Skip to Content

Apache Hop Security Vulnerability Scans

Last Updated: 14 Aug 2026 00:49:18

Development

Severity Breakdown

SeverityCount
CRITICAL1
HIGH19
MEDIUM23
LOW2

Details for version: Development

CVE Details for Version: Development

SeverityScoreCVE IDDescription
CRITICAL9.1CVE-2023-44981zookeeper: Authorization Bypass in Apache ZooKeeper
HIGH8.2CVE-2022-46751apache-ivy: XML External Entity vulnerability
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-52999com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2025-67721aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-24308Apache ZooKeeper: Apache ZooKeeper: Information disclosure via improper handling of configuration values
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2026-40983micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests
HIGH7.5CVE-2026-40984micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-56740JLine is a Java library for handling console input. Prior to 3.30.14, ...
HIGH7.5CVE-2026-56741JLine is a Java library for handling console input. Prior to 3.30.14, ...
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.4CVE-2026-24281Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing
MEDIUM7.5CVE-2026-50193jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2026-54518jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM5.9CVE-2018-10237guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.5CVE-2023-2976guava: insecure temporary directory creation
MEDIUM5.5CVE-2026-34479org.apache.logging.log4j/log4j-1.2-api: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping
MEDIUM5.5CVE-2026-34481org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2024-23944Apache-ZooKeeper: Apache ZooKeeper: Information disclosure in persistent watcher handling
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-54516jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties
MEDIUM5.3CVE-2026-54517jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM4.0CVE-2025-49128com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocation
MEDIUM3.7CVE-2024-6763org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.3CVE-2020-8908guava: local information disclosure via temporary directory created with unsafe permissions

2.18.1

Severity Breakdown

SeverityCount
HIGH36
MEDIUM52
LOW2

Details for version: 2.18.1

CVE Details for Version: 2.18.1

SeverityScoreCVE IDDescription
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-11352curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability
HIGH8.0CVE-2026-11586curl: curl: Denial of Service via WebSocket PING flood
HIGH8.0CVE-2026-12064curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-47063openjdk: Enhance Jar handling (Oracle CPU 2026-07)
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-55851io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
HIGH8.0CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-56817io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0CVE-2026-8286curl: curl: Insecure connection establishment due to TLS configuration mismatch
HIGH8.0CVE-2026-8458curl: libcurl: Unauthorized connection reuse due to a logical error
HIGH8.0CVE-2026-8925curl: curl: Double-free vulnerability in SASL authentication
HIGH8.0CVE-2026-8927curl: Information disclosure due to uncleared proxy authentication state
HIGH8.0CVE-2026-9547curl: curl: Man-in-the-middle attack via SSH host key bypass
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2026-2100p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-44891io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56740JLine is a Java library for handling console input. Prior to 3.30.14, ...
HIGH7.5CVE-2026-56741JLine is a Java library for handling console input. Prior to 3.30.14, ...
HIGH7.5CVE-2026-56816Netty is a network application framework for development of protocol s ...
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.5CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
HIGH7.4CVE-2026-56820io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack
HIGH7.4CVE-2026-56821io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp
HIGH7.4CVE-2026-56822io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp
MEDIUM6.9CVE-2026-56132expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
MEDIUM6.9CVE-2026-56403libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
MEDIUM6.9CVE-2026-56404libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding
MEDIUM6.9CVE-2026-56405libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow
MEDIUM6.5CVE-2026-54518jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-56818io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59920io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.9CVE-2026-50219expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
MEDIUM5.9CVE-2026-56412libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2026-10051jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
MEDIUM5.5CVE-2026-10536libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service
MEDIUM5.5CVE-2026-11564libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse
MEDIUM5.5CVE-2026-11856curl: curl: Information disclosure via incorrect Digest authentication header reuse
MEDIUM5.5CVE-2026-46917openjdk: Improve DTLS handshaking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-46968openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47021openjdk: Enhance XBM image support (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47027openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-56131libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
MEDIUM5.5CVE-2026-56406libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
MEDIUM5.5CVE-2026-56407libexpat: libexpat: Arbitrary code execution due to integer overflow
MEDIUM5.5CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...
MEDIUM5.5CVE-2026-56410libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
MEDIUM5.5CVE-2026-56411expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-59919io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy
MEDIUM5.5CVE-2026-60147openjdk: Improve certification checking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-8924curl: curl: Cookie injection via malicious HTTP server using super cookies
MEDIUM5.5CVE-2026-8926curl: curl: Information disclosure via incorrect .netrc password lookup
MEDIUM5.5CVE-2026-8932libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
MEDIUM5.5CVE-2026-9079libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
MEDIUM5.5CVE-2026-9080libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback
MEDIUM5.5CVE-2026-9545libcurl: libcurl: Information disclosure via cached SSL session and early data
MEDIUM5.5CVE-2026-9546libcurl: libcurl: Information disclosure due to persistent Referer header
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-54516jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties
MEDIUM5.3CVE-2026-54517jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM5.3CVE-2026-8384jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
LOW2.0CVE-2026-47010openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
LOW2.0CVE-2026-47059openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)

