org.yamcs:yamcs-core vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55566Mediumorg.yamcs:yamcs-core: Yamcs has DOM XSS in Extension RoutingCVE-2026-55565Criticalorg.yamcs:yamcs-core: Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)CVE-2026-55559Criticalorg.yamcs:yamcs-core: Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)CVE-2026-55552Highorg.yamcs:yamcs-core: Yamcs has Unauthenticated Directory TraversalCVE-2026-55549Mediumorg.yamcs:yamcs-core: Yamcs has Reflected XSS in the URL of the Authorize EndpointCVE-2026-55548Mediumorg.yamcs:yamcs-core: Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packetsCVE-2026-55547Mediumorg.yamcs:yamcs-core: Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security…CVE-2026-55545Mediumorg.yamcs:yamcs-core: Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforceCVE-2026-55521Highorg.yamcs:yamcs-core: Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilitiesCVE-2026-55511Criticalorg.yamcs:yamcs-core: Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`CVE-2026-46621Criticalorg.yamcs:yamcs-core: Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code InjectionCVE-2026-46562Criticalorg.yamcs:yamcs-core: Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm overrideCVE-2026-44632Criticalorg.yamcs:yamcs-core: Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`CVE-2026-44596Mediumorg.yamcs:yamcs-core: Yamcs has No Rate Limiting on Authentication EndpointCVE-2026-44595Mediumorg.yamcs:yamcs-core: Yamcs vulnerable to unauthorized user enumeration via IAM API endpointsCVE-2026-42568Mediumorg.yamcs:yamcs-core: Yamcs Vulnerable to LDAP Injection in LdapAuthModule

Stop the waste.
Protect your environment with Kodem.