Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40968Mediumorg.springframework.grpc:spring-grpc: Spring gRPC SecurityContext leaks across requests upon authorization failureCVE-2026-40978Highorg.springframework.ai:spring-ai-azure-cosmos-db-store: Spring AI has SQL Injection in CosmosDBVectorStore.doDelete()CVE-2026-40979Mediumorg.springframework.ai:spring-ai-transformers: Spring AI's ONNX model cache defaults to world-writable predictable /tmp directoryCVE-2026-40980Mediumorg.springframework.ai:spring-ai-pdf-document-reader: Spring AI Vulnerable to OOM by attacker-controlled PDFCVE-2026-40966Mediumorg.springframework.ai:spring-ai-advisors-vector-store: Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltrationCVE-2026-40967Highorg.springframework.ai:spring-ai-vector-store: Spring AI has a VectorStore FilterExpression Converter injectionCVE-2026-40977Mediumorg.springframework.boot:spring-boot-cassandra: Spring Boot's PID file write follows symlinks at predictable default pathCVE-2026-40973Highorg.springframework.boot:spring-boot: Spring Boot accepts predictable temp directory without ownership verificationCVE-2026-40974Mediumorg.springframework.boot:spring-boot-cassandra: Spring Boot's Cassandra SSL auto-configuration disables TLS hostname verificationCVE-2026-40975Mediumorg.springframework.boot:spring-boot-cassandra: Spring Boot's random value property source uses a weak PRNG unsuitable for secretsCVE-2026-40976Criticalorg.springframework.boot:spring-boot: Spring Boot's default security filter chain has no authorization rule with Actuator but without HealthCVE-2026-40971Mediumorg.springframework.boot:spring-boot-rabbitmq: Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ brokerCVE-2026-40972Highorg.springframework.boot:spring-boot-devtools: Spring Boot DevTools remote secret comparison is vulnerable to timing attacksCVE-2026-40970Mediumorg.springframework.boot:spring-boot-elasticsearch: Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.CVE-2026-40557Mediumorg.apache.storm:storm-metrics-prometheus: Apache Storm Prometheus Reporter vulnerable to Improper Certificate Validation via Global SSL Context DowngradeCVE-2026-41081Mediumorg.apache.storm:storm-client: Apache Storm's Improper Handling of TLS Client Authentication Failure Leads to Anonymous Principal AssignmentCVE-2026-27172Mediumorg.apache.camel:camel-consul: Apache Camel-Consul component vulnerable to Deserialization of Untrusted DataCVE-2026-33453Criticalorg.apache.camel:camel-coap: Apache camel-coap allows header injection that can lead to remote code executionCVE-2026-40858Highorg.apache.camel:camel-infinispan: Apache Camel-Infinispan Component Vulnerable to Deserialization of Untrusted DataCVE-2026-40022Highorg.apache.camel:camel-platform-http-main: Apache Camel Vulnerable to Authentication Bypass Using an Alternate Path or ChannelCVE-2026-33454Criticalorg.apache.camel:camel-mail: Apache Camel's Camel-Mail component is vulnerable to Camel message header injectionCVE-2026-41409Criticalorg.apache.mina:mina-core: Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)CVE-2026-41635Criticalorg.apache.mina:mina-core: Apache MINA vulnerable to Deserialization of Untrusted DataCVE-2026-40473Highorg.apache.camel:camel-mina: Camel-MINA Vulnerable to Deserialization of Untrusted DataCVE-2026-40453Criticalorg.apache.camel:camel-coap: Apache Camel has an incomplete fix for CVE-2025-27636

Stop the waste.
Protect your environment with Kodem.