2.18.0

Severity Breakdown

SeverityCount
HIGH47
MEDIUM59
LOW13

Details for version: 2.18.0

CVE Details for Version: 2.18.0

SeverityScoreCVE IDDescription
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-45447openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
HIGH8.0CVE-2026-47063openjdk: Enhance Jar handling (Oracle CPU 2026-07)
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-55851io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
HIGH8.0CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-56817io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2026-2100p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-44250netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays
HIGH7.5CVE-2026-44890netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads
HIGH7.5CVE-2026-44891io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder
HIGH7.5CVE-2026-44892Netty is a network application framework for development of protocol s ...
HIGH7.5CVE-2026-44893netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
HIGH7.5CVE-2026-44894netty-codec-classes-quic: Netty: Denial of Service amplification via improper QUIC token validation
HIGH7.5CVE-2026-45186libexpat: denial of service via crafted XML input
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-46340netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments
HIGH7.5CVE-2026-48006netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
HIGH7.5CVE-2026-48059netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
HIGH7.5CVE-2026-48748netty: Netty: Denial of Service due to memory exhaustion in HTTP/3 codec
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-50011netty-codec-redis: Netty: Denial of Service via malicious Redis array header
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56740JLine is a Java library for handling console input. Prior to 3.30.14, ...
HIGH7.5CVE-2026-56741JLine is a Java library for handling console input. Prior to 3.30.14, ...
HIGH7.5CVE-2026-56816Netty is a network application framework for development of protocol s ...
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.5CVE-2026-5773curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse
HIGH7.5CVE-2026-6276curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers
HIGH7.5CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
HIGH7.4CVE-2026-56820io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack
HIGH7.4CVE-2026-56821io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp
HIGH7.4CVE-2026-56822io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp
MEDIUM6.9CVE-2026-56132expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
MEDIUM6.9CVE-2026-56403libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
MEDIUM6.9CVE-2026-56404libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding
MEDIUM6.9CVE-2026-56405libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2026-54518jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass
MEDIUM6.5CVE-2026-5545curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-56818io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59920io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.9CVE-2026-50219expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
MEDIUM5.9CVE-2026-56412libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2026-10051jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
MEDIUM5.5CVE-2026-34182openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages
MEDIUM5.5CVE-2026-34183openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
MEDIUM5.5CVE-2026-42764openssl: NULL pointer dereference in QUIC server initial packet handling
MEDIUM5.5CVE-2026-45445openssl: AES-OCB IV Ignored on EVP_Cipher() Path
MEDIUM5.5CVE-2026-46917openjdk: Improve DTLS handshaking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-46968openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47021openjdk: Enhance XBM image support (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47027openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-4873curl: curl: Information disclosure due to incorrect TLS connection reuse
MEDIUM5.5CVE-2026-56131libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
MEDIUM5.5CVE-2026-56406libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
MEDIUM5.5CVE-2026-56407libexpat: libexpat: Arbitrary code execution due to integer overflow
MEDIUM5.5CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...
MEDIUM5.5CVE-2026-56410libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
MEDIUM5.5CVE-2026-56411expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-59919io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy
MEDIUM5.5CVE-2026-60147openjdk: Improve certification checking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-6253curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies
MEDIUM5.5CVE-2026-6429curl: libcurl: Credential leak via reused proxy connection during HTTP redirects
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-54516jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties
MEDIUM5.3CVE-2026-54517jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-7009curl: Curl: Certificate validation bypass due to OCSP stapling flaw
MEDIUM5.3CVE-2026-7168curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM5.3CVE-2026-8384jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications
MEDIUM4.8CVE-2026-50009Netty is a network application framework for development of protocol s ...
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
LOW2.0CVE-2026-34180openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.
LOW2.0CVE-2026-34181openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
LOW2.0CVE-2026-41080libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
LOW2.0CVE-2026-42766openssl: Possible NULL Dereference in Password-Based CMS Decryption
LOW2.0CVE-2026-42767openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption
LOW2.0CVE-2026-42768openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
LOW2.0CVE-2026-42769openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
LOW2.0CVE-2026-42770openssl: FFC-DH Peer Validation Uses Attacker-Supplied q
LOW2.0CVE-2026-45446openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
LOW2.0CVE-2026-47010openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
LOW2.0CVE-2026-47059openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)
LOW2.0CVE-2026-7383openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing
LOW2.0CVE-2026-9076openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption

2.17.0

Severity Breakdown

SeverityCount
CRITICAL10
HIGH72
MEDIUM88
LOW22

Details for version: 2.17.0

CVE Details for Version: 2.17.0

SeverityScoreCVE IDDescription
CRITICAL9.8CVE-2026-31789openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
CRITICAL9.8CVE-2026-41409Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix
CRITICAL9.8CVE-2026-41635Apache MINA: Apache MINA: Arbitrary code execution via classname allowlist bypass
CRITICAL9.8CVE-2026-42027Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
CRITICAL9.8CVE-2026-42778Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409)
CRITICAL9.8CVE-2026-42779Apache MINA: Apache MINA: Arbitrary Code Execution via Classname Allowlist Bypass
CRITICAL9.8CVE-2026-47065mina: mina: Arbitrary Code Execution via Deserialization Bypass
CRITICAL9.5CVE-2025-14813bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
CRITICAL9.1CVE-2026-40682org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing
CRITICAL8.1CVE-2026-8178Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.1CVE-2026-25646libpng: LIBPNG has a heap buffer overflow in png_set_quantize
HIGH8.1CVE-2026-28387openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-22016openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04)
HIGH8.0CVE-2026-27135nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-34282openjdk: Enhance TLS connection handling (Oracle CPU 2026-04)
HIGH8.0CVE-2026-40200musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
HIGH8.0CVE-2026-45447openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
HIGH8.0CVE-2026-47063openjdk: Enhance Jar handling (Oracle CPU 2026-07)
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-55851io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
HIGH8.0CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-56817io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.8CVE-2026-22184zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2026-1605org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests
HIGH7.5CVE-2026-2100p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
