Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40048Highorg.apache.camel:camel-pqc: Camel-PQC Vulnerable to Deserialization of Untrusted DataCVE-2026-7045Mediumcom.baomidou:dynamic-datasource-spring: Dynamic-Datasource has an Injection vulnerabilityCVE-2026-33524Highio.github.ndsev:zserio-runtime: Zserio Runtime: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in DeserializationCVE-2026-41044Highorg.apache.activemq:apache-activemq: Apache ActiveMQ Vulnerable to Code InjectionCVE-2026-23902Highorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler has an Incorrect Authorization VulnerabilityCVE-2026-40466Highorg.apache.activemq:apache-activemq: Apache ActiveMQ Vulnerable to Improper Input Validation and Code InjectionCVE-2025-62233Mediumorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerabilityCVE-2026-41043Mediumorg.apache.activemq:apache-activemq: Apache ActiveMQ Vulnerable to Cross-site ScriptingCVE-2026-39973Highorg.apktool:apktool-lib: Apktool: Path Traversal to Arbitrary File WriteCVE-2026-3960Mediumai.h2o:h2o-core: H2O-3 is Vulnerable to Code InjectionCVE-2026-30139Mediumorg.silverpeas.core:silverpeas-core-war: Silverpeas Core has a reflected cross-site scripting vulnerabilityCVE-2026-6857Highorg.apache.camel:camel-infinispan: camel-infinispan Vulnerable to Deserialization of Untrusted DataCVE-2026-41166Highio.openremote:openremote-manager: OpenRemote has Improper Access Control via updateUserRealmRoles functionCVE-2026-40542Highorg.apache.httpcomponents.client5:httpclient5: Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verificationCVE-2026-22753Highorg.springframework.security:spring-security-config: Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchersCVE-2026-22748Mediumorg.springframework.security:spring-security-oauth2-jose: Spring Security has Potential Security Misconfiguration when Using withIssuerLocationCVE-2026-22754Highorg.springframework.security:spring-security-config: Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization RulesCVE-2026-22747Mediumorg.springframework.security:spring-security-web: Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client CertificatesCVE-2026-22746Loworg.springframework.security:spring-security-core: Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProviderCVE-2026-22751Mediumorg.springframework.security:spring-security-core: Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configuredCVE-2026-32613Criticalio.spinnaker.echo:echo-pipelinetriggers: Spinnaker: RCE via expression parsing due to unrestricted context handlingCVE-2026-32604Criticalio.spinnaker.clouddriver:clouddriver-artifacts-gitrepo: Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and pathsCVE-2026-33557Criticalorg.apache.kafka:kafka-clients: Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementationCVE-2026-33558Mediumorg.apache.kafka:kafka-clients: Apache Kafka exposes sensitive information in its DEBUG logsCVE-2026-5598Highorg.bouncycastle:bcprov-jdk15to18: Bouncy Castle Has Covert Timing Channel Vulnerability

Stop the waste.
Protect your environment with Kodem.