Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53573Mediumorg.geonetwork-opensource:geonetwork: core-geonetwork has an Open Redirect BypassCVE-2026-56819Highio.netty:netty-codec-http2: Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)CVE-2026-41695Highorg.springframework.data:spring-data-commons: Spring Data: Unbounded property-path cache keyed by externally-supplied path stringCVE-2026-54704Mediumio.opentelemetry.javaagent:opentelemetry-javaagent: OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text PasswordsCVE-2026-54712Mediumio.opentelemetry.javaagent:opentelemetry-javaagent: OpenTelemetry Javaagent RMI context propagation allows resource exhaustionCVE-2026-50559Highio.quarkus:quarkus-vertx-http: Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization VulnerabilitiesCVE-2026-54081Mediumorg.verapdf:parser: veraPDF Parser DoS via PostScript Type 1 Font ProgramsCVE-2026-54080Mediumorg.verapdf:parser: veraPDF Parser DoS via PostScript CMap StreamsCVE-2026-54082Mediumorg.verapdf:validation-model: veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFsCVE-2026-54078Highorg.verapdf:validation-model: veraPDF Validation XXE via Rich TextCVE-2026-54079Highorg.verapdf:validation-model: veraPDF Validation XXE via XFACVE-2026-54609Highcom.quietterminal:qti-neon: QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwardingCVE-2026-55771Highcom.cedarpolicy:cedar-java: Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilitiesCVE-2026-43910Highio.appium:java-client: java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutorCVE-2023-37465Mediumorg.xwiki.contrib:discussions-server: org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messagesGHSA-FP43-VJ7G-PG92Highorg.omnifaces:omnifaces: OmniFaces: Forged combined-resource IDs and related output/push boundariesGHSA-7PPR-R889-MCF2Highorg.http4s:http4s-blaze-server_2.13: blaze: Unbounded WebSocket message aggregation in http4s-blaze-serverGHSA-46Q4-43PH-C6FRHighorg.http4s:blaze-http_2.13: blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)GHSA-MHVJ-JHPQ-885VHighorg.http4s:http4s-blaze-server_2.13: blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parserGHSA-P279-2CQP-84JGCriticalorg.openidentityplatform.opendj:opendj-server-legacy: OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope checkGHSA-68R5-9HPG-7QW9Criticalorg.openidentityplatform.opendj:opendj-dsml-servlet: OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gatewayCVE-2026-62379Criticalorg.openidentityplatform.openam:openam-core: OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallbackCVE-2026-62280Mediumorg.openidentityplatform.openam:openam-oauth2: OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent pageCVE-2026-62263Criticalorg.openidentityplatform.openam:openam-auth-webauthn: OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypassGHSA-V74W-7MR3-4QG3Highio.netty:netty-codec-xml: Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

Stop the waste.
Protect your environment with Kodem.