Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59889Mediumcom.fasterxml.jackson.core:jackson-databind: jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserializationGHSA-R7WM-3CXJ-WFF9Highcom.fasterxml.jackson.core:jackson-core: jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-MHM7-754M-9P8WMediumcom.fasterxml.jackson.core:jackson-databind: jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`CVE-2026-59888Mediumcom.fasterxml.jackson.core:jackson-databind: jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategyCVE-2026-54291Highorg.postgresql:postgresql: PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithmsCVE-2026-11400Highsoftware.amazon.jdbc:aws-advanced-jdbc-wrapper: AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instanceGHSA-X8MG-6R4P-87PFHighcom.arcadedb:arcadedb-server: ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorizationGHSA-VWJC-V7X7-CM6GHighcom.arcadedb:arcadedb-engine: ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE jsGHSA-X9F9-R4M8-9XC2Highcom.arcadedb:arcadedb-engine: ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)GHSA-48QW-824M-86PRHighcom.arcadedb:arcadedb-server: ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file readCVE-2026-54076Highcom.arcadedb:arcadedb-engine: ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)CVE-2026-54077Highcom.arcadedb:arcadedb-engine: ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated usersCVE-2026-50270Highcom.datadoghq:dd-java-agent: dd-trace-java: Improper parsing of W3C baggage headers may lead to DoSCVE-2026-44891Highio.netty:netty-codec-stomp: Netty: Denial of Service via Unbounded Headers in StompSubframeDecoderCVE-2026-59955Highcom.ctrip.framework.apollo:apollo: Apollo ConfigService access key authentication bypass via raw config file appId parsingCVE-2026-59954Highcom.ctrip.framework.apollo:apollo: Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingCVE-2025-32781Mediumcom.ctrip.framework.apollo:apollo: Apollo Portal: There is a risk of unauthorized access to the Apollo configuration centerCVE-2026-49485Highca.uhn.hapi.fhir:org.hl7.fhir.dstu2: org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP EndpointGHSA-Q6GH-6V2R-HJV3Mediumio.micronaut:micronaut-http-client: Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headersGHSA-387M-935M-C4VWHighio.micronaut:micronaut-http-client: Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoSCVE-2026-49464Highnl.nl-portal:taak: NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taakCVE-2026-49463Mediumnl.nl-portal:documenten-api: NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-librariesCVE-2026-49833Mediumorg.dspace:dspace-api: DSpace: Path Traversal is possible through LDN message generationCVE-2026-49830Mediumorg.dspace:dspace-api: DSpace: ORE resource URI does not validate scheme for non-web resourcesCVE-2026-49831Mediumorg.dspace:dspace-api: DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path

Stop the waste.
Protect your environment with Kodem.