Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40982Criticalorg.springframework.cloud:spring-cloud-config-server: Spring Cloud Config vulnerable to Path TraversalCVE-2026-40981Highorg.springframework.cloud:spring-cloud-config-server: Spring Cloud Config has an Authorization Bypass Through User-Controlled Key CVE-2026-41002Highorg.springframework.cloud:spring-cloud-config-server: Spring Cloud Config Server Susceptible To TOCTOU AttackCVE-2026-44248Mediumio.netty:netty-codec-mqtt: Netty MQTT: Resource exhaustion in MqttDecoderCVE-2026-44503Highcom.microsoft.kiota:microsoft-kiota-abstractions: Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirectCVE-2026-42587Highio.netty:netty-codec-http: Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoSCVE-2026-42586Mediumio.netty:netty-codec-redis: Netty Redis Codec Encoder has a CRLF Injection IssueCVE-2026-42585Mediumio.netty:netty-codec-http: Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-EncodingCVE-2026-42584Highio.netty:netty-codec-http: Netty has HttpClientCodec response desynchronizationCVE-2026-42583Highio.netty:netty-codec-compression: Netty Lz4FrameDecoder is vulnerable to resource exhaustion CVE-2026-42582Highio.netty:netty-codec-http3: Netty HTTP/3 QPACK literal unbounded allocationCVE-2026-42581Mediumio.netty:netty-codec-http: Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling SanitizationCVE-2026-42580Mediumio.netty:netty-codec-http: Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsingCVE-2026-42579Highio.netty:netty-codec-dns: Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)CVE-2026-42578Lowio.netty:netty-handler-proxy: Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)GHSA-X5HG-X4GV-J98MLoworg.opensearch.plugin:opensearch-security: OpenSearch has ineffective TLS certificate hostname verificationGHSA-X83W-23JP-G6PWMediumorg.opensearch.plugin:opensearch-security: OpenSearch Security plugin: DLS not applied on documents linked by has_child or has_parent relationGHSA-22VX-2X23-98W6Loworg.opensearch.plugin:opensearch-security: OpenSearch vulnerable to improper authorization for Rollover RequestsGHSA-83X9-VC3C-HGHCLoworg.opensearch.plugin:opensearch-security: OpenSearch has a bypass of REST Layer Authorization Using Malformed PathsCVE-2026-44308Mediumio.awspring.cloud:spring-cloud-aws-sns: Spring Cloud AWS missing SNS message signature verification allows spoofing of HTTP/HTTPS endpoint notificationsGHSA-248H-974Q-XRC2Mediumcom.getaxonflow:axonflow-sdk: axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verificationCVE-2026-42577Highio.netty:netty-transport-classes-epoll: Netty epoll transport denial of service via RST on half-closed TCP connectionCVE-2026-42555Criticalcom.ritense.valtimo:document: Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin usersCVE-2026-44241Highio.micronaut:micronaut-context: Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Language` HeaderCVE-2026-44242Lowio.micronaut:micronaut-inject: Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header

Stop the waste.
Protect your environment with Kodem.