Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-22754Highorg.springframework.security:spring-security-config: Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization RulesCVE-2026-22747Mediumorg.springframework.security:spring-security-web: Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client CertificatesCVE-2026-22746Loworg.springframework.security:spring-security-core: Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProviderCVE-2026-22751Mediumorg.springframework.security:spring-security-core: Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configuredCVE-2026-32613Criticalio.spinnaker.echo:echo-pipelinetriggers: Spinnaker: RCE via expression parsing due to unrestricted context handlingCVE-2026-32604Criticalio.spinnaker.clouddriver:clouddriver-artifacts-gitrepo: Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and pathsCVE-2026-33557Criticalorg.apache.kafka:kafka-clients: Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementationCVE-2026-33558Mediumorg.apache.kafka:kafka-clients: Apache Kafka exposes sensitive information in its DEBUG logsCVE-2026-5598Highorg.bouncycastle:bcprov-jdk15to18: Bouncy Castle Has Covert Timing Channel VulnerabilityCVE-2026-0636Mediumorg.bouncycastle:bcprov-jdk14: Bouncy Castle has an LDAP injectionCVE-2025-14813Criticalorg.bouncycastle:bcprov-jdk14: Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocksCVE-2026-3505Highorg.bouncycastle:bcpg-jdk12: Bouncy Castle Uncontrolled Resource Consumption vulnerabilityCVE-2026-40458Highorg.pac4j:pac4j-core: PAC4J has a Cross-Site Request Forgery (CSRF) VulnerabilityCVE-2026-41883Highorg.omnifaces:omnifaces: OmniFaces: EL injection via crafted resource name in wildcard CDN mappingCVE-2026-41245Mediumcom.github.junrar:junrar: Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name PrefixCVE-2026-34164Mediumcom.ritense.valtimo:inbox: Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingServiceCVE-2026-30778Highorg.apache.skywalking:server-core: SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration informationCVE-2026-40478Criticalorg.thymeleaf:thymeleaf: Improper neutralization of specific syntax patterns for unauthorized expressions in ThymeleafCVE-2026-40477Criticalorg.thymeleaf:thymeleaf: Improper restriction of the scope of accessible objects in Thymeleaf expressionsCVE-2026-40882Highio.openremote:openremote-manager: OpenRemote has XXE in Velbus Asset ImportCVE-2026-40942Mediumdev.dsf:dsf-bpe-process-api-v2: Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token CacheCVE-2026-40939Mediumdev.dsf:dsf-common-jetty: Data Sharing Framework is Missing Session Timeout for OIDC SessionsCVE-2026-5588Mediumorg.bouncycastle:bcpkix-jdk18on: Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modulesCVE-2026-2332Highorg.eclipse.jetty:jetty-http: Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String ParsingCVE-2026-40104Mediumorg.xwiki.platform:xwiki-platform-oldcore: XWiki's REST APIs can list all pages/spaces, leading to unavailability

Stop the waste.
Protect your environment with Kodem.