Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40105Mediumorg.xwiki.platform:xwiki-platform-web-templates: XWiki has Reflected Cross-Site Scripting (XSS) in page history compareCVE-2026-39842Criticalio.openremote:openremote-manager: Expression Injection in OpenRemoteCVE-2026-37980Mediumorg.keycloak:keycloak-services: Keycloak: Arbitrary code execution via Stored Cross-Site Scripting (XSS) in organization selection login pageCVE-2026-33929Mediumorg.apache.pdfbox:pdfbox-examples: Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example CodeCVE-2026-40490Mediumorg.asynchttpclient:async-http-client: AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirectsCVE-2026-5795Highorg.eclipse.jetty.ee11:jetty-ee11-jaspi: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variablesCVE-2026-35582Highgov.nsa.emissary:emissary: Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in ExecutrixCVE-2026-35337Highorg.apache.storm:storm-client: Apache Storm: Deserialization of Untrusted Data vulnerabilityCVE-2026-35565Mediumorg.apache.storm:storm-webapp: Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology MetadataCVE-2026-6125Loworg.dromara.warm:warm-flow-plugin-modes-sb: Warm-Flow has a SpEL Expression Injection in SpelHelper.parseExpressionCVE-2026-34479Mediumorg.apache.logging.log4j:log4j-1.2-api: Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden charactersCVE-2026-34481Mediumorg.apache.logging.log4j:log4j-layout-template-json: Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayoutCVE-2026-34478Mediumorg.apache.logging.log4j:log4j-core: Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibilityCVE-2026-34480Mediumorg.apache.logging.log4j:log4j-core: Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden charactersCVE-2026-34477Mediumorg.apache.logging.log4j:log4j-core: Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configurationCVE-2026-39304Highorg.apache.activemq:activemq-client: Apache ActiveMQ: Denial of Service via Out of Memory vulnerabilityCVE-2026-22750Highorg.springframework.cloud:spring-cloud-gateway: Spring Cloud Gateway's SSL bundle configuration silently bypassedCVE-2026-34500Mediumorg.apache.tomcat:tomcat-coyote-ffm: Apache Tomcat: CLIENT_CERT authentication does not fail as expectedCVE-2026-34486Highorg.apache.tomcat:tomcat: Apache Tomcat Missing Encryption of Sensitive Data vulnerabilityCVE-2026-34483Highorg.apache.tomcat:tomcat-catalina: Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValveCVE-2026-34487Highorg.apache.tomcat:tomcat: Apache Tomcat vulnerable to Insertion of Sensitive Information into Log FileCVE-2026-32990Mediumorg.apache.tomcat:tomcat: Apache Tomcat has an Improper Input Validation vulnerabilityCVE-2026-25854Mediumorg.apache.tomcat:tomcat-catalina: Apache Tomcat has an Open Redirect vulnerabilityCVE-2026-29129Highorg.apache.tomcat:tomcat: Apache Tomcat: Configured cipher preference order not preservedCVE-2026-29145Criticalorg.apache.tomcat:tomcat: Apache Tomcat: CLIENT_CERT authentication does not fail as expected

Stop the waste.
Protect your environment with Kodem.