Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-33013Highio.micronaut:micronaut-json-core: Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indicesCVE-2025-54920Highorg.apache.spark:spark-core_2.13: Apache Spark: Spark History Server Code Execution VulnerabilityCVE-2026-25534Criticalio.spinnaker.clouddriver:clouddriver-artifacts: Spinnaker clouddriver and orca URL validation bypass via underscores in hostnamesCVE-2025-66249Mediumorg.apache.livy:livy-server: Apache Livy: Unauthorized directory accessCVE-2025-60012Mediumorg.apache.livy:livy-server: Apache Livy: Restrict file access CVE-2026-2366Low@keycloak/keycloak-admin-client: Keycloak vulnerable to authorization bypass via the Admin APICVE-2026-3429Mediumorg.keycloak:keycloak-services: Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST APICVE-2026-3911Loworg.keycloak:keycloak-services: Keycloak: Information disclosure of disabled user attributes via administrative endpointCVE-2026-2741Lowcom.vaadin:flow-project: Vaadin: Specially crafted ZIP archives can escape the intended extraction directoryCVE-2026-2742Mediumcom.vaadin:flow-server: Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing SlashCVE-2026-23907Mediumorg.apache.pdfbox:pdfbox-examples: Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() functionCVE-2026-24713Criticalorg.apache.iotdb:iotdb-core: Apache IoTDB has an Improper Input Validation vulnerabilityCVE-2026-24015Criticalorg.apache.iotdb:iotdb-core: Apache IoTDB has an Insecure Default Configuration VulnerabilityCVE-2026-24281Highorg.apache.zookeeper:zookeeper: Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManagerCVE-2026-24308Highorg.apache.zookeeper:zookeeper: Apache ZooKeeper has improper handling of configuration valuesCVE-2025-11143Loworg.eclipse.jetty:jetty-http: org.eclipse.jetty:jetty-http has different parsing of invalid URIsCVE-2026-22723Mediumorg.cloudfoundry.identity:cloudfoundry-identity-server: Cloudfoundry UAA has logic error in the token revocation endpoint implementationCVE-2026-3009Highorg.keycloak:keycloak-services: Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administratorCVE-2026-3047Highorg.keycloak:keycloak-broker-saml: Keycloak SAML Broken has Authentication Bypass by Primary WeaknessCVE-2026-1605Highorg.eclipse.jetty:jetty-server: The Eclipse Jetty Server Artifact has a Gzip request memory leak CVE-2026-29000Criticalorg.pac4j:pac4j-jwt: pac4j-jwt: JwtAuthenticator Authentication Bypass via JWE-Wrapped PlainJWTCVE-2026-29062Hightools.jackson.core:jackson-core: jackson-core has Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource ExhaustionCVE-2025-66024Highorg.xwiki.contrib.blog:application-blog-ui: XWiki Blog Application home page vulnerable to Stored XSS via Post TitleCVE-2026-27446Criticalorg.apache.activemq:artemis-server: Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical FunctionsCVE-2025-66168Mediumorg.apache.activemq:apache-activemq: Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound

Stop the waste.
Protect your environment with Kodem.