Putki Security Vulnerability Scans
Last Updated: 01 Sep 2026 00:44:20
Quick Navigation
↑Development
Severity Breakdown
| Severity | Count |
|---|---|
| HIGH | 7 |
| MEDIUM | 9 |
Details for version: Development
CVE Details for Version: Development
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-67721 | aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| MEDIUM | 6.5 | CVE-2016-5004 | xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip |
| MEDIUM | 6.5 | CVE-2026-54518 | jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-54516 | jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties |
| MEDIUM | 5.3 | CVE-2026-54517 | jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application |
↑2026.06
Severity Breakdown
| Severity | Count |
|---|---|
| HIGH | 20 |
| MEDIUM | 31 |
| LOW | 8 |
Details for version: 2026.06
CVE Details for Version: 2026.06
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-14456 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| HIGH | 8.0 | CVE-2026-26740 | giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-47063 | openjdk: Enhance Jar handling (Oracle CPU 2026-07) |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | CVE-2026-62574 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Orac ... |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-54428 | org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| MEDIUM | 6.5 | CVE-2016-5004 | xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip |
| MEDIUM | 6.5 | CVE-2026-54518 | jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59903 | Netty is an asynchronous, event-driven network application framework. ... |
| MEDIUM | 6.5 | CVE-2026-59949 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ... |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2026-10051 | jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections |
| MEDIUM | 5.5 | CVE-2026-18798 | openssl: QUIC server may trigger double free when processing INITIAL packet |
| MEDIUM | 5.5 | CVE-2026-46917 | openjdk: Improve DTLS handshaking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-46968 | openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47021 | openjdk: Enhance XBM image support (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47027 | openjdk: Enhance Jar file processing (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-49844 | org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-60147 | openjdk: Improve certification checking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-63072 | openssl: heap buffer overflow in CMS key unwrapping |
| MEDIUM | 5.5 | CVE-2026-63076 | openssl: invalid pointer dereference in CMP server via crafted protectionAlg |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-54516 | jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties |
| MEDIUM | 5.3 | CVE-2026-54517 | jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application |
| MEDIUM | 5.3 | CVE-2026-64607 | org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-8384 | jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| LOW | 2.0 | CVE-2026-14457 | openssl: RPK server signature algorithm selection can dereference a missing certificate |
| LOW | 2.0 | CVE-2026-47010 | openjdk: Enhance JPEG handling (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-47059 | openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-54874 | openssl: excessive memory use buffering DTLS records for a future epoch |
| LOW | 2.0 | CVE-2026-63073 | openssl: untrusted sender DN used as format string in CMP response validation |
| LOW | 2.0 | CVE-2026-63074 | openssl: CMP indefinite cache growth of ExtraCerts |
| LOW | 2.0 | CVE-2026-63075 | openssl: QUIC ACK-only packet retention can cause memory exhaustion |
| LOW | 2.0 | CVE-2026-75803 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ... |
↑2026.03.05
Severity Breakdown
| Severity | Count |
|---|---|
| HIGH | 34 |
| MEDIUM | 45 |
| LOW | 11 |
Details for version: 2026.03.05
CVE Details for Version: 2026.03.05
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-14456 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| HIGH | 8.0 | CVE-2026-26740 | giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-47063 | openjdk: Enhance Jar handling (Oracle CPU 2026-07) |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | CVE-2026-62574 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Orac ... |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2026-1605 | org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42577 | Netty is an asynchronous, event-driven network application framework. ... |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-54428 | org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2016-5004 | xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59903 | Netty is an asynchronous, event-driven network application framework. ... |
| MEDIUM | 6.5 | CVE-2026-59949 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ... |
