Skip to Content

Putki Security Vulnerability Scans

Last Updated: 01 Sep 2026 00:44:20

Development

Severity Breakdown

SeverityCount
HIGH7
MEDIUM9

Details for version: Development

CVE Details for Version: Development

SeverityScoreCVE IDDescription
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-67721aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
MEDIUM6.5CVE-2016-5004xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip
MEDIUM6.5CVE-2026-54518jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-54516jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties
MEDIUM5.3CVE-2026-54517jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application

2026.06

Severity Breakdown

SeverityCount
HIGH20
MEDIUM31
LOW8

Details for version: 2026.06

CVE Details for Version: 2026.06

SeverityScoreCVE IDDescription
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-14456openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server
HIGH8.0CVE-2026-26740giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-47063openjdk: Enhance Jar handling (Oracle CPU 2026-07)
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0CVE-2026-62574Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Orac ...
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-54428org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
MEDIUM6.5CVE-2016-5004xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip
MEDIUM6.5CVE-2026-54518jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59903Netty is an asynchronous, event-driven network application framework. ...
MEDIUM6.5CVE-2026-59949yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2026-10051jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
MEDIUM5.5CVE-2026-18798openssl: QUIC server may trigger double free when processing INITIAL packet
MEDIUM5.5CVE-2026-46917openjdk: Improve DTLS handshaking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-46968openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47021openjdk: Enhance XBM image support (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47027openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-49844org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-60147openjdk: Improve certification checking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-63072openssl: heap buffer overflow in CMS key unwrapping
MEDIUM5.5CVE-2026-63076openssl: invalid pointer dereference in CMP server via crafted protectionAlg
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-54516jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties
MEDIUM5.3CVE-2026-54517jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application
MEDIUM5.3CVE-2026-64607org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-8384jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
LOW2.0CVE-2026-14457openssl: RPK server signature algorithm selection can dereference a missing certificate
LOW2.0CVE-2026-47010openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
LOW2.0CVE-2026-47059openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)
LOW2.0CVE-2026-54874openssl: excessive memory use buffering DTLS records for a future epoch
LOW2.0CVE-2026-63073openssl: untrusted sender DN used as format string in CMP response validation
LOW2.0CVE-2026-63074openssl: CMP indefinite cache growth of ExtraCerts
LOW2.0CVE-2026-63075openssl: QUIC ACK-only packet retention can cause memory exhaustion
LOW2.0CVE-2026-75803Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ...

2026.03.05

Severity Breakdown

SeverityCount
HIGH34
MEDIUM45
LOW11

Details for version: 2026.03.05

CVE Details for Version: 2026.03.05

SeverityScoreCVE IDDescription
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-14456openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server
HIGH8.0CVE-2026-26740giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-47063openjdk: Enhance Jar handling (Oracle CPU 2026-07)
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0CVE-2026-62574Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Orac ...
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2026-1605org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42577Netty is an asynchronous, event-driven network application framework. ...
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-54428org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2016-5004xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59903Netty is an asynchronous, event-driven network application framework. ...
MEDIUM6.5CVE-2026-59949yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...
MEDIUM5.9CVE-2026-28208com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2026-10051jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
MEDIUM5.5CVE-2026-18798openssl: QUIC server may trigger double free when processing INITIAL packet
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-46917openjdk: Improve DTLS handshaking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-46968openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47021openjdk: Enhance XBM image support (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47027openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-49844org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-60147openjdk: Improve certification checking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-63072openssl: heap buffer overflow in CMS key unwrapping
MEDIUM5.5CVE-2026-63076openssl: invalid pointer dereference in CMP server via crafted protectionAlg
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-64607org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names
MEDIUM5.3CVE-2026-8384jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.0CVE-2026-14457openssl: RPK server signature algorithm selection can dereference a missing certificate
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
LOW2.0CVE-2026-47010openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
LOW2.0CVE-2026-47059openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)
LOW2.0CVE-2026-54874openssl: excessive memory use buffering DTLS records for a future epoch
LOW2.0CVE-2026-63073openssl: untrusted sender DN used as format string in CMP response validation
LOW2.0CVE-2026-63074openssl: CMP indefinite cache growth of ExtraCerts
LOW2.0CVE-2026-63075openssl: QUIC ACK-only packet retention can cause memory exhaustion
LOW2.0CVE-2026-75803Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ...

