Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55225Highio.strimzi:strimzi: Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`CVE-2026-55471Criticalca.uhn.hapi.fhir:org.hl7.fhir.utilities: HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactoryCVE-2026-55470Highca.uhn.hapi.fhir:org.hl7.fhir.dstu2: HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoSCVE-2026-55760Highcom.github.jknack:handlebars: handlebars.java FileTemplateLoader Path TraversalCVE-2026-55405Highdev.langchain4j:langchain4j-mariadb: LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvectorCVE-2026-49268Highorg.apache.shiro:shiro-core: Apache Shiro: LDAP DN Injection in DefaultLdapRealmCVE-2026-47340Mediumorg.apache.dolphinscheduler:dolphinscheduler-api: Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with…CVE-2026-42357Mediumorg.apache.dolphinscheduler:dolphinscheduler-api: Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects…CVE-2026-41280Mediumorg.apache.dolphinscheduler:dolphinscheduler-api: Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in…CVE-2026-32967Criticalorg.apache.dolphinscheduler:dolphinscheduler-api: Apache DolphinScheduler: The `/v2` experimental interface lacks permission checksCVE-2026-32966Criticalorg.apache.dolphinscheduler:dolphinscheduler-api: Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure CVE-2026-50560Mediumio.netty:netty-codec-http2: Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signatureCVE-2026-50020Mediumio.netty:netty-codec-http: Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permittedCVE-2026-50011Highio.netty:netty-codec-redis: Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array lengthCVE-2026-50010Highio.netty:netty-handler: Netty: Wrapping plain trust manager silently disables hostname verificationCVE-2026-50009Mediumio.netty:netty-codec-classes-quic: Netty: QUIC stateless reset token material exposed through header-visible connection IDsCVE-2026-48748Highio.netty:netty-codec-http3: Netty HTTP/3 QPACK Blocked Streams Memory ExhaustionCVE-2026-54697Mediumorg.connectbot.sshlib:sshlib: ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsingCVE-2026-54700Mediumorg.connectbot.sshlib:sshlib: ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocationGHSA-J9GF-VW2F-9HRWHighcom.appsmith:server: Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generationGHSA-9WCP-79G5-5C3CHighcom.appsmith:server: Appsmith Super User Creation Race Condition Allows Multiple Instance AdministratorsCVE-2025-58175Mediumorg.geoserver.web:gs-web-app: GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity ResolutionCVE-2025-52465Highorg.geoserver.web:gs-web-app: GeoServer has an arbitrary file write vulnerability in its Master Password Dump PageCVE-2025-27511Highorg.geoserver.extension:gs-db2: GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store ConnectionCVE-2026-48059Highio.netty:netty-codec-haproxy: Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

Stop the waste.
Protect your environment with Kodem.