| MEDIUM | 5.9 | CVE-2026-28208 | com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2026-10051 | jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections |
| MEDIUM | 5.5 | CVE-2026-18798 | openssl: QUIC server may trigger double free when processing INITIAL packet |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-46917 | openjdk: Improve DTLS handshaking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-46968 | openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47021 | openjdk: Enhance XBM image support (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47027 | openjdk: Enhance Jar file processing (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-49844 | org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-60147 | openjdk: Improve certification checking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-63072 | openssl: heap buffer overflow in CMS key unwrapping |
| MEDIUM | 5.5 | CVE-2026-63076 | openssl: invalid pointer dereference in CMP server via crafted protectionAlg |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-64607 | org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names |
| MEDIUM | 5.3 | CVE-2026-8384 | jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.0 | CVE-2026-14457 | openssl: RPK server signature algorithm selection can dereference a missing certificate |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| LOW | 2.0 | CVE-2026-47010 | openjdk: Enhance JPEG handling (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-47059 | openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-54874 | openssl: excessive memory use buffering DTLS records for a future epoch |
| LOW | 2.0 | CVE-2026-63073 | openssl: untrusted sender DN used as format string in CMP response validation |
| LOW | 2.0 | CVE-2026-63074 | openssl: CMP indefinite cache growth of ExtraCerts |
| LOW | 2.0 | CVE-2026-63075 | openssl: QUIC ACK-only packet retention can cause memory exhaustion |
| LOW | 2.0 | CVE-2026-75803 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ... |
↑2026.03.04
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 1 |
| HIGH | 31 |
| MEDIUM | 40 |
| LOW | 4 |
Details for version: 2026.03.04
CVE Details for Version: 2026.03.04
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.8 | CVE-2026-47065 | CVE-2026-47065: Deserialization of Untrusted Data |
| HIGH | 8.8 | CVE-2025-69194 | CVE-2025-69194 |
| HIGH | 8.7 | CVE-2026-10050 | CVE-2026-10050: Improper Handling of Alternate Encoding |
| HIGH | 8.7 | CVE-2026-33871 | CVE-2026-33871: Allocation of Resources Without Limits or Throttling |
| HIGH | 8.7 | CVE-2026-35554 | CVE-2026-35554: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
| HIGH | 8.7 | CVE-2026-45674 | CVE-2026-45674: Insufficient Verification of Data Authenticity |
| HIGH | 8.7 | CVE-2026-47691 | CVE-2026-47691: Insufficient Verification of Data Authenticity |
| HIGH | 8.7 | CVE-2026-56745 | CVE-2026-56745: Uncontrolled Resource Consumption |
| HIGH | 8.7 | CVE-2026-59901 | CVE-2026-59901: Loop with Unreachable Exit Condition ('Infinite Loop') |
| HIGH | 8.7 | GHSA-r7wm-3cxj-wff9 | GHSA-r7wm-3cxj-wff9: Allocation of Resources Without Limits or Throttling |
| HIGH | 8.2 | CVE-2026-26740 | CVE-2026-26740 |
| HIGH | 8.2 | CVE-2026-54291 | CVE-2026-54291: Not Failing Securely ('Failing Open') |
| HIGH | 8.1 | CVE-2026-44249 | CVE-2026-44249: Improper Access Control |
| HIGH | 8.1 | CVE-2026-54512 | CVE-2026-54512: Incomplete List of Disallowed Inputs |
| HIGH | 8.1 | CVE-2026-54513 | CVE-2026-54513: Incomplete List of Disallowed Inputs |
| HIGH | 7.8 | CVE-2026-62574 | CVE-2026-62574 |
| HIGH | 7.5 | CVE-2022-41404 | CVE-2022-41404: Uncontrolled Resource Consumption |
| HIGH | 7.5 | CVE-2026-1605 | CVE-2026-1605: Uncontrolled Resource Consumption |
| HIGH | 7.5 | CVE-2026-33870 | CVE-2026-33870: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| HIGH | 7.5 | CVE-2026-42198 | CVE-2026-42198: Allocation of Resources Without Limits or Throttling |
| HIGH | 7.5 | CVE-2026-42577 | CVE-2026-42577: Missing Release of Resource after Effective Lifetime |
| HIGH | 7.5 | CVE-2026-42579 | CVE-2026-42579: Improper Input Validation |
| HIGH | 7.5 | CVE-2026-42583 | CVE-2026-42583: Uncontrolled Resource Consumption |
| HIGH | 7.5 | CVE-2026-42587 | CVE-2026-42587: Uncontrolled Resource Consumption |
| HIGH | 7.5 | CVE-2026-45416 | CVE-2026-45416: Allocation of Resources Without Limits or Throttling |
| HIGH | 7.5 | CVE-2026-47063 | CVE-2026-47063 |
| HIGH | 7.5 | CVE-2026-50010 | CVE-2026-50010: Improper Verification of Cryptographic Signature |
| HIGH | 7.5 | CVE-2026-55831 | CVE-2026-55831: Uncontrolled Resource Consumption |
| HIGH | 7.5 | CVE-2026-55833 | CVE-2026-55833: Uncontrolled Resource Consumption |
| HIGH | 7.5 | CVE-2026-56819 | CVE-2026-56819: Uncontrolled Resource Consumption |
