Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-0636Mediumorg.bouncycastle:bcprov-jdk14: Bouncy Castle has an LDAP injectionCVE-2025-14813Criticalorg.bouncycastle:bcprov-jdk14: Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocksCVE-2026-3505Highorg.bouncycastle:bcpg-jdk12: Bouncy Castle Uncontrolled Resource Consumption vulnerabilityCVE-2026-40458Highorg.pac4j:pac4j-core: PAC4J has a Cross-Site Request Forgery (CSRF) VulnerabilityCVE-2026-41883Highorg.omnifaces:omnifaces: OmniFaces: EL injection via crafted resource name in wildcard CDN mappingCVE-2026-41245Mediumcom.github.junrar:junrar: Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name PrefixCVE-2026-34164Mediumcom.ritense.valtimo:inbox: Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingServiceCVE-2026-30778Highorg.apache.skywalking:server-core: SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration informationCVE-2026-40478Criticalorg.thymeleaf:thymeleaf: Improper neutralization of specific syntax patterns for unauthorized expressions in ThymeleafCVE-2026-40477Criticalorg.thymeleaf:thymeleaf: Improper restriction of the scope of accessible objects in Thymeleaf expressionsCVE-2026-40882Highio.openremote:openremote-manager: OpenRemote has XXE in Velbus Asset ImportCVE-2026-40942Mediumdev.dsf:dsf-bpe-process-api-v2: Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token CacheCVE-2026-40939Mediumdev.dsf:dsf-common-jetty: Data Sharing Framework is Missing Session Timeout for OIDC SessionsCVE-2026-5588Mediumorg.bouncycastle:bcpkix-jdk18on: Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modulesCVE-2026-2332Highorg.eclipse.jetty:jetty-http: Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingCVE-2026-40104Mediumorg.xwiki.platform:xwiki-platform-oldcore: XWiki's REST APIs can list all pages/spaces, leading to unavailabilityCVE-2026-40105Mediumorg.xwiki.platform:xwiki-platform-web-templates: XWiki has Reflected Cross-Site Scripting (XSS) in page history compareCVE-2026-39842Criticalio.openremote:openremote-manager: Expression Injection in OpenRemoteCVE-2026-37980Mediumorg.keycloak:keycloak-services: Keycloak: Arbitrary code execution via Stored Cross-Site Scripting (XSS) in organization selection login pageCVE-2026-33929Mediumorg.apache.pdfbox:pdfbox-examples: Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example CodeCVE-2026-40490Mediumorg.asynchttpclient:async-http-client: AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirectsCVE-2026-5795Highorg.eclipse.jetty.ee11:jetty-ee11-jaspi: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variablesCVE-2026-35582Highgov.nsa.emissary:emissary: Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in ExecutrixCVE-2026-35337Highorg.apache.storm:storm-client: Apache Storm: Deserialization of Untrusted Data vulnerabilityCVE-2026-35565Mediumorg.apache.storm:storm-webapp: Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata

Stop the waste.
Protect your environment with Kodem.