Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-41207Mediumio.netty.incubator:netty-incubator-codec-ohttp: netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failuresCVE-2026-48048Highorg.xwiki.platform:xwiki-platform-livetable-ui: XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requestsCVE-2026-48047Mediumorg.xwiki.platform:xwiki-platform-webjars-api: XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) adminCVE-2026-33137Criticalorg.xwiki.platform:xwiki-platform-rest-server: XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}CVE-2026-23734Criticalorg.xwiki.commons:xwiki-commons-classloader-api: XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slashCVE-2026-9497Loworg.mengyun:tcc-transaction: TCC-TRANSACTION has an Improper Input Validation vulnerabilityCVE-2026-48589Loworg.apache.shiro:shiro-jakarta-ee: Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user loginCVE-2026-43827Mediumorg.apache.shiro:shiro-core: Apache Shiro has a session fixation vulnerabilityCVE-2026-44598Mediumorg.apache.shiro:shiro-jakarta-ee: Apache Shiro Vulnerable to Open Redirect, Server-Side Request ForgeryCVE-2026-43828Mediumorg.apache.shiro:shiro-web: Apache Shiro sends sensitive cookies in HTTPS session without 'Secure' attributeCVE-2026-42797Mediumorg.apache.syncope.core:syncope-core-provisioning-api: Apache Syncope Vulnerable to Exposure of Sensitive Information Through Data QueriesCVE-2026-42782Highorg.apache.syncope.core:syncope-core-spring: Apache Syncope has an Improper Isolation or Compartmentalization vulnerabilityCVE-2026-41863Mediumorg.springframework.ai:spring-ai-anthropic: Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to diskCVE-2026-9370Lowcom.github.ulisesbocchio:jasypt-spring-boot: jasypt-spring-boot Uses a One-Way Hash without a SaltCVE-2026-44930Criticalorg.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap: Apache CXF has an LDAP injection vulnerabilityCVE-2026-44417Highorg.apache.cxf:cxf-rt-transports-jms: Apache CXF: Untrusted JMS configuration can lead to RCECVE-2026-44618Mediumorg.apache.cxf:cxf-rt-ws-transfer: Apache CXF's WS-Transfer module has an insecure XML parser configurationCVE-2026-46481Highorg.open-metadata:openmetadata-service: OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular usersCVE-2026-9087Mediumorg.keycloak:keycloak-services: Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromiseCVE-2026-45799Highcom.squareup.wire:wire-runtime-jvm: Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service CVE-2026-6009Highnet.sf.jasperreports:jasperreports: Jaspersoft Reports: Java Deserialization Vulnerability Lleads to Remote Code Execution (RCE)GHSA-XM96-GFJX-JCRCHighland.oras:oras-java-sdk: ORAS Java: Path traversal in pullArtifact via attacker-controlled org.opencontainers.image.title annotationCVE-2026-45581Mediumorg.hyperledger.fabric-chaincode-java:fabric-chaincode-shim: fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service ModeCVE-2026-2587Criticalorg.glassfish.main.admingui:admingui: GlassFish's gadget handler is vulnerable to RCECVE-2026-2586Criticalorg.glassfish.main.admingui:console-common: GlassFish's Administration Console is Vulnerable to RCE

Stop the waste.
Protect your environment with Kodem.