| HIGH | 7.4 | CVE-2026-2332 | CVE-2026-2332: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| HIGH | 7.3 | CVE-2026-42584 | CVE-2026-42584: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| MEDIUM | 6.9 | CVE-2026-10051 | CVE-2026-10051: Exposure of Sensitive Information to an Unauthorized Actor |
| MEDIUM | 6.9 | CVE-2026-34478 | CVE-2026-34478: Improper Output Neutralization for Logs |
| MEDIUM | 6.9 | CVE-2026-34480 | CVE-2026-34480: Improper Encoding or Escaping of Output |
| MEDIUM | 6.9 | CVE-2026-50560 | CVE-2026-50560: Allocation of Resources Without Limits or Throttling |
| MEDIUM | 6.9 | CVE-2026-59899 | CVE-2026-59899: Allocation of Resources Without Limits or Throttling |
| MEDIUM | 6.9 | CVE-2026-59900 | CVE-2026-59900: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| MEDIUM | 6.9 | GHSA-72hv-8253-57qq | GHSA-72hv-8253-57qq: Allocation of Resources Without Limits or Throttling |
| MEDIUM | 6.8 | CVE-2026-45673 | CVE-2026-45673: Use of Insufficiently Random Values |
| MEDIUM | 6.5 | CVE-2016-5004 | CVE-2016-5004: Uncontrolled Resource Consumption |
| MEDIUM | 6.5 | CVE-2024-45993 | CVE-2024-45993 |
| MEDIUM | 6.5 | CVE-2025-48924 | CVE-2025-48924: Uncontrolled Recursion |
| MEDIUM | 6.5 | CVE-2026-42580 | CVE-2026-42580: Integer Overflow or Wraparound |
| MEDIUM | 6.5 | CVE-2026-42585 | CVE-2026-42585: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| MEDIUM | 6.5 | CVE-2026-56746 | CVE-2026-56746: Improper Access Control |
| MEDIUM | 6.5 | CVE-2026-59888 | CVE-2026-59888: Improperly Controlled Modification of Dynamically-Determined Object Attributes |
| MEDIUM | 6.5 | CVE-2026-59949 | CVE-2026-59949: Out-of-bounds Read |
| MEDIUM | 6.5 | CVE-2026-60147 | CVE-2026-60147 |
| MEDIUM | 6.3 | CVE-2026-34477 | CVE-2026-34477: Improper Validation of Certificate with Host Mismatch |
| MEDIUM | 6.3 | CVE-2026-59898 | CVE-2026-59898: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| MEDIUM | 5.9 | CVE-2026-28208 | CVE-2026-28208: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| MEDIUM | 5.9 | CVE-2026-41245 | CVE-2026-41245: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| MEDIUM | 5.8 | CVE-2026-42581 | CVE-2026-42581: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| MEDIUM | 5.7 | CVE-2026-59921 | CVE-2026-59921: Improper Neutralization of CRLF Sequences ('CRLF Injection') |
| MEDIUM | 5.3 | CVE-2026-33558 | CVE-2026-33558: Insertion of Sensitive Information into Log File |
| MEDIUM | 5.3 | CVE-2026-41417 | CVE-2026-41417: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| MEDIUM | 5.3 | CVE-2026-45292 | CVE-2026-45292: Allocation of Resources Without Limits or Throttling |
| MEDIUM | 5.3 | CVE-2026-46917 | CVE-2026-46917 |
| MEDIUM | 5.3 | CVE-2026-47027 | CVE-2026-47027 |
| MEDIUM | 5.3 | CVE-2026-47244 | CVE-2026-47244: Uncontrolled Resource Consumption |
| MEDIUM | 5.3 | CVE-2026-48043 | CVE-2026-48043: Uncontrolled Resource Consumption |
| MEDIUM | 5.3 | CVE-2026-50020 | CVE-2026-50020: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| MEDIUM | 5.3 | CVE-2026-54514 | CVE-2026-54514: Server-Side Request Forgery (SSRF) |
| MEDIUM | 5.3 | CVE-2026-54515 | CVE-2026-54515: Improperly Controlled Modification of Dynamically-Determined Object Attributes |
| MEDIUM | 5.3 | CVE-2026-6790 | CVE-2026-6790: Improper Input Validation |
| MEDIUM | 5.3 | CVE-2026-8384 | CVE-2026-8384: Use of Non-Canonical URL Paths for Authorization Decisions |
| MEDIUM | 5.3 | GHSA-mfg7-5gfp-c4w3 | GHSA-mfg7-5gfp-c4w3: Missing Release of Resource after Effective Lifetime |
| MEDIUM | 5.1 | CVE-2026-23868 | CVE-2026-23868 |
| MEDIUM | 4.7 | CVE-2026-71497 | CVE-2026-71497: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| MEDIUM | 4.0 | CVE-2026-41254 | CVE-2026-41254 |
| MEDIUM | 4.0 | CVE-2026-45536 | CVE-2026-45536: Exposure of Sensitive Information to an Unauthorized Actor |
| LOW | 3.7 | CVE-2025-11143 | CVE-2025-11143: Improper Input Validation |
| LOW | 3.7 | CVE-2026-47059 | CVE-2026-47059 |
| LOW | 2.9 | CVE-2026-42578 | CVE-2026-42578: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') |
| LOW | 1.9 | CVE-2026-3293 | CVE-2026-3293: Uncontrolled Resource Consumption |
↑2025.08.03
Severity Breakdown
| Severity | Count |
|---|---|
| HIGH | 44 |
| MEDIUM | 58 |
| LOW | 18 |
Details for version: 2025.08.03
CVE Details for Version: 2025.08.03
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| HIGH | 8.8 | CVE-2025-48734 | commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.2 | CVE-2025-49146 | pgjdbc: pgjdbc insecure authentication in channel binding |
| HIGH | 8.1 | CVE-2025-59250 | JDBC Driver for SQL Server has improper input validation issue |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-14456 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| HIGH | 8.0 | CVE-2026-26740 | giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-47063 | openjdk: Enhance Jar handling (Oracle CPU 2026-07) |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | CVE-2026-62574 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Orac ... |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.5 | CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2023-1370 | json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) |
