Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-85717Mediumorg.asynchttpclient:async-http-client: AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect targetCVE-2026-85720Mediumorg.asynchttpclient:async-http-client: AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT requestCVE-2026-85721Highorg.asynchttpclient:async-http-client: AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of serviceCVE-2026-85716Loworg.asynchttpclient:async-http-client: AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responsesCVE-2026-73245Mediumio.kestra:kestra: Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-authCVE-2026-73247Highio.kestra:core: Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadataCVE-2026-86071Lowcom.github.junrar:junrar: Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction rootCVE-2026-61700Loworg.mariadb.jdbc:mariadb-java-client: MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requestsCVE-2026-63126Highcom.squareup.wire:wire-runtime: Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)CVE-2026-75516Highcom.rabbitmq:amqp-client: RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcementCVE-2026-88975Highorg.http4s:http4s-ember-core_2.13: Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZECVE-2026-69201Mediumorg.http4s:http4s-server_2.12: Http4s: ResourceService and Webjar Service path escape via percent-encoded separatorsCVE-2026-69218Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2: unbounded continuation frame accumulationCVE-2026-69216Mediumorg.http4s:http4s-ember-core_2.12: Http4s: Ember chunk parser lenience (TE.TE request smuggling)CVE-2026-69215Mediumorg.http4s:http4s-client_2.12: Http4s: CookieJar middleware matches by substring, leaking cookies cross-originCVE-2026-69214Mediumorg.http4s:http4s-client_2.12: Http4s: CookieJar middleware accepts arbitrary Set-Cookie domainCVE-2026-69213Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2 has an unbounded outbound frame queueCVE-2026-69208Highorg.http4s:http4s-ember-server_2.12: Http4s: DigestAuth nonce map grows unboundedCVE-2026-69206Mediumorg.http4s:http4s-ember-core_2.12: Http4s: DigestAuth allows replay of captured requestsCVE-2026-69205Highorg.http4s:http4s-ember-core_3: Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)CVE-2026-69204Criticalorg.http4s:http4s-ember-core_2.12: Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)CVE-2026-69203Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMSCVE-2026-69202Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2: unbounded inbound body bufferingCVE-2026-11745Highcom.linecorp.centraldogma:centraldogma-server-mirror-git: Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)CVE-2026-11746Criticalcom.linecorp.centraldogma:centraldogma-server: Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover

Stop the waste.
Protect your environment with Kodem.