2026.03.04

Severity Breakdown

SeverityCount
CRITICAL1
HIGH31
MEDIUM40
LOW4

Details for version: 2026.03.04

CVE Details for Version: 2026.03.04

SeverityScoreCVE IDDescription
CRITICAL9.8CVE-2026-47065CVE-2026-47065: Deserialization of Untrusted Data
HIGH8.8CVE-2025-69194CVE-2025-69194
HIGH8.7CVE-2026-10050CVE-2026-10050: Improper Handling of Alternate Encoding
HIGH8.7CVE-2026-33871CVE-2026-33871: Allocation of Resources Without Limits or Throttling
HIGH8.7CVE-2026-35554CVE-2026-35554: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
HIGH8.7CVE-2026-45674CVE-2026-45674: Insufficient Verification of Data Authenticity
HIGH8.7CVE-2026-47691CVE-2026-47691: Insufficient Verification of Data Authenticity
HIGH8.7CVE-2026-56745CVE-2026-56745: Uncontrolled Resource Consumption
HIGH8.7CVE-2026-59901CVE-2026-59901: Loop with Unreachable Exit Condition ('Infinite Loop')
HIGH8.7GHSA-r7wm-3cxj-wff9GHSA-r7wm-3cxj-wff9: Allocation of Resources Without Limits or Throttling
HIGH8.2CVE-2026-26740CVE-2026-26740
HIGH8.2CVE-2026-54291CVE-2026-54291: Not Failing Securely ('Failing Open')
HIGH8.1CVE-2026-44249CVE-2026-44249: Improper Access Control
HIGH8.1CVE-2026-54512CVE-2026-54512: Incomplete List of Disallowed Inputs
HIGH8.1CVE-2026-54513CVE-2026-54513: Incomplete List of Disallowed Inputs
HIGH7.8CVE-2026-62574CVE-2026-62574
HIGH7.5CVE-2022-41404CVE-2022-41404: Uncontrolled Resource Consumption
HIGH7.5CVE-2026-1605CVE-2026-1605: Uncontrolled Resource Consumption
HIGH7.5CVE-2026-33870CVE-2026-33870: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
HIGH7.5CVE-2026-42198CVE-2026-42198: Allocation of Resources Without Limits or Throttling
HIGH7.5CVE-2026-42577CVE-2026-42577: Missing Release of Resource after Effective Lifetime
HIGH7.5CVE-2026-42579CVE-2026-42579: Improper Input Validation
HIGH7.5CVE-2026-42583CVE-2026-42583: Uncontrolled Resource Consumption
HIGH7.5CVE-2026-42587CVE-2026-42587: Uncontrolled Resource Consumption
HIGH7.5CVE-2026-45416CVE-2026-45416: Allocation of Resources Without Limits or Throttling
HIGH7.5CVE-2026-47063CVE-2026-47063
HIGH7.5CVE-2026-50010CVE-2026-50010: Improper Verification of Cryptographic Signature
HIGH7.5CVE-2026-55831CVE-2026-55831: Uncontrolled Resource Consumption
HIGH7.5CVE-2026-55833CVE-2026-55833: Uncontrolled Resource Consumption
HIGH7.5CVE-2026-56819CVE-2026-56819: Uncontrolled Resource Consumption
HIGH7.4CVE-2026-2332CVE-2026-2332: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
HIGH7.3CVE-2026-42584CVE-2026-42584: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
MEDIUM6.9CVE-2026-10051CVE-2026-10051: Exposure of Sensitive Information to an Unauthorized Actor
MEDIUM6.9CVE-2026-34478CVE-2026-34478: Improper Output Neutralization for Logs
MEDIUM6.9CVE-2026-34480CVE-2026-34480: Improper Encoding or Escaping of Output
MEDIUM6.9CVE-2026-50560CVE-2026-50560: Allocation of Resources Without Limits or Throttling
MEDIUM6.9CVE-2026-59899CVE-2026-59899: Allocation of Resources Without Limits or Throttling