HIGH7.5CVE-2026-28388openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing
HIGH7.5CVE-2026-28389openssl: OpenSSL: Denial of Service vulnerability in CMS processing
HIGH7.5CVE-2026-28390openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42440org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files
HIGH7.5CVE-2026-42577Netty is an asynchronous, event-driven network application framework. ...
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42582netty: io.netty/netty-codec-http3: Netty: Denial of Service due to improper length validation in header block decoding
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-44250netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays
HIGH7.5CVE-2026-44890netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads
HIGH7.5CVE-2026-44891io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder
HIGH7.5CVE-2026-44892Netty is a network application framework for development of protocol s ...
HIGH7.5CVE-2026-44893netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
HIGH7.5CVE-2026-44894netty-codec-classes-quic: Netty: Denial of Service amplification via improper QUIC token validation
HIGH7.5CVE-2026-45186libexpat: denial of service via crafted XML input
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-46340netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments
HIGH7.5CVE-2026-48006netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
HIGH7.5CVE-2026-48059netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
HIGH7.5CVE-2026-48748netty: Netty: Denial of Service due to memory exhaustion in HTTP/3 codec
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-50011netty-codec-redis: Netty: Denial of Service via malicious Redis array header
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56740JLine is a Java library for handling console input. Prior to 3.30.14, ...
HIGH7.5CVE-2026-56741JLine is a Java library for handling console input. Prior to 3.30.14, ...
HIGH7.5CVE-2026-56816Netty is a network application framework for development of protocol s ...
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.5CVE-2026-5773curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse
HIGH7.5CVE-2026-6276curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers
HIGH7.5CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.4CVE-2026-56820io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack
HIGH7.4CVE-2026-56821io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp
HIGH7.4CVE-2026-56822io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
MEDIUM6.9CVE-2026-56132expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
MEDIUM6.9CVE-2026-56403libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
MEDIUM6.9CVE-2026-56404libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding
MEDIUM6.9CVE-2026-56405libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow
MEDIUM6.8CVE-2026-42586netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-5545curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-56818io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59920io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM5.9CVE-2026-28208com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.9CVE-2026-50219expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
MEDIUM5.9CVE-2026-56412libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2025-14017curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers
MEDIUM5.5CVE-2026-0636bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
MEDIUM5.5CVE-2026-10051jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
MEDIUM5.5CVE-2026-1965curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication
MEDIUM5.5CVE-2026-22013openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04)
MEDIUM5.5CVE-2026-22021openjdk: Enhance certificate chain validation (Oracle CPU 2026-04)
MEDIUM5.5CVE-2026-23865freetype: Information disclosure or denial of service via specially crafted font files
MEDIUM5.5CVE-2026-2673openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group
MEDIUM5.5CVE-2026-27171zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions
MEDIUM5.5CVE-2026-31790openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
MEDIUM5.5CVE-2026-32776libexpat: libexpat: Denial of Service due to NULL pointer dereference
MEDIUM5.5CVE-2026-32777libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
MEDIUM5.5CVE-2026-32778libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
MEDIUM5.5CVE-2026-33416libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
MEDIUM5.5CVE-2026-33636libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
MEDIUM5.5CVE-2026-34182openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages
MEDIUM5.5CVE-2026-34183openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-3783curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect
MEDIUM5.5CVE-2026-3784curl: curl: Unauthorized access due to improper HTTP proxy connection reuse
MEDIUM5.5CVE-2026-3805curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling
MEDIUM5.5CVE-2026-40930LIBPNG is a reference library for use in applications that process PNG ...
MEDIUM5.5CVE-2026-42764openssl: NULL pointer dereference in QUIC server initial packet handling
MEDIUM5.5CVE-2026-45445openssl: AES-OCB IV Ignored on EVP_Cipher() Path
MEDIUM5.5CVE-2026-46917openjdk: Improve DTLS handshaking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-46968openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47021openjdk: Enhance XBM image support (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-47027openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-4873curl: curl: Information disclosure due to incorrect TLS connection reuse
MEDIUM5.5CVE-2026-56131libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
MEDIUM5.5CVE-2026-56406libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
MEDIUM5.5CVE-2026-56407libexpat: libexpat: Arbitrary code execution due to integer overflow
MEDIUM5.5CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...
MEDIUM5.5CVE-2026-56410libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
MEDIUM5.5CVE-2026-56411expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-59919io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy
MEDIUM5.5CVE-2026-60147openjdk: Improve certification checking (Oracle CPU 2026-07)
MEDIUM5.5CVE-2026-6042musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv
MEDIUM5.5CVE-2026-6253curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies
MEDIUM5.5CVE-2026-6429curl: libcurl: Credential leak via reused proxy connection during HTTP redirects
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-44248netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-7009curl: Curl: Certificate validation bypass due to OCSP stapling flaw
MEDIUM5.3CVE-2026-7168curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM5.3CVE-2026-8384jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications
MEDIUM4.8CVE-2026-50009Netty is a network application framework for development of protocol s ...
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
MEDIUM4.4CVE-2026-34757libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.0CVE-2025-14524curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token
LOW2.0CVE-2025-14819curl: libcurl: Improper certificate validation due to cached TLS settings reuse
LOW2.0CVE-2026-22007openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04)
LOW2.0CVE-2026-22018openjdk: Enhance Zip file reading (Oracle CPU 2026-04)
LOW2.0CVE-2026-32588Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
LOW2.0CVE-2026-34180openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.
LOW2.0CVE-2026-34181openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
LOW2.0CVE-2026-34268openjdk: Enhance key generation (Oracle CPU 2026-04)
LOW2.0CVE-2026-41080libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
LOW2.0CVE-2026-42766openssl: Possible NULL Dereference in Password-Based CMS Decryption
LOW2.0CVE-2026-42767openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption
LOW2.0CVE-2026-42768openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
LOW2.0CVE-2026-42769openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
LOW2.0CVE-2026-42770openssl: FFC-DH Peer Validation Uses Attacker-Supplied q
LOW2.0CVE-2026-45446openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
LOW2.0CVE-2026-47010openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
LOW2.0CVE-2026-47059openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)
LOW2.0CVE-2026-7383openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing
LOW2.0CVE-2026-9076openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption

2.16.0

Severity Breakdown

SeverityCount
CRITICAL10
HIGH88
MEDIUM89
LOW32

Details for version: 2.16.0

CVE Details for Version: 2.16.0

SeverityScoreCVE IDDescription
CRITICAL9.8CVE-2026-31789openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
CRITICAL9.8CVE-2026-41409Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix
CRITICAL9.8CVE-2026-41635Apache MINA: Apache MINA: Arbitrary code execution via classname allowlist bypass
CRITICAL9.8CVE-2026-42027Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
CRITICAL9.8CVE-2026-42778Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409)
CRITICAL9.8CVE-2026-42779Apache MINA: Apache MINA: Arbitrary Code Execution via Classname Allowlist Bypass
CRITICAL9.8CVE-2026-47065mina: mina: Arbitrary Code Execution via Deserialization Bypass
CRITICAL9.5CVE-2025-14813bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
CRITICAL9.1CVE-2026-40682org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing
CRITICAL8.1CVE-2026-8178Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.1CVE-2025-59250JDBC Driver for SQL Server has improper input validation issue
HIGH8.1CVE-2026-25646libpng: LIBPNG has a heap buffer overflow in png_set_quantize
HIGH8.1CVE-2026-28387openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-15467openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
HIGH8.0CVE-2025-64720libpng: LIBPNG buffer overflow
HIGH8.0CVE-2025-65018libpng: LIBPNG heap buffer overflow
HIGH8.0CVE-2025-66293libpng: LIBPNG out-of-bounds read in png_image_read_composite
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-21932openjdk: Enhance Handling of URIs (Oracle CPU 2026-01)
HIGH8.0CVE-2026-21945openjdk: Enhance Certificate Checking (Oracle CPU 2026-01)
HIGH8.0CVE-2026-22016openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04)
HIGH8.0CVE-2026-27135nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-34282openjdk: Enhance TLS connection handling (Oracle CPU 2026-04)
HIGH8.0CVE-2026-40200musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
HIGH8.0CVE-2026-45447openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-55851io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
HIGH8.0CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-56817io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.8CVE-2026-22184zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility
HIGH7.8CVE-2026-22801libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
HIGH7.8CVE-2026-25210libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
HIGH7.5CVE-2021-31684json-smart: Denial of Service in JSONParserByteArray function
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2023-1370json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)
HIGH7.5CVE-2023-28118kaml has potential denial of service while parsing input with anchors and aliases
HIGH7.5CVE-2023-52428nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
HIGH7.5CVE-2024-21634ion-java: ion-java: Ion Java StackOverflow vulnerability
HIGH7.5CVE-2024-47072com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
HIGH7.5CVE-2025-41249org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2025-69421openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing
HIGH7.5CVE-2026-1605org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests
HIGH7.5CVE-2026-2100p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
HIGH7.5CVE-2026-28388openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing
HIGH7.5CVE-2026-28389openssl: OpenSSL: Denial of Service vulnerability in CMS processing
HIGH7.5CVE-2026-28390openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-41849spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
HIGH7.5CVE-2026-41850spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42440org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files
HIGH7.5CVE-2026-42577Netty is an asynchronous, event-driven network application framework. ...
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42582netty: io.netty/netty-codec-http3: Netty: Denial of Service due to improper length validation in header block decoding
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-44250netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays
HIGH7.5CVE-2026-44890netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads
HIGH7.5CVE-2026-44891io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder
HIGH7.5CVE-2026-44892Netty is a network application framework for development of protocol s ...
HIGH7.5CVE-2026-44893netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
HIGH7.5CVE-2026-44894netty-codec-classes-quic: Netty: Denial of Service amplification via improper QUIC token validation
HIGH7.5CVE-2026-45186libexpat: denial of service via crafted XML input
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-46340netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments
HIGH7.5CVE-2026-48006netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
HIGH7.5CVE-2026-48059netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
HIGH7.5CVE-2026-48748netty: Netty: Denial of Service due to memory exhaustion in HTTP/3 codec
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-50011netty-codec-redis: Netty: Denial of Service via malicious Redis array header
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56816Netty is a network application framework for development of protocol s ...
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.5CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.4CVE-2026-56820io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack
HIGH7.4CVE-2026-56821io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp
HIGH7.4CVE-2026-56822io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
HIGH7.1CVE-2026-22695libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
MEDIUM6.9CVE-2026-56132expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
MEDIUM6.9CVE-2026-56403libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
MEDIUM6.9CVE-2026-56404libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding
MEDIUM6.9CVE-2026-56405libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow
MEDIUM6.8CVE-2026-42586netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2025-67735netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-5545curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-56818io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59920io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM5.9CVE-2026-28208com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.9CVE-2026-50219expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
MEDIUM5.9CVE-2026-56412libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2024-35255azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity
MEDIUM5.5CVE-2024-58251In netstat in BusyBox through 1.37.0, local users can launch of networ ...
MEDIUM5.5CVE-2025-11187openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file
MEDIUM5.5CVE-2025-62408c-ares: c-ares: Denial of Service due to query termination after maximum attempts
MEDIUM5.5CVE-2025-64505libpng: LIBPNG heap buffer overflow via malformed palette index
MEDIUM5.5CVE-2025-64506libpng: LIBPNG heap buffer over-read
MEDIUM5.5CVE-2025-68161Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
MEDIUM5.5CVE-2025-69419openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
MEDIUM5.5CVE-2026-0636bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
MEDIUM5.5CVE-2026-10051jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections
MEDIUM5.5CVE-2026-21925openjdk: Improve JMX connections (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-21933openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-22013openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04)
MEDIUM5.5CVE-2026-22021openjdk: Enhance certificate chain validation (Oracle CPU 2026-04)
MEDIUM5.5CVE-2026-23865freetype: Information disclosure or denial of service via specially crafted font files
MEDIUM5.5CVE-2026-2673openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group
MEDIUM5.5CVE-2026-27171zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions
MEDIUM5.5CVE-2026-31790openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
MEDIUM5.5CVE-2026-32776libexpat: libexpat: Denial of Service due to NULL pointer dereference
MEDIUM5.5CVE-2026-32777libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
MEDIUM5.5CVE-2026-32778libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
MEDIUM5.5CVE-2026-33416libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
MEDIUM5.5CVE-2026-33636libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
MEDIUM5.5CVE-2026-34182openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages
MEDIUM5.5CVE-2026-34183openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-42764openssl: NULL pointer dereference in QUIC server initial packet handling
MEDIUM5.5CVE-2026-45445openssl: AES-OCB IV Ignored on EVP_Cipher() Path
MEDIUM5.5CVE-2026-56131libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
MEDIUM5.5CVE-2026-56406libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
MEDIUM5.5CVE-2026-56407libexpat: libexpat: Arbitrary code execution due to integer overflow
MEDIUM5.5CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...
MEDIUM5.5CVE-2026-56410libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
MEDIUM5.5CVE-2026-56411expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-59919io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy
MEDIUM5.5CVE-2026-6042musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-41851Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation
MEDIUM5.3CVE-2026-44248netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM5.3CVE-2026-8384jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications
MEDIUM4.8CVE-2026-50009Netty is a network application framework for development of protocol s ...
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
MEDIUM4.4CVE-2026-34757libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability
MEDIUM4.3CVE-2021-39194Improper Handling of Missing Values in kaml
MEDIUM4.3CVE-2024-38808spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.7CVE-2026-41848spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher
LOW3.7CVE-2026-41852spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation
LOW3.3CVE-2025-46394In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.5CVE-2026-24515libexpat: libexpat null pointer dereference
LOW2.0CVE-2025-13151libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
LOW2.0CVE-2025-15468openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling
LOW2.0CVE-2025-15469openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation
LOW2.0CVE-2025-66199openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
LOW2.0CVE-2025-66453Rhino is an open-source implementation of JavaScript written entirely ...
LOW2.0CVE-2025-68160openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter
LOW2.0CVE-2025-69418openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
LOW2.0CVE-2025-69420openssl: OpenSSL: Denial of Service via malformed TimeStamp Response
LOW2.0CVE-2026-22007openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04)
LOW2.0CVE-2026-22018openjdk: Enhance Zip file reading (Oracle CPU 2026-04)
LOW2.0CVE-2026-22795openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing
LOW2.0CVE-2026-22796openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification
LOW2.0CVE-2026-32588Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
LOW2.0CVE-2026-34180openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.
LOW2.0CVE-2026-34181openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
LOW2.0CVE-2026-34268openjdk: Enhance key generation (Oracle CPU 2026-04)
LOW2.0CVE-2026-41080libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
LOW2.0CVE-2026-42766openssl: Possible NULL Dereference in Password-Based CMS Decryption
LOW2.0CVE-2026-42767openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption
LOW2.0CVE-2026-42768openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
LOW2.0CVE-2026-42769openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
LOW2.0CVE-2026-42770openssl: FFC-DH Peer Validation Uses Attacker-Supplied q
LOW2.0CVE-2026-45446openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
LOW2.0CVE-2026-7383openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing
LOW2.0CVE-2026-9076openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption

