Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-48043Mediumio.netty:netty-codec-http2: netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory ExhaustionCVE-2026-48040Mediumio.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringssl: netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory…CVE-2026-48006Highio.netty:netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregatorCVE-2026-40987Highorg.springframework.integration:spring-integration-file: Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystemCVE-2025-53114Highorg.cometd.java:cometd-java-server-common: Acknowledgement extension out of memoryCVE-2026-53441Highorg.jenkins-ci.main:jenkins-core: Jenkins: Stored XSS vulnerability in node offline cause description CVE-2026-47838Mediumorg.springframework.security:spring-security-web: Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client CertificatesCVE-2026-41726Mediumorg.springframework.kafka:spring-kafka: In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector headerCVE-2026-41731Highorg.springframework.kafka:spring-kafka: In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserializationCVE-2026-47691Highio.netty:netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS RecordsCVE-2026-47244Mediumio.netty:netty-codec-http2: Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforcedCVE-2026-46340Highio.netty:netty-transport-sctp: Netty: SCTP reassembly nests buffers without boundCVE-2026-45674Highio.netty:netty-resolver-dns: Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME RecordsCVE-2026-45673Mediumio.netty:netty-resolver-dns: Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source PortCVE-2026-45536Mediumio.netty:netty-transport-native-epoll: Netty: Unix-socket fd receive leaks descriptors when peer sends two at onceCVE-2026-45416Highio.netty:netty-handler: Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytesCVE-2026-44894Highio.netty:netty-codec-classes-quic: Netty's Default QUIC token handler accepts any client-supplied tokenCVE-2026-44893Highio.netty:netty-codec-haproxy: Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV lengthCVE-2026-44892Highio.netty:netty-codec-http3: Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header SizeCVE-2026-44890Highio.netty:netty-codec-redis: Netty has Unbounded Direct Memory Consumption in its RedisDecoderCVE-2026-44250Highio.netty:netty-codec-redis: Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested ArraysCVE-2026-44249Highio.netty:netty-handler: Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator MaskingCVE-2026-9088Loworg.keycloak:keycloak-services: Keycloak: Information disclosure due to user profile permission bypassCVE-2026-50076Criticalorg.apache.fory:fory-core: Apache Fory Java SDK Has Deserialization of Untrusted Data in the Java replace-resolve pathCVE-2026-47672Mediumcom.oviva.telematik:epa4all-rest-service: epa4all-client: Unauthenticated REST API for Patient Record Writes

Stop the waste.
Protect your environment with Kodem.