MEDIUM6.9CVE-2026-59900CVE-2026-59900: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
MEDIUM6.9GHSA-72hv-8253-57qqGHSA-72hv-8253-57qq: Allocation of Resources Without Limits or Throttling
MEDIUM6.8CVE-2026-45673CVE-2026-45673: Use of Insufficiently Random Values
MEDIUM6.5CVE-2016-5004CVE-2016-5004: Uncontrolled Resource Consumption
MEDIUM6.5CVE-2024-45993CVE-2024-45993
MEDIUM6.5CVE-2025-48924CVE-2025-48924: Uncontrolled Recursion
MEDIUM6.5CVE-2026-42580CVE-2026-42580: Integer Overflow or Wraparound
MEDIUM6.5CVE-2026-42585CVE-2026-42585: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
MEDIUM6.5CVE-2026-56746CVE-2026-56746: Improper Access Control
MEDIUM6.5CVE-2026-59888CVE-2026-59888: Improperly Controlled Modification of Dynamically-Determined Object Attributes
MEDIUM6.5CVE-2026-59949CVE-2026-59949: Out-of-bounds Read
MEDIUM6.5CVE-2026-60147CVE-2026-60147
MEDIUM6.3CVE-2026-34477CVE-2026-34477: Improper Validation of Certificate with Host Mismatch
MEDIUM6.3CVE-2026-59898CVE-2026-59898: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
MEDIUM5.9CVE-2026-28208CVE-2026-28208: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
MEDIUM5.9CVE-2026-41245CVE-2026-41245: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
MEDIUM5.8CVE-2026-42581CVE-2026-42581: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
MEDIUM5.7CVE-2026-59921CVE-2026-59921: Improper Neutralization of CRLF Sequences ('CRLF Injection')
MEDIUM5.3CVE-2026-33558CVE-2026-33558: Insertion of Sensitive Information into Log File
MEDIUM5.3CVE-2026-41417CVE-2026-41417: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
MEDIUM5.3CVE-2026-45292CVE-2026-45292: Allocation of Resources Without Limits or Throttling
MEDIUM5.3CVE-2026-46917CVE-2026-46917
MEDIUM5.3CVE-2026-47027CVE-2026-47027
MEDIUM5.3CVE-2026-47244CVE-2026-47244: Uncontrolled Resource Consumption
MEDIUM5.3CVE-2026-48043CVE-2026-48043: Uncontrolled Resource Consumption
MEDIUM5.3CVE-2026-50020CVE-2026-50020: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
MEDIUM5.3CVE-2026-54514CVE-2026-54514: Server-Side Request Forgery (SSRF)
MEDIUM5.3CVE-2026-54515CVE-2026-54515: Improperly Controlled Modification of Dynamically-Determined Object Attributes
MEDIUM5.3CVE-2026-6790CVE-2026-6790: Improper Input Validation
MEDIUM5.3CVE-2026-8384CVE-2026-8384: Use of Non-Canonical URL Paths for Authorization Decisions
MEDIUM5.3GHSA-mfg7-5gfp-c4w3GHSA-mfg7-5gfp-c4w3: Missing Release of Resource after Effective Lifetime
MEDIUM5.1CVE-2026-23868CVE-2026-23868
MEDIUM4.7CVE-2026-71497CVE-2026-71497: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
MEDIUM4.0CVE-2026-41254CVE-2026-41254
MEDIUM4.0CVE-2026-45536CVE-2026-45536: Exposure of Sensitive Information to an Unauthorized Actor
LOW3.7CVE-2025-11143CVE-2025-11143: Improper Input Validation
LOW3.7CVE-2026-47059CVE-2026-47059
LOW2.9CVE-2026-42578CVE-2026-42578: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
LOW1.9CVE-2026-3293CVE-2026-3293: Uncontrolled Resource Consumption