2.15.0

Severity Breakdown

SeverityCount
CRITICAL8
HIGH85
MEDIUM100
LOW39

Details for version: 2.15.0

CVE Details for Version: 2.15.0

SeverityScoreCVE IDDescription
CRITICAL9.8CVE-2025-54988org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
CRITICAL9.8CVE-2026-31789openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
CRITICAL9.8CVE-2026-42027Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
CRITICAL9.5CVE-2025-14813bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
CRITICAL9.5CVE-2025-66516tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
CRITICAL9.1CVE-2025-58050pcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS
CRITICAL9.1CVE-2026-40682org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing
CRITICAL8.1CVE-2026-8178Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
HIGH8.8CVE-2025-48734commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.1CVE-2025-59250JDBC Driver for SQL Server has improper input validation issue
HIGH8.1CVE-2026-25646libpng: LIBPNG has a heap buffer overflow in png_set_quantize
HIGH8.1CVE-2026-28387openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-15467openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
HIGH8.0CVE-2025-59375firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
HIGH8.0CVE-2025-59419io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection
HIGH8.0CVE-2025-64720libpng: LIBPNG buffer overflow
HIGH8.0CVE-2025-65018libpng: LIBPNG heap buffer overflow
HIGH8.0CVE-2025-66293libpng: LIBPNG out-of-bounds read in png_image_read_composite
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-21932openjdk: Enhance Handling of URIs (Oracle CPU 2026-01)
HIGH8.0CVE-2026-21945openjdk: Enhance Certificate Checking (Oracle CPU 2026-01)
HIGH8.0CVE-2026-22016openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04)
HIGH8.0CVE-2026-27135nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-34282openjdk: Enhance TLS connection handling (Oracle CPU 2026-04)
HIGH8.0CVE-2026-40200musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
HIGH8.0CVE-2026-45447openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-55851io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
HIGH8.0CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-56817io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.8CVE-2026-22184zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility
HIGH7.8CVE-2026-22801libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
HIGH7.8CVE-2026-25210libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
HIGH7.5CVE-2021-31684json-smart: Denial of Service in JSONParserByteArray function
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2023-1370json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)
HIGH7.5CVE-2023-28118kaml has potential denial of service while parsing input with anchors and aliases
HIGH7.5CVE-2023-52428nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
HIGH7.5CVE-2024-21634ion-java: ion-java: Ion Java StackOverflow vulnerability
HIGH7.5CVE-2024-47072com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
HIGH7.5CVE-2025-41249org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2025-69421openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing
HIGH7.5CVE-2026-2100p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
HIGH7.5CVE-2026-28388openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing
HIGH7.5CVE-2026-28389openssl: OpenSSL: Denial of Service vulnerability in CMS processing
HIGH7.5CVE-2026-28390openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-41849spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
HIGH7.5CVE-2026-41850spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42440org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-44250netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays
HIGH7.5CVE-2026-44890netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads
HIGH7.5CVE-2026-44891io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder
HIGH7.5CVE-2026-44893netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
HIGH7.5CVE-2026-45186libexpat: denial of service via crafted XML input
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-46340netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments
HIGH7.5CVE-2026-48006netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
HIGH7.5CVE-2026-48059netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-50011netty-codec-redis: Netty: Denial of Service via malicious Redis array header
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.5CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.4CVE-2026-56820io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack
HIGH7.4CVE-2026-56821io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp
HIGH7.4CVE-2026-56822io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
HIGH7.2CVE-2024-13009jetty-server: Jetty: Gzip Request Body Buffer Corruption
HIGH7.1CVE-2026-22695libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
MEDIUM7.5CVE-2025-7962com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability
MEDIUM6.9CVE-2026-56132expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
MEDIUM6.9CVE-2026-56403libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
MEDIUM6.9CVE-2026-56404libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding
MEDIUM6.9CVE-2026-56405libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow
MEDIUM6.8CVE-2026-42586netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2025-67735netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-5545curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-56818io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59920io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM5.9CVE-2024-8184org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
MEDIUM5.9CVE-2026-28208com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.9CVE-2026-50219expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
MEDIUM5.9CVE-2026-56412libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2024-35255azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity
MEDIUM5.5CVE-2024-58251In netstat in BusyBox through 1.37.0, local users can launch of networ ...
MEDIUM5.5CVE-2025-11187openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file
MEDIUM5.5CVE-2025-53057openjdk: Enhance certificate handling (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-53066openjdk: Enhance Path Factories (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-58057netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
MEDIUM5.5CVE-2025-62408c-ares: c-ares: Denial of Service due to query termination after maximum attempts
MEDIUM5.5CVE-2025-64505libpng: LIBPNG heap buffer overflow via malformed palette index
MEDIUM5.5CVE-2025-64506libpng: LIBPNG heap buffer over-read
MEDIUM5.5CVE-2025-68161Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
MEDIUM5.5CVE-2025-69419openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
MEDIUM5.5CVE-2025-9086curl: libcurl: Curl out of bounds read for cookie path
MEDIUM5.5CVE-2025-9230openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
MEDIUM5.5CVE-2025-9231openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
MEDIUM5.5CVE-2026-0636bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
MEDIUM5.5CVE-2026-21925openjdk: Improve JMX connections (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-21933openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-22013openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04)
MEDIUM5.5CVE-2026-22021openjdk: Enhance certificate chain validation (Oracle CPU 2026-04)
MEDIUM5.5CVE-2026-23865freetype: Information disclosure or denial of service via specially crafted font files
MEDIUM5.5CVE-2026-2673openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group
MEDIUM5.5CVE-2026-27171zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions
MEDIUM5.5CVE-2026-31790openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
MEDIUM5.5CVE-2026-32776libexpat: libexpat: Denial of Service due to NULL pointer dereference
MEDIUM5.5CVE-2026-32777libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
MEDIUM5.5CVE-2026-32778libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
MEDIUM5.5CVE-2026-33416libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
MEDIUM5.5CVE-2026-33636libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
MEDIUM5.5CVE-2026-34182openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages
MEDIUM5.5CVE-2026-34183openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-42764openssl: NULL pointer dereference in QUIC server initial packet handling
MEDIUM5.5CVE-2026-45445openssl: AES-OCB IV Ignored on EVP_Cipher() Path
MEDIUM5.5CVE-2026-56131libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
MEDIUM5.5CVE-2026-56406libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
MEDIUM5.5CVE-2026-56407libexpat: libexpat: Arbitrary code execution due to integer overflow
MEDIUM5.5CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...
MEDIUM5.5CVE-2026-56410libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
MEDIUM5.5CVE-2026-56411expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-59919io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy
MEDIUM5.5CVE-2026-6042musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2021-34429jetty: crafted URIs allow bypassing security constraints
MEDIUM5.3CVE-2023-26048jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()
MEDIUM5.3CVE-2023-40167jetty: Improper validation of HTTP/1 content-length
MEDIUM5.3CVE-2024-9823org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
MEDIUM5.3CVE-2025-31672org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-41851Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation
MEDIUM5.3CVE-2026-44248netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
MEDIUM4.4CVE-2026-34757libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability
MEDIUM4.3CVE-2021-39194Improper Handling of Missing Values in kaml
MEDIUM4.3CVE-2024-38808spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
MEDIUM3.7CVE-2024-6763org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOW3.9GHSA-58qw-p7qm-5rvhEclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.7CVE-2026-41848spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher
LOW3.7CVE-2026-41852spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation
LOW3.5CVE-2023-36479jetty: Improper addition of quotation marks to user inputs in CgiServlet
LOW3.3CVE-2025-46394In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.7CVE-2022-2047jetty-http: improver hostname input handling
LOW2.5CVE-2026-24515libexpat: libexpat null pointer dereference
LOW2.4CVE-2023-26049jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies
LOW2.0CVE-2025-10148curl: predictable WebSocket mask
LOW2.0CVE-2025-13151libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
LOW2.0CVE-2025-15468openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling
LOW2.0CVE-2025-15469openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation
LOW2.0CVE-2025-58056netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
LOW2.0CVE-2025-66199openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
LOW2.0CVE-2025-66453Rhino is an open-source implementation of JavaScript written entirely ...
LOW2.0CVE-2025-68160openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter
LOW2.0CVE-2025-69418openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
LOW2.0CVE-2025-69420openssl: OpenSSL: Denial of Service via malformed TimeStamp Response
LOW2.0CVE-2025-9232openssl: Out-of-bounds read in HTTP client no_proxy handling
LOW2.0CVE-2026-22007openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04)
LOW2.0CVE-2026-22018openjdk: Enhance Zip file reading (Oracle CPU 2026-04)
LOW2.0CVE-2026-22795openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing
LOW2.0CVE-2026-22796openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification
LOW2.0CVE-2026-32588Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
LOW2.0CVE-2026-34180openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.
LOW2.0CVE-2026-34181openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
LOW2.0CVE-2026-34268openjdk: Enhance key generation (Oracle CPU 2026-04)
LOW2.0CVE-2026-41080libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
LOW2.0CVE-2026-42766openssl: Possible NULL Dereference in Password-Based CMS Decryption
LOW2.0CVE-2026-42767openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption
LOW2.0CVE-2026-42768openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
LOW2.0CVE-2026-42769openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
LOW2.0CVE-2026-42770openssl: FFC-DH Peer Validation Uses Attacker-Supplied q
LOW2.0CVE-2026-45446openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
LOW2.0CVE-2026-7383openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing
LOW2.0CVE-2026-9076openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption

