Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-4634Highorg.keycloak:keycloak-services: Keycloak: Application-Level DoS via Scope ProcessingCVE-2026-4282Highorg.keycloak:keycloak-services: Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flawCVE-2026-4325Mediumorg.keycloak:keycloak-services: Keycloak: Replay of action tokens via improper handling of single-use entriesCVE-2026-4636Highorg.keycloak:keycloak-services: Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission GrantsCVE-2026-3872Highorg.keycloak:keycloak-services: Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpointCVE-2026-34237Mediumio.modelcontextprotocol.sdk:mcp-core: MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)CVE-2026-34361Criticalca.uhn.hapi.fhir:org.hl7.fhir.validation: FHIR Validator HTTP service has SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token TheftCVE-2026-34360Mediumca.uhn.hapi.fhir:org.hl7.fhir.core: FHIR Validator: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network ProbingCVE-2026-34359Highca.uhn.hapi.fhir:org.hl7.fhir.core: HAPI FHIR Core has Authentication Credential Leakage via Improper URL Prefix Matching on HTTP RedirectCVE-2026-34214Highio.trino:trino-iceberg: Trino: Iceberg REST catalog static and vended credentials are accessible via query JSONGHSA-443W-3RQ3-5M5HHighsoftware.amazon.awssdk:cloudfront: AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing UtilitiesCVE-2026-28368Highio.undertow:undertow-parent: Undertow is Vulnerable to HTTP Request/Response SmugglingCVE-2026-28367Highio.undertow:undertow-parent: Undertow is Vulnerable to HTTP Request/Response SmugglingCVE-2026-28369Highio.undertow:undertow-parent: Undertow is Vulnerable to HTTP Request/Response SmugglingCVE-2026-22744Highorg.springframework.ai:spring-ai-redis-store: Spring AI Redis Store has TAG Field Query Injection Through Improper Neutralization of Special CharactersCVE-2026-22742Highorg.springframework.ai:spring-ai-bedrock-converse: Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLsCVE-2026-22743Highorg.springframework.ai:spring-ai-neo4j-store: Spring AI has a Cypher Injection vulnerability in Neo4jVectorFilterExpressionConverterCVE-2026-22738Criticalorg.springframework.ai:spring-ai-vector-store: Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression keyCVE-2026-3190Mediumorg.keycloak:keycloak-server-spi-private: Keycloak: Missing Role Enforcement on UMA 2.0 Permission Ticket Endpoint Leads to Information DisclosureCVE-2026-3121Mediumorg.keycloak:keycloak-services: Keycloak: manage-clients permission escalates to full realm admin accessCVE-2026-33871Highio.netty:netty-codec-http2: Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame BypassCVE-2026-33870Highio.netty:netty-codec-http: Netty: HTTP Request Smuggling via Chunked Extension Quoted-String ParsingGHSA-H8W2-RV57-VC6FCriticalcom.splunk:splunk-otel-javaagent: splunk-otel-javaagent: Unsafe deserialization in RMI instrumentation may lead to Remote Code ExecutionCVE-2026-33728Criticalcom.datadoghq:dd-java-agent: dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code executionCVE-2026-4874Loworg.keycloak:keycloak-services: Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation

Stop the waste.
Protect your environment with Kodem.