Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59899Mediumio.netty:netty-codec-http: Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of ServiceCVE-2026-59898Mediumio.netty:netty-codec-http: Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validationCVE-2026-56822Highio.netty:netty-handler-ssl-ocsp: Netty: TOCTOU in OcspServerCertificateValidatorCVE-2026-56821Highio.netty:netty-handler-ssl-ocsp: Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidatorCVE-2026-56820Highio.netty:netty-handler-ssl-ocsp: Netty: Missing CertificateID Validation in OCSP Response Allows Replay AttacksCVE-2026-56817Highio.netty:netty-codec-xml: Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handlingCVE-2026-56816Highio.netty:netty-codec-http3: Netty: Memory Exhaustion via HTTP/3 Reserved Frame TypesCVE-2026-56746Mediumio.netty:netty-codec-http: Netty: Security Control Bypass via CORS Short-Circuit FailureCVE-2026-56745Highio.netty:netty-codec-http: Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory ExhaustionCVE-2026-55851Highio.netty:netty-codec-haproxy: Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory ExhaustionCVE-2026-55833Highio.netty:netty-codec-http: Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncationCVE-2026-55831Highio.netty:netty-codec-http: Netty SPDY SETTINGS frame count materializes unbounded settings mapCVE-2026-59889Mediumcom.fasterxml.jackson.core:jackson-databind: jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserializationGHSA-R7WM-3CXJ-WFF9Highcom.fasterxml.jackson.core:jackson-core: jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)GHSA-MHM7-754M-9P8WMediumcom.fasterxml.jackson.core:jackson-databind: jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`CVE-2026-59888Mediumcom.fasterxml.jackson.core:jackson-databind: jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategyCVE-2026-54291Highorg.postgresql:postgresql: PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithmsCVE-2026-11400Highsoftware.amazon.jdbc:aws-advanced-jdbc-wrapper: AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instanceGHSA-X8MG-6R4P-87PFHighcom.arcadedb:arcadedb-server: ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorizationGHSA-VWJC-V7X7-CM6GHighcom.arcadedb:arcadedb-engine: ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE jsGHSA-X9F9-R4M8-9XC2Highcom.arcadedb:arcadedb-engine: ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)GHSA-48QW-824M-86PRHighcom.arcadedb:arcadedb-server: ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file readCVE-2026-54076Highcom.arcadedb:arcadedb-engine: ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)CVE-2026-54077Highcom.arcadedb:arcadedb-engine: ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated usersCVE-2026-50270Highcom.datadoghq:dd-java-agent: dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

Stop the waste.
Protect your environment with Kodem.