Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-47323Criticalorg.apache.camel:camel-cxf-rest: Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound FilteringCVE-2026-7860Lowcom.vaadin:flow-plugins: Vaadin Build Plugins is Affected by a Possible Information Disclosure VulnerabilityCVE-2026-7507Highorg.keycloak:keycloak-services: Keycloak: Session fixation in OIDC login flow that can lead to account takeoverCVE-2026-7504Highorg.keycloak:keycloak-services: Keycloak: Open redirect when using wildcard valid redirect URIs in KeycloakCVE-2026-7571Highorg.keycloak:keycloak-services: Keycloak: Access token disclosure and implicit flow bypass via forged client dataCVE-2026-7307Highorg.keycloak:keycloak-saml-core: Keycloak: Denial of Service via specially crafted SAML inputCVE-2026-4630Mediumorg.keycloak:keycloak-services: Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource ServersCVE-2026-37981Mediumorg.keycloak:keycloak-services: Keycloak Account Resources user lookup contains broken access controlCVE-2026-37982Mediumorg.keycloak:keycloak-services: Keycloak: Unauthorized account takeover via WebAuthn token replayCVE-2026-37979Mediumorg.keycloak:keycloak-services: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypassCVE-2026-37978Mediumorg.keycloak:keycloak-services: Keycloak: Information Disclosure via evaluate-scopes Admin APICVE-2026-8922Mediumorg.keycloak:keycloak-services: Keycloak: Revoked Tokens Can Remain Active When Both Realm-Level and Client-Level `notBefore` Revocation Policies are ConfiguredCVE-2026-8830Mediumorg.keycloak:keycloak-services: Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulationCVE-2026-45367Highca.uhn.hapi.fhir:org.hl7.fhir.dstu2: HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP EndpointCVE-2026-45300Highorg.asynchttpclient:async-http-client: async-http-client: Cookie header not stripped on cross-origin redirectCVE-2026-45609Highorg.springaicommunity:mcp-client-security: Spring AI MCP Security: Unvalidated URL Fetching (SSRF)CVE-2026-8771Mediumorg.linlinjava:litemall-wx-api: org.linlinjava:litemall-wx-api has an Injection issueCVE-2026-8759Mediumcom.ibeetl:beetl-spring-classic: Beetl's SpELFunction extension function has an expression injection riskCVE-2026-45575Highcom.oviva.telematik:epa4all-client: Improper Verification of Cryptographic Signature in com.oviva.telematik:epa4all-clientCVE-2026-35194Highorg.apache.flink:flink-table-planner_2.12: Apache Flink: Remote code execution via SQL injection in code generationCVE-2026-45574Highcom.oviva.telematik:epa4all-client: epa4all-client: TLS Certificate Validation Disabled in ProductionCVE-2026-45292Mediumio.opentelemetry:opentelemetry-api: OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage PropagationCVE-2026-8178Criticalcom.amazon.redshift:redshift-jdbc42: Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class LoadingCVE-2026-45205Mediumorg.apache.commons:commons-configuration2: Apache Commons Configuration: StackOverflowError for YAML input with cyclesCVE-2026-45083Criticalio.goobi.viewer:viewer-core: Goobi viewer - Core: Unauthenticated Solr Streaming Expression Proxy

Stop the waste.
Protect your environment with Kodem.