| HIGH | 7.5 | CVE-2023-52428 | nimbus-jose-jwt: large JWE p2c header value causes Denial of Service |
| HIGH | 7.5 | CVE-2024-47072 | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-54428 | org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| HIGH | 7.2 | CVE-2024-13009 | jetty-server: Jetty: Gzip Request Body Buffer Corruption |
| MEDIUM | 7.5 | CVE-2025-27817 | org.apache.kafka: Kafka Client Arbitrary File Read SSRF |
| MEDIUM | 7.5 | CVE-2025-7962 | com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2016-5004 | xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2025-67735 | netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59903 | Netty is an asynchronous, event-driven network application framework. ... |
| MEDIUM | 6.5 | CVE-2026-59949 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ... |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 6.1 | CVE-2025-22227 | io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects |
| MEDIUM | 5.9 | CVE-2024-8184 | org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2023-2976 | guava: insecure temporary directory creation |
| MEDIUM | 5.5 | CVE-2025-4949 | org.eclipse.jgit: XXE vulnerability in Eclipse JGit |
| MEDIUM | 5.5 | CVE-2025-58057 | netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack |
| MEDIUM | 5.5 | CVE-2025-68161 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification |
| MEDIUM | 5.5 | CVE-2026-18798 | openssl: QUIC server may trigger double free when processing INITIAL packet |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-46917 | openjdk: Improve DTLS handshaking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-46968 | openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47021 | openjdk: Enhance XBM image support (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47027 | openjdk: Enhance Jar file processing (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-49844 | org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-60147 | openjdk: Improve certification checking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-63072 | openssl: heap buffer overflow in CMS key unwrapping |
| MEDIUM | 5.5 | CVE-2026-63076 | openssl: invalid pointer dereference in CMP server via crafted protectionAlg |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints |
| MEDIUM | 5.3 | CVE-2023-26048 | jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() |
| MEDIUM | 5.3 | CVE-2023-40167 | jetty: Improper validation of HTTP/1 content-length |
| MEDIUM | 5.3 | CVE-2024-9823 | org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter |
| MEDIUM | 5.3 | CVE-2025-31672 | org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-64607 | org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| MEDIUM | 3.7 | CVE-2024-6763 | org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority |
| LOW | 3.9 | GHSA-58qw-p7qm-5rvh | Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.5 | CVE-2023-36479 | jetty: Improper addition of quotation marks to user inputs in CgiServlet |
| LOW | 3.3 | CVE-2020-8908 | guava: local information disclosure via temporary directory created with unsafe permissions |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.7 | CVE-2022-2047 | jetty-http: improver hostname input handling |
| LOW | 2.4 | CVE-2023-26049 | jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies |
| LOW | 2.0 | CVE-2025-58056 | netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions |
| LOW | 2.0 | CVE-2025-66453 | Rhino is an open-source implementation of JavaScript written entirely ... |
| LOW | 2.0 | CVE-2026-14457 | openssl: RPK server signature algorithm selection can dereference a missing certificate |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| LOW | 2.0 | CVE-2026-47010 | openjdk: Enhance JPEG handling (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-47059 | openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-54874 | openssl: excessive memory use buffering DTLS records for a future epoch |
| LOW | 2.0 | CVE-2026-63073 | openssl: untrusted sender DN used as format string in CMP response validation |
| LOW | 2.0 | CVE-2026-63074 | openssl: CMP indefinite cache growth of ExtraCerts |
| LOW | 2.0 | CVE-2026-63075 | openssl: QUIC ACK-only packet retention can cause memory exhaustion |
| LOW | 2.0 | CVE-2026-75803 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ... |
↑2025.05.03
Severity Breakdown
| Severity | Count |
|---|---|
| HIGH | 44 |
| MEDIUM | 58 |
| LOW | 18 |
Details for version: 2025.05.03
CVE Details for Version: 2025.05.03
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| HIGH | 8.8 | CVE-2025-48734 | commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.2 | CVE-2025-49146 | pgjdbc: pgjdbc insecure authentication in channel binding |
