Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-68925Mediumnet.gleske:jervis: Jervis Has a JWT Algorithm Confusion VulnerabilityCVE-2025-68704Highnet.gleske:jervis: Jervis Has Weak Random for Timing Attack MitigationCVE-2025-68703Highnet.gleske:jervis: Jervis's Salt for PBKDF2 derived from passwordCVE-2025-68702Highnet.gleske:jervis: Jervis Has a SHA-256 Hex String Padding BugCVE-2025-68701Highnet.gleske:jervis: Jervis has Deterministic AES IV Derivation from PassphraseCVE-2025-68698Highnet.gleske:jervis: Jervis Has a RSA PKCS#1 Padding VulnerabilityCVE-2025-68493Highorg.apache.struts:struts2-core: Apache Struts 2 is Missing XML ValidationCVE-2025-65091Criticalorg.xwiki.contrib:macro-fullcalendar-pom: XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONServiceCVE-2025-65090Mediumorg.xwiki.contrib:macro-fullcalendar-pom: XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONServiceCVE-2025-70974Criticalcom.alibaba:fastjson: FASTJSON Includes Functionality from Untrusted Control Sphere CVE-2026-0707Mediumorg.keycloak:keycloak-parent: Keycloak has Incorrect Behavior Order: Authorization Before Parsing and CanonicalizationCVE-2026-22187Mediumome:pom-bio-formats: Bio-Formats performs unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processingCVE-2026-22186Mediumome:pom-bio-formats: Bio-Formats has an XML External Entity (XXE) vulnerabilityCVE-2026-22244Highorg.open-metadata:platform: OpenMetadata's Server-Side Template Injection (SSTI) in FreeMarker email templates leads to RCECVE-2025-12543Criticalio.undertow:undertow-core: Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requestsCVE-2025-66560Mediumio.quarkus:quarkus-rest: Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to writeCVE-2025-61916Highio.spinnaker.clouddriver:clouddriver-artifacts: Spinnaker vulnerable to SSRF due to improper restrictions on http from user inputCVE-2025-68280Mediumorg.apache.sis.core:sis-metadata: Apache SIS has Improper Restriction of XML External Entity Reference vulnerabilityCVE-2026-21452Highorg.msgpack:msgpack-core: MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload AllocationCVE-2025-66518Highorg.apache.kyuubi:kyuubi-server_2.12: Apache Kyuubi Server vulnerable to Path TraversalCVE-2025-15022Mediumcom.vaadin:vaadin-server: Vaadin vulnerable to Cross-site ScriptingCVE-2025-47411Mediumorg.apache.streampipes:streampipes-parent: Apache StreamPipes has Improper Privilege Management issueCVE-2025-13467Mediumorg.keycloak:keycloak-ldap-federation: Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserializationCVE-2025-66524Highorg.apache.nifi:nifi-asana-processors: Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe DeserializationCVE-2025-68390Mediumorg.elasticsearch.plugin:x-pack-core: Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation

Stop the waste.
Protect your environment with Kodem.