Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44672Criticalorg.mapfish.print:print-lib: Mapfish Print: Remote Code Injection (RCE) in Dynamic tableCVE-2026-33117Criticalcom.azure:azure-security-keyvault-keys: Security feature bypass vulnerability in Azure Key Vault Keys library for JavaCVE-2026-41284Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handlingCVE-2026-43512Criticalorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat - Digest authenticator will authenticate any unknown userCVE-2026-43513Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat: LockOutRealm treats user names as case-sensitiveCVE-2026-43515Criticalorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat - Security constraints not correctly appliedCVE-2026-43514Loworg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat - AJP secret compared in non-constant timeCVE-2026-41293Criticalorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat - HTTP/2 request headers not validatedCVE-2026-42498Highorg.apache.tomcat.embed:tomcat-embed-core: Apache Tomcat - WebSocket authentication header exposureCVE-2026-45091Criticalsealed-env: sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)CVE-2026-41712Highorg.springframework.ai:spring-ai-client-chat: Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakageCVE-2026-41713Highorg.springframework.ai:spring-ai-client-chat: Spring AI: Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisorCVE-2026-27478Criticalio.unitycatalog:unitycatalog-server: Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User ImpersonationCVE-2026-44516Highcom.ritense.valtimo:web: Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizerCVE-2026-41705Highorg.springframework.ai:spring-ai-milvus-store: Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDsCVE-2026-6860Mediumio.vertx:vertx-core: Vert.x has a DoS via unbounded server-side SNI SslContext cache growthCVE-2026-44900Highcom.oviva.telematik:epa4all-client: epa4all-client has a VAU Signature bypassCVE-2026-44714Highorg.bitcoinj:bitcoinj-core: bitcoinj has a ScriptExecution P2PKH/P2WPKH Verification BypassCVE-2026-39816Highorg.apache.nifi:nifi-other-graph-services-nar: Apache NiFi is missing the Restricted annotation with the Execute Code Required PermissionCVE-2026-8149Mediumorg.bouncycastle:bcprov-lts8on: Bouncy Castle LTS native GCM chunking can cause bad-tag exception on decryptionCVE-2023-42345Mediumorg.opencms:opencms-core: Alkacon OpenCms is vulnerable to XSS via updateModelGroups.jspCVE-2023-42346Highorg.opencms:opencms-core: Alkacon OpenCms is vulnerable to XXE when the <!DOCTYPE> refers to an external hostCVE-2023-42344Highorg.opencms:opencms-core: Alkacon OpenCms allows remote unauthenticated attackers to obtain sensitive informationCVE-2023-42343Mediumorg.opencms:opencms-core: Alkacon OpenCms is vulnerable to XSS via cmis-online/typeCVE-2026-41004Mediumorg.springframework.cloud:spring-cloud-config-server: Spring Cloud Config Server Logged Sensitive Information

Stop the waste.
Protect your environment with Kodem.