CVE Archive

Maven Vulnerability Archive

Recent and critical CVEs affecting Maven packages. Kodem’s runtime-powered SCA identifies which are actually reachable in your applications.

Top affected packages
Recent Maven CVEs
CVE
Package / summary
Severity
CVE-2026-55847
io.qameta.allure:allure-generator · Allure Report: Stored XSS via unescaped ANSI helper in status message/trace…
Medium
CVE-2026-55846
io.qameta.allure:allure-commandline · Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
Medium
CVE-2026-55773
com.cedarpolicy:cedar-java · CedarJava has policy injection vulnerability
High
CVE-2026-55772
com.cedarpolicy:cedar-java · CedarJava has type confusion vulnerability
High
CVE-2026-55414
nl.nl-portal:form · NL Portal Backend Libraries: Unauthenticated form resolver forwards the…
Medium
CVE-2026-54683
nl.nl-portal:documenten-api · NL Portal Backend Libraries: Document contents remained downloadable by any…
Medium
CVE-2026-55226
io.strimzi:strimzi · Strimzi: Unrestricted access to all Secrets within namespace watched by the…
Medium
CVE-2026-55225
io.strimzi:strimzi · Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`
High
CVE-2026-55470
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 · HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches()…
High
CVE-2026-55760
com.github.jknack:handlebars · handlebars.java FileTemplateLoader Path Traversal
High
CVE-2026-55405
dev.langchain4j:langchain4j-mariadb · LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and…
High
CVE-2026-47340
org.apache.dolphinscheduler:dolphinscheduler-api · Apache DolphinScheduler: An incorrect authorization vulnerability allows…
Medium
CVE-2026-42357
org.apache.dolphinscheduler:dolphinscheduler-api · Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to…
Medium
CVE-2026-41280
org.apache.dolphinscheduler:dolphinscheduler-api · Apache DolphinScheduler: Incorrect Authorization vulnerability allows users…
Medium
CVE-2026-32967
org.apache.dolphinscheduler:dolphinscheduler-api · Apache DolphinScheduler: The `/v2` experimental interface lacks permission…
Critical
CVE-2026-32966
org.apache.dolphinscheduler:dolphinscheduler-api · Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to…
Critical
CVE-2026-50560
io.netty:netty-codec-http2 · Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
Medium
CVE-2026-50020
io.netty:netty-codec-http · Netty: HttpObjectDecoder skips arbitrary initial control characters when only…
Medium
CVE-2026-50011
io.netty:netty-codec-redis · Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
High
CVE-2026-50010
io.netty:netty-handler · Netty: Wrapping plain trust manager silently disables hostname verification
High
CVE-2026-50009
io.netty:netty-codec-classes-quic · Netty: QUIC stateless reset token material exposed through header-visible…
Medium
CVE-2026-48748
io.netty:netty-codec-http3 · Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
High
CVE-2025-58175
org.geoserver.web:gs-web-app · GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML…
Medium
CVE-2025-52465
org.geoserver.web:gs-web-app · GeoServer has an arbitrary file write vulnerability in its Master Password Dump…
High
CVE-2025-27511
org.geoserver.extension:gs-db2 · GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
High
CVE-2026-48043
io.netty:netty-codec-http2 · netty-codec-http2: ByteBuf Reference-Count Leak in…
Medium
CVE-2025-53114
org.cometd.java:cometd-java-server-common · Acknowledgement extension out of memory
High
CVE-2026-53441
org.jenkins-ci.main:jenkins-core · Jenkins: Stored XSS vulnerability in node offline cause description
High
CVE-2026-41726
org.springframework.kafka:spring-kafka · In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled,…
Medium
CVE-2026-41731
org.springframework.kafka:spring-kafka · In Spring for Apache Kafka, overly broad trusted-package matching in header…
High
CVE-2026-47691
io.netty:netty-resolver-dns · Netty has Insufficient Bailiwick Validation for NS Records
High
CVE-2026-47244
io.netty:netty-codec-http2 · Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
Medium

Stop the waste.
Protect your environment with Kodem.