2025.08.03

Severity Breakdown

SeverityCount
HIGH44
MEDIUM58
LOW18

Details for version: 2025.08.03

CVE Details for Version: 2025.08.03

SeverityScoreCVE IDDescription
HIGH8.8CVE-2025-48734commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.2CVE-2025-49146pgjdbc: pgjdbc insecure authentication in channel binding
HIGH8.1CVE-2025-59250JDBC Driver for SQL Server has improper input validation issue
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-14456openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server
HIGH8.0CVE-2026-26740giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-47063openjdk: Enhance Jar handling (Oracle CPU 2026-07)
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0CVE-2026-62574Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Orac ...
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.5CVE-2021-31684json-smart: Denial of Service in JSONParserByteArray function
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2023-1370json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)
HIGH7.5CVE-2023-52428nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
HIGH7.5CVE-2024-47072com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-54428org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
HIGH7.2CVE-2024-13009jetty-server: Jetty: Gzip Request Body Buffer Corruption
MEDIUM7.5CVE-2025-27817org.apache.kafka: Kafka Client Arbitrary File Read SSRF
MEDIUM7.5CVE-2025-7962com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2016-5004xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2025-67735netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59903Netty is an asynchronous, event-driven network application framework. ...
MEDIUM6.5CVE-2026-59949yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM6.1CVE-2025-22227io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
MEDIUM5.9CVE-2024-8184org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2023-2976guava: insecure temporary directory creation
MEDIUM5.5CVE-2025-4949org.eclipse.jgit: XXE vulnerability in Eclipse JGit
MEDIUM5.5CVE-2025-58057netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
MEDIUM5.5CVE-2025-68161Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
MEDIUM5.5CVE-2026-18798openssl: QUIC server may trigger double free when processing INITIAL packet
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-46917openjdk: Improve DTLS handshaking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-46968openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47021openjdk: Enhance XBM image support (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47027openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-49844org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-60147openjdk: Improve certification checking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-63072openssl: heap buffer overflow in CMS key unwrapping
MEDIUM5.5CVE-2026-63076openssl: invalid pointer dereference in CMP server via crafted protectionAlg
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2021-34429jetty: crafted URIs allow bypassing security constraints
MEDIUM5.3CVE-2023-26048jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()
MEDIUM5.3CVE-2023-40167jetty: Improper validation of HTTP/1 content-length
MEDIUM5.3CVE-2024-9823org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
MEDIUM5.3CVE-2025-31672org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-64607org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
MEDIUM3.7CVE-2024-6763org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOW3.9GHSA-58qw-p7qm-5rvhEclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.5CVE-2023-36479jetty: Improper addition of quotation marks to user inputs in CgiServlet
LOW3.3CVE-2020-8908guava: local information disclosure via temporary directory created with unsafe permissions
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.7CVE-2022-2047jetty-http: improver hostname input handling
LOW2.4CVE-2023-26049jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies
LOW2.0CVE-2025-58056netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
LOW2.0CVE-2025-66453Rhino is an open-source implementation of JavaScript written entirely ...
LOW2.0CVE-2026-14457openssl: RPK server signature algorithm selection can dereference a missing certificate
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
LOW2.0CVE-2026-47010openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
LOW2.0CVE-2026-47059openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)
LOW2.0CVE-2026-54874openssl: excessive memory use buffering DTLS records for a future epoch
LOW2.0CVE-2026-63073openssl: untrusted sender DN used as format string in CMP response validation
LOW2.0CVE-2026-63074openssl: CMP indefinite cache growth of ExtraCerts
LOW2.0CVE-2026-63075openssl: QUIC ACK-only packet retention can cause memory exhaustion
LOW2.0CVE-2026-75803Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ...

