (@JsonView) filters are applied. Specifically, setterless collections annotated with a restricted @JsonView can be po…
CVE-2026-48480MediumOHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
CVE-2026-44913Medium· 7.2Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
CVE-2026-54665Medium· 5.3Apache NiFi fails to validate proxy host headers when constructing qualified URLs
Apache NiFi fails to validate proxy host headers when constructing qualified URLs
CVE-2026-44911LowApache NiFi allows read-only users to submit component configuration verification request
Apache NiFi allows read-only users to submit component configuration verification request
CVE-2026-44179Critical· 9.9xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
CVE-2026-44795High· 8.5Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types
Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types
CVE-2026-56120Critical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-55414Medium· 5.3NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
CVE-2026-55772High· 8.8CedarJava has type confusion vulnerability
CedarJava has type confusion vulnerability
CVE-2026-55773High· 8.8CedarJava has policy injection vulnerability
CedarJava has policy injection vulnerability
GHSA-jrpc-7vxp-69p6Mediumhttp4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`
GHSA-m4w9-hjfw-vwj4Highhttp4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`
http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`
GHSA-pr33-38xx-6r26Mediumhttp4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default
http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default
GHSA-c7jm-38gq-h67hMediumhttp4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
GHSA-h3m5-97jq-qjrfCritical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
GHSA-2c85-rfcc-g74jHighKarate Mock Server RCE via embedded expression evaluation of request-derived data
Karate Mock Server RCE via embedded expression evaluation of request-derived data
GHSA-2r2c-cx56-8933High· 7.5JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
GHSA-47qp-hqvx-6r3fHigh· 7.5JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
CVE-2026-54683Medium· 6.5NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
CVE-2026-11752MediumArmeria: External Control of File Name or Path in xDS SDS DataSource
Armeria: External Control of File Name or Path in xDS SDS DataSource
CVE-2026-32966Critical· 9.8Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
CVE-2026-32967Critical· 9.1Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CVE-2026-41280Medium· 4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
CVE-2026-42357Medium· 6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
CVE-2026-47340Medium· 6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.