Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45049Highorg.openidentityplatform.openam:openam-federation: OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServletCVE-2026-45048Highorg.openidentityplatform.openam:openam-core: OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPCCVE-2026-46495Criticalorg.openidentityplatform.opendj:opendj-server-legacy: OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMICVE-2026-44795Highio.spinnaker.rosco:rosco-core: Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific typesCVE-2026-44793Loworg.openidentityplatform.openam:openam-federation-library: OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`CVE-2026-44203Criticalorg.openidentityplatform.openam:openam-oauth2: OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)CVE-2026-44202Mediumorg.openidentityplatform.openam:openam-core: OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`CVE-2026-44179Criticalcom.xwiki.pro:xwiki-pro-macros: xwiki-pro-macros has remote code execution from page title and content via excerpt-include macroCVE-2026-41573Highorg.openidentityplatform.openam:openam-core-rest: OpenAM has LDAP Injection via `_queryId` ParameterCVE-2026-57168Criticalio.openremote:openremote-manager: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)GHSA-C7JM-38GQ-H67HMediumorg.http4k:http4k-security-digest: http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in…GHSA-PR33-38XX-6R26Mediumorg.http4k:http4k-core: http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now…GHSA-M4W9-HJFW-VWJ4Highorg.http4k:http4k-core: http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash`…GHSA-JRPC-7VXP-69P6Mediumorg.http4k:http4k-core: http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`CVE-2026-55847Mediumio.qameta.allure:allure-generator: Allure Report: Stored XSS via unescaped ANSI helper in status message/trace renderingCVE-2026-55846Mediumio.qameta.allure:allure-commandline: Allure Report: Path Traversal in HTTP Server Allows Arbitrary File ReadCVE-2026-55773Highcom.cedarpolicy:cedar-java: CedarJava has policy injection vulnerabilityCVE-2026-55772Highcom.cedarpolicy:cedar-java: CedarJava has type confusion vulnerability CVE-2026-55414Mediumnl.nl-portal:form: NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)CVE-2026-11752Mediumcom.linecorp.armeria:armeria-xds: Armeria: External Control of File Name or Path in xDS SDS DataSourceCVE-2026-54683Mediumnl.nl-portal:documenten-api: NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)CVE-2026-56740Highorg.jline:jline-remote-telnet: JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON VariablesCVE-2026-56741Highorg.jline:jline-remote-telnet: JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal GeometryGHSA-2C85-RFCC-G74JHighio.karatelabs:karate-core: Karate Mock Server RCE via embedded expression evaluation of request-derived dataCVE-2026-55226Mediumio.strimzi:strimzi: Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator

Stop the waste.
Protect your environment with Kodem.