2025.05.03

Severity Breakdown

SeverityCount
HIGH44
MEDIUM58
LOW18

Details for version: 2025.05.03

CVE Details for Version: 2025.05.03

SeverityScoreCVE IDDescription
HIGH8.8CVE-2025-48734commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.2CVE-2025-49146pgjdbc: pgjdbc insecure authentication in channel binding
HIGH8.1CVE-2025-59250JDBC Driver for SQL Server has improper input validation issue
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-14456openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server
HIGH8.0CVE-2026-26740giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-47063openjdk: Enhance Jar handling (Oracle CPU 2026-07)
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0CVE-2026-62574Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Orac ...
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.5CVE-2021-31684json-smart: Denial of Service in JSONParserByteArray function
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2023-1370json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)
HIGH7.5CVE-2023-52428nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
HIGH7.5CVE-2024-47072com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-54428org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
HIGH7.2CVE-2024-13009jetty-server: Jetty: Gzip Request Body Buffer Corruption
MEDIUM7.5CVE-2025-27817org.apache.kafka: Kafka Client Arbitrary File Read SSRF
MEDIUM7.5CVE-2025-7962com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2016-5004xmlrpc: DoS through decompression-bomb attack when Content-Encoding=gzip
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2025-67735netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59903Netty is an asynchronous, event-driven network application framework. ...
MEDIUM6.5CVE-2026-59949yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM6.1CVE-2025-22227io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
MEDIUM5.9CVE-2024-8184org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2023-2976guava: insecure temporary directory creation
MEDIUM5.5CVE-2025-4949org.eclipse.jgit: XXE vulnerability in Eclipse JGit
MEDIUM5.5CVE-2025-58057netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
MEDIUM5.5CVE-2025-68161Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
MEDIUM5.5CVE-2026-18798openssl: QUIC server may trigger double free when processing INITIAL packet
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-46917openjdk: Improve DTLS handshaking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-46968openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47021openjdk: Enhance XBM image support (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47027openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-49844org.apache.logging.log4j/log4j-api: Apache Log4j API: Malformed JSON output due to improper encoding of floating-point values
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-60147openjdk: Improve certification checking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-63072openssl: heap buffer overflow in CMS key unwrapping
MEDIUM5.5CVE-2026-63076openssl: invalid pointer dereference in CMP server via crafted protectionAlg
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2021-34429jetty: crafted URIs allow bypassing security constraints
MEDIUM5.3CVE-2023-26048jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()
MEDIUM5.3CVE-2023-40167jetty: Improper validation of HTTP/1 content-length
MEDIUM5.3CVE-2024-9823org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
MEDIUM5.3CVE-2025-31672org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-64607org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
MEDIUM3.7CVE-2024-6763org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOW3.9GHSA-58qw-p7qm-5rvhEclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.5CVE-2023-36479jetty: Improper addition of quotation marks to user inputs in CgiServlet
LOW3.3CVE-2020-8908guava: local information disclosure via temporary directory created with unsafe permissions
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.7CVE-2022-2047jetty-http: improver hostname input handling
LOW2.4CVE-2023-26049jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies
LOW2.0CVE-2025-58056netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
LOW2.0CVE-2025-66453Rhino is an open-source implementation of JavaScript written entirely ...
LOW2.0CVE-2026-14457openssl: RPK server signature algorithm selection can dereference a missing certificate
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
LOW2.0CVE-2026-47010openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
LOW2.0CVE-2026-47059openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)
LOW2.0CVE-2026-54874openssl: excessive memory use buffering DTLS records for a future epoch
LOW2.0CVE-2026-63073openssl: untrusted sender DN used as format string in CMP response validation
LOW2.0CVE-2026-63074openssl: CMP indefinite cache growth of ExtraCerts
LOW2.0CVE-2026-63075openssl: QUIC ACK-only packet retention can cause memory exhaustion
LOW2.0CVE-2026-75803Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ...