Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44891Highio.netty:netty-codec-stomp: Netty: Denial of Service via Unbounded Headers in StompSubframeDecoderCVE-2026-59955Highcom.ctrip.framework.apollo:apollo: Apollo ConfigService access key authentication bypass via raw config file appId parsingCVE-2026-59954Highcom.ctrip.framework.apollo:apollo: Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matchingCVE-2025-32781Mediumcom.ctrip.framework.apollo:apollo: Apollo Portal: There is a risk of unauthorized access to the Apollo configuration centerCVE-2026-49485Highca.uhn.hapi.fhir:org.hl7.fhir.dstu2: org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP EndpointGHSA-Q6GH-6V2R-HJV3Mediumio.micronaut:micronaut-http-client: Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headersGHSA-387M-935M-C4VWHighio.micronaut:micronaut-http-client: Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoSCVE-2026-49464Highnl.nl-portal:taak: NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taakCVE-2026-49463Mediumnl.nl-portal:documenten-api: NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-librariesCVE-2026-49833Mediumorg.dspace:dspace-api: DSpace: Path Traversal is possible through LDN message generationCVE-2026-49830Mediumorg.dspace:dspace-api: DSpace: ORE resource URI does not validate scheme for non-web resourcesCVE-2026-49831Mediumorg.dspace:dspace-api: DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output pathCVE-2026-49832Highorg.dspace:dspace-api: DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDNCVE-2026-34151Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+GHSA-CGFV-JRFP-2R7VHighio.openremote:openremote-manager: OpenRemote has Authenticated SQL Injection via Datapoint Crosstab ExportCVE-2026-54640Highio.openremote:openremote-agent: OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected…CVE-2026-54641Highio.openremote:openremote-manager: OpenRemote has Cross-Realm User Information Disclosure in UserResourceImplCVE-2026-49439Mediumio.openremote:openremote-manager: OpenRemote read-only asset users can write predicted datapointsCVE-2026-53913Criticalorg.apache.camel:camel-keycloak: Apache Camel: KeycloakSecurityPolicy has Improper Authentication, Missing Authentication for Critical Function and Failing Open…CVE-2026-48205Criticalorg.apache.camel:camel-dns: Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) CVE-2026-48204Criticalorg.apache.camel:camel-mongodb-gridfs: Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered  gridfs.*  HTTP…CVE-2026-54617Criticalpro.gravit.launcher:launchserver-api: LaunchServer FileServerHandler has an unauthenticated path traversal issueCVE-2026-2092Highorg.keycloak:keycloak-services: Keycloak: Unauthorized access via improper validation of encrypted SAML assertionsCVE-2026-53712Highcom.ongres.scram:scram-client: OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithmsCVE-2026-9795Highorg.keycloak:keycloak-services: Keycloak has privilege escalation via improper scope mapping enforcement

Stop the waste.
Protect your environment with Kodem.