2.14.0

Severity Breakdown

SeverityCount
CRITICAL7
HIGH86
MEDIUM98
LOW26

Details for version: 2.14.0

CVE Details for Version: 2.14.0

SeverityScoreCVE IDDescription
CRITICAL9.8CVE-2025-54988org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
CRITICAL9.8CVE-2026-31789openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
CRITICAL9.8CVE-2026-42027Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
CRITICAL9.5CVE-2025-14813bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
CRITICAL9.5CVE-2025-66516tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
CRITICAL9.1CVE-2026-40682org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing
CRITICAL8.1CVE-2026-8178Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
HIGH8.8CVE-2025-48734commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.2CVE-2025-49146pgjdbc: pgjdbc insecure authentication in channel binding
HIGH8.1CVE-2025-59250JDBC Driver for SQL Server has improper input validation issue
HIGH8.1CVE-2026-25646libpng: LIBPNG has a heap buffer overflow in png_set_quantize
HIGH8.1CVE-2026-28387openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-15467openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
HIGH8.0CVE-2025-30749openjdk: Better Glyph drawing (Oracle CPU 2025-07)
HIGH8.0CVE-2025-50059openjdk: Improve HTTP client header handling (Oracle CPU 2025-07)
HIGH8.0CVE-2025-50106openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07)
HIGH8.0CVE-2025-59375firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
HIGH8.0CVE-2025-59419io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection
HIGH8.0CVE-2025-64720libpng: LIBPNG buffer overflow
HIGH8.0CVE-2025-65018libpng: LIBPNG heap buffer overflow
HIGH8.0CVE-2025-66293libpng: LIBPNG out-of-bounds read in png_image_read_composite
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-21932openjdk: Enhance Handling of URIs (Oracle CPU 2026-01)
HIGH8.0CVE-2026-21945openjdk: Enhance Certificate Checking (Oracle CPU 2026-01)
HIGH8.0CVE-2026-27135nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-40200musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-55851io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
HIGH8.0CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-56817io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.8CVE-2026-22184zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility
HIGH7.8CVE-2026-22801libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
HIGH7.8CVE-2026-25210libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
HIGH7.5CVE-2021-31684json-smart: Denial of Service in JSONParserByteArray function
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2023-1370json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)
HIGH7.5CVE-2023-28118kaml has potential denial of service while parsing input with anchors and aliases
HIGH7.5CVE-2023-52428nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
HIGH7.5CVE-2024-21634ion-java: ion-java: Ion Java StackOverflow vulnerability
HIGH7.5CVE-2024-47072com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
HIGH7.5CVE-2025-41249org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2025-69421openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing
HIGH7.5CVE-2026-2100p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
HIGH7.5CVE-2026-28388openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing
HIGH7.5CVE-2026-28389openssl: OpenSSL: Denial of Service vulnerability in CMS processing
HIGH7.5CVE-2026-28390openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-41849spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
HIGH7.5CVE-2026-41850spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42440org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-44250netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays
HIGH7.5CVE-2026-44890netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads
HIGH7.5CVE-2026-44891io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder
HIGH7.5CVE-2026-44893netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
HIGH7.5CVE-2026-45186libexpat: denial of service via crafted XML input
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-46340netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments
HIGH7.5CVE-2026-48006netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
HIGH7.5CVE-2026-48059netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-50011netty-codec-redis: Netty: Denial of Service via malicious Redis array header
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.5CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.4CVE-2026-56820io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack
HIGH7.4CVE-2026-56821io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp
HIGH7.4CVE-2026-56822io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
HIGH7.2CVE-2024-13009jetty-server: Jetty: Gzip Request Body Buffer Corruption
HIGH7.1CVE-2026-22695libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
MEDIUM7.5CVE-2025-27817org.apache.kafka: Kafka Client Arbitrary File Read SSRF
MEDIUM7.5CVE-2025-7962com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability
MEDIUM6.9CVE-2026-56132expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
MEDIUM6.9CVE-2026-56403libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
MEDIUM6.9CVE-2026-56404libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding
MEDIUM6.9CVE-2026-56405libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow
MEDIUM6.8CVE-2026-42586netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2025-67735netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-56818io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59920io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM6.1CVE-2025-22227io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
MEDIUM5.9CVE-2024-8184org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
MEDIUM5.9CVE-2026-28208com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.9CVE-2026-50219expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
MEDIUM5.9CVE-2026-56412libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2023-2976guava: insecure temporary directory creation
MEDIUM5.5CVE-2024-35255azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity
MEDIUM5.5CVE-2024-58251In netstat in BusyBox through 1.37.0, local users can launch of networ ...
MEDIUM5.5CVE-2025-30754openjdk: Enhance TLS protocol support (Oracle CPU 2025-07)
MEDIUM5.5CVE-2025-4947libcurl: curl: QUIC certificate check skip with wolfSSL
MEDIUM5.5CVE-2025-4949org.eclipse.jgit: XXE vulnerability in Eclipse JGit
MEDIUM5.5CVE-2025-5025curl: libcurl: QUIC Certificate Pinning Bypass
MEDIUM5.5CVE-2025-53057openjdk: Enhance certificate handling (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-53066openjdk: Enhance Path Factories (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-5399curl: libcurl: WebSocket endless loop
MEDIUM5.5CVE-2025-58057netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
MEDIUM5.5CVE-2025-62408c-ares: c-ares: Denial of Service due to query termination after maximum attempts
MEDIUM5.5CVE-2025-64505libpng: LIBPNG heap buffer overflow via malformed palette index
MEDIUM5.5CVE-2025-64506libpng: LIBPNG heap buffer over-read
MEDIUM5.5CVE-2025-68161Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
MEDIUM5.5CVE-2025-69419openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
MEDIUM5.5CVE-2025-9086curl: libcurl: Curl out of bounds read for cookie path
MEDIUM5.5CVE-2025-9230openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
MEDIUM5.5CVE-2025-9231openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
MEDIUM5.5CVE-2026-0636bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
MEDIUM5.5CVE-2026-21925openjdk: Improve JMX connections (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-21933openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-27171zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions
MEDIUM5.5CVE-2026-31790openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
MEDIUM5.5CVE-2026-32776libexpat: libexpat: Denial of Service due to NULL pointer dereference
MEDIUM5.5CVE-2026-32777libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
MEDIUM5.5CVE-2026-32778libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
MEDIUM5.5CVE-2026-33416libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
MEDIUM5.5CVE-2026-33636libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-56131libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
MEDIUM5.5CVE-2026-56406libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
MEDIUM5.5CVE-2026-56407libexpat: libexpat: Arbitrary code execution due to integer overflow
MEDIUM5.5CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...
MEDIUM5.5CVE-2026-56410libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
MEDIUM5.5CVE-2026-56411expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-59919io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy
MEDIUM5.5CVE-2026-6042musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2021-34429jetty: crafted URIs allow bypassing security constraints
MEDIUM5.3CVE-2023-26048jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()
MEDIUM5.3CVE-2023-40167jetty: Improper validation of HTTP/1 content-length
MEDIUM5.3CVE-2024-9823org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
MEDIUM5.3CVE-2025-31672org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-41851Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation
MEDIUM5.3CVE-2026-44248netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
MEDIUM4.4CVE-2026-34757libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability
MEDIUM4.3CVE-2021-39194Improper Handling of Missing Values in kaml
MEDIUM4.3CVE-2024-38808spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
MEDIUM3.7CVE-2024-6763org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOW3.9GHSA-58qw-p7qm-5rvhEclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.7CVE-2026-41848spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher
LOW3.7CVE-2026-41852spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation
LOW3.5CVE-2023-36479jetty: Improper addition of quotation marks to user inputs in CgiServlet
LOW3.3CVE-2020-8908guava: local information disclosure via temporary directory created with unsafe permissions
LOW3.3CVE-2025-46394In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.7CVE-2022-2047jetty-http: improver hostname input handling
LOW2.5CVE-2026-24515libexpat: libexpat null pointer dereference
LOW2.4CVE-2023-26049jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies
LOW2.0CVE-2025-10148curl: predictable WebSocket mask
LOW2.0CVE-2025-13151libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
LOW2.0CVE-2025-15468openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling
LOW2.0CVE-2025-58056netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
LOW2.0CVE-2025-66199openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
LOW2.0CVE-2025-66453Rhino is an open-source implementation of JavaScript written entirely ...
LOW2.0CVE-2025-68160openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter
LOW2.0CVE-2025-69418openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
LOW2.0CVE-2025-69420openssl: OpenSSL: Denial of Service via malformed TimeStamp Response
LOW2.0CVE-2025-9232openssl: Out-of-bounds read in HTTP client no_proxy handling
LOW2.0CVE-2026-22795openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing
LOW2.0CVE-2026-22796openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification
LOW2.0CVE-2026-32588Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
LOW2.0CVE-2026-41080libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