| HIGH | 8.1 | CVE-2025-59250 | JDBC Driver for SQL Server has improper input validation issue |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-14456 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| HIGH | 8.0 | CVE-2026-26740 | giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-47063 | openjdk: Enhance Jar handling (Oracle CPU 2026-07) |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | CVE-2026-62574 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Orac ... |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.5 | CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2023-1370 | json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) |
| HIGH | 7.5 | CVE-2023-52428 | nimbus-jose-jwt: large JWE p2c header value causes Denial of Service |
| HIGH | 7.5 | CVE-2024-47072 | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-54428 | org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| HIGH | 7.2 | CVE-2024-13009 | jetty-server: Jetty: Gzip Request Body Buffer Corruption |
| MEDIUM | 7.5 | CVE-2025-27817 | org.apache.kafka: Kafka Client Arbitrary File Read SSRF |
| MEDIUM | 7.5 | CVE-2025-7962 | com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2016-5004 | xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2025-67735 | netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59903 | Netty is an asynchronous, event-driven network application framework. ... |
| MEDIUM | 6.5 | CVE-2026-59949 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ... |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 6.1 | CVE-2025-22227 | io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects |
| MEDIUM | 5.9 | CVE-2024-8184 | org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2023-2976 | guava: insecure temporary directory creation |
| MEDIUM | 5.5 | CVE-2025-4949 | org.eclipse.jgit: XXE vulnerability in Eclipse JGit |
| MEDIUM | 5.5 | CVE-2025-58057 | netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack |
| MEDIUM | 5.5 | CVE-2025-68161 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification |
| MEDIUM | 5.5 | CVE-2026-18798 | openssl: QUIC server may trigger double free when processing INITIAL packet |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-46917 | openjdk: Improve DTLS handshaking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-46968 | openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47021 | openjdk: Enhance XBM image support (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47027 | openjdk: Enhance Jar file processing (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-49844 | org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-60147 | openjdk: Improve certification checking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-63072 | openssl: heap buffer overflow in CMS key unwrapping |
| MEDIUM | 5.5 | CVE-2026-63076 | openssl: invalid pointer dereference in CMP server via crafted protectionAlg |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints |
| MEDIUM | 5.3 | CVE-2023-26048 | jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() |
| MEDIUM | 5.3 | CVE-2023-40167 | jetty: Improper validation of HTTP/1 content-length |
| MEDIUM | 5.3 | CVE-2024-9823 | org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter |
| MEDIUM | 5.3 | CVE-2025-31672 | org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-64607 | org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| MEDIUM | 3.7 | CVE-2024-6763 | org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority |
| LOW | 3.9 | GHSA-58qw-p7qm-5rvh | Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.5 | CVE-2023-36479 | jetty: Improper addition of quotation marks to user inputs in CgiServlet |
| LOW | 3.3 | CVE-2020-8908 | guava: local information disclosure via temporary directory created with unsafe permissions |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.7 | CVE-2022-2047 | jetty-http: improver hostname input handling |
| LOW | 2.4 | CVE-2023-26049 | jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies |
| LOW | 2.0 | CVE-2025-58056 | netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions |
| LOW | 2.0 | CVE-2025-66453 | Rhino is an open-source implementation of JavaScript written entirely ... |
| LOW | 2.0 | CVE-2026-14457 | openssl: RPK server signature algorithm selection can dereference a missing certificate |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| LOW | 2.0 | CVE-2026-47010 | openjdk: Enhance JPEG handling (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-47059 | openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-54874 | openssl: excessive memory use buffering DTLS records for a future epoch |
| LOW | 2.0 | CVE-2026-63073 | openssl: untrusted sender DN used as format string in CMP response validation |
| LOW | 2.0 | CVE-2026-63074 | openssl: CMP indefinite cache growth of ExtraCerts |
| LOW | 2.0 | CVE-2026-63075 | openssl: QUIC ACK-only packet retention can cause memory exhaustion |
| LOW | 2.0 | CVE-2026-75803 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ... |