2.13.0

Severity Breakdown

SeverityCount
CRITICAL7
HIGH87
MEDIUM98
LOW26

Details for version: 2.13.0

CVE Details for Version: 2.13.0

SeverityScoreCVE IDDescription
CRITICAL9.8CVE-2025-54988org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
CRITICAL9.8CVE-2026-31789openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
CRITICAL9.8CVE-2026-42027Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
CRITICAL9.5CVE-2025-14813bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly
CRITICAL9.5CVE-2025-66516tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
CRITICAL9.1CVE-2026-40682org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing
CRITICAL8.1CVE-2026-8178Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
HIGH8.8CVE-2025-48734commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.2CVE-2025-49146pgjdbc: pgjdbc insecure authentication in channel binding
HIGH8.1CVE-2025-59250JDBC Driver for SQL Server has improper input validation issue
HIGH8.1CVE-2026-25646libpng: LIBPNG has a heap buffer overflow in png_set_quantize
HIGH8.1CVE-2026-28387openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-15467openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
HIGH8.0CVE-2025-30749openjdk: Better Glyph drawing (Oracle CPU 2025-07)
HIGH8.0CVE-2025-46762org.apache.parquet/parquet-avro: Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata
HIGH8.0CVE-2025-50059openjdk: Improve HTTP client header handling (Oracle CPU 2025-07)
HIGH8.0CVE-2025-50106openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07)
HIGH8.0CVE-2025-59375firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
HIGH8.0CVE-2025-59419io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection
HIGH8.0CVE-2025-64720libpng: LIBPNG buffer overflow
HIGH8.0CVE-2025-65018libpng: LIBPNG heap buffer overflow
HIGH8.0CVE-2025-66293libpng: LIBPNG out-of-bounds read in png_image_read_composite
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-21932openjdk: Enhance Handling of URIs (Oracle CPU 2026-01)
HIGH8.0CVE-2026-21945openjdk: Enhance Certificate Checking (Oracle CPU 2026-01)
HIGH8.0CVE-2026-27135nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-40200musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-55851io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
HIGH8.0CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-56817io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.8CVE-2026-22184zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility
HIGH7.8CVE-2026-22801libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
HIGH7.8CVE-2026-25210libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
HIGH7.5CVE-2021-31684json-smart: Denial of Service in JSONParserByteArray function
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2023-1370json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)
HIGH7.5CVE-2023-28118kaml has potential denial of service while parsing input with anchors and aliases
HIGH7.5CVE-2023-52428nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
HIGH7.5CVE-2024-21634ion-java: ion-java: Ion Java StackOverflow vulnerability
HIGH7.5CVE-2024-47072com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
HIGH7.5CVE-2025-41249org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2025-69421openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing
HIGH7.5CVE-2026-2100p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
HIGH7.5CVE-2026-28388openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing
HIGH7.5CVE-2026-28389openssl: OpenSSL: Denial of Service vulnerability in CMS processing
HIGH7.5CVE-2026-28390openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-41849spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
HIGH7.5CVE-2026-41850spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42440org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-44250netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays
HIGH7.5CVE-2026-44890netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads
HIGH7.5CVE-2026-44891io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder
HIGH7.5CVE-2026-44893netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
HIGH7.5CVE-2026-45186libexpat: denial of service via crafted XML input
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-46340netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments
HIGH7.5CVE-2026-48006netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
HIGH7.5CVE-2026-48059netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-50011netty-codec-redis: Netty: Denial of Service via malicious Redis array header
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.5CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.4CVE-2026-56820io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack
HIGH7.4CVE-2026-56821io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp
HIGH7.4CVE-2026-56822io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
HIGH7.2CVE-2024-13009jetty-server: Jetty: Gzip Request Body Buffer Corruption
HIGH7.1CVE-2026-22695libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
MEDIUM7.5CVE-2025-27817org.apache.kafka: Kafka Client Arbitrary File Read SSRF
MEDIUM7.5CVE-2025-7962com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability
MEDIUM6.9CVE-2026-56132expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
MEDIUM6.9CVE-2026-56403libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
MEDIUM6.9CVE-2026-56404libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding
MEDIUM6.9CVE-2026-56405libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow
MEDIUM6.8CVE-2026-42586netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2025-67735netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-56818io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59889jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
MEDIUM6.5CVE-2026-59920io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.5GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
MEDIUM6.1CVE-2025-22227io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
MEDIUM5.9CVE-2024-8184org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
MEDIUM5.9CVE-2026-28208com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.9CVE-2026-50219expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
MEDIUM5.9CVE-2026-56412libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2023-2976guava: insecure temporary directory creation
MEDIUM5.5CVE-2024-35255azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity
MEDIUM5.5CVE-2024-58251In netstat in BusyBox through 1.37.0, local users can launch of networ ...
MEDIUM5.5CVE-2025-30754openjdk: Enhance TLS protocol support (Oracle CPU 2025-07)
MEDIUM5.5CVE-2025-4947libcurl: curl: QUIC certificate check skip with wolfSSL
MEDIUM5.5CVE-2025-4949org.eclipse.jgit: XXE vulnerability in Eclipse JGit
MEDIUM5.5CVE-2025-5025curl: libcurl: QUIC Certificate Pinning Bypass
MEDIUM5.5CVE-2025-53057openjdk: Enhance certificate handling (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-53066openjdk: Enhance Path Factories (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-5399curl: libcurl: WebSocket endless loop
MEDIUM5.5CVE-2025-58057netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
MEDIUM5.5CVE-2025-62408c-ares: c-ares: Denial of Service due to query termination after maximum attempts
MEDIUM5.5CVE-2025-64505libpng: LIBPNG heap buffer overflow via malformed palette index
MEDIUM5.5CVE-2025-64506libpng: LIBPNG heap buffer over-read
MEDIUM5.5CVE-2025-68161Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
MEDIUM5.5CVE-2025-69419openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
MEDIUM5.5CVE-2025-9086curl: libcurl: Curl out of bounds read for cookie path
MEDIUM5.5CVE-2025-9230openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
MEDIUM5.5CVE-2025-9231openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
MEDIUM5.5CVE-2026-0636bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
MEDIUM5.5CVE-2026-21925openjdk: Improve JMX connections (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-21933openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-27171zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions
MEDIUM5.5CVE-2026-31790openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
MEDIUM5.5CVE-2026-32776libexpat: libexpat: Denial of Service due to NULL pointer dereference
MEDIUM5.5CVE-2026-32777libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
MEDIUM5.5CVE-2026-32778libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
MEDIUM5.5CVE-2026-33416libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
MEDIUM5.5CVE-2026-33636libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-56131libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
MEDIUM5.5CVE-2026-56406libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
MEDIUM5.5CVE-2026-56407libexpat: libexpat: Arbitrary code execution due to integer overflow
MEDIUM5.5CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...
MEDIUM5.5CVE-2026-56410libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
MEDIUM5.5CVE-2026-56411expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-59919io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy
MEDIUM5.5CVE-2026-6042musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2021-34429jetty: crafted URIs allow bypassing security constraints
MEDIUM5.3CVE-2023-26048jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()
MEDIUM5.3CVE-2023-40167jetty: Improper validation of HTTP/1 content-length
MEDIUM5.3CVE-2024-9823org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
MEDIUM5.3CVE-2025-31672org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-41851Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation
MEDIUM5.3CVE-2026-44248netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
MEDIUM4.4CVE-2026-34757libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability
MEDIUM4.3CVE-2021-39194Improper Handling of Missing Values in kaml
MEDIUM4.3CVE-2024-38808spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
MEDIUM3.7CVE-2024-6763org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOW3.9GHSA-58qw-p7qm-5rvhEclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.7CVE-2026-41848spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher
LOW3.7CVE-2026-41852spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation
LOW3.5CVE-2023-36479jetty: Improper addition of quotation marks to user inputs in CgiServlet
LOW3.3CVE-2020-8908guava: local information disclosure via temporary directory created with unsafe permissions
LOW3.3CVE-2025-46394In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.7CVE-2022-2047jetty-http: improver hostname input handling
LOW2.5CVE-2026-24515libexpat: libexpat null pointer dereference
LOW2.4CVE-2023-26049jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies
LOW2.0CVE-2025-10148curl: predictable WebSocket mask
LOW2.0CVE-2025-13151libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
LOW2.0CVE-2025-15468openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling
LOW2.0CVE-2025-58056netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
LOW2.0CVE-2025-66199openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
LOW2.0CVE-2025-66453Rhino is an open-source implementation of JavaScript written entirely ...
LOW2.0CVE-2025-68160openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter
LOW2.0CVE-2025-69418openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
LOW2.0CVE-2025-69420openssl: OpenSSL: Denial of Service via malformed TimeStamp Response
LOW2.0CVE-2025-9232openssl: Out-of-bounds read in HTTP client no_proxy handling
LOW2.0CVE-2026-22795openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing
LOW2.0CVE-2026-22796openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification
LOW2.0CVE-2026-32588Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
LOW2.0CVE-2026-41080libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

2.12.0

Severity Breakdown

SeverityCount
CRITICAL7
HIGH86
MEDIUM105
LOW28

Details for version: 2.12.0

CVE Details for Version: 2.12.0

SeverityScoreCVE IDDescription
CRITICAL9.8CVE-2025-54988org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
CRITICAL9.8CVE-2026-31789openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
CRITICAL9.8CVE-2026-42027Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
CRITICAL9.5CVE-2025-30065org.apache.parquet/parquet-avro: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
CRITICAL9.5CVE-2025-66516tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
CRITICAL9.1CVE-2026-40682org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing
CRITICAL8.1CVE-2026-8178Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
HIGH8.9CVE-2024-25638dnsjava: Improper response validation allowing DNSSEC bypass
HIGH8.8CVE-2025-48734commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.2CVE-2025-49146pgjdbc: pgjdbc insecure authentication in channel binding
HIGH8.1CVE-2025-59250JDBC Driver for SQL Server has improper input validation issue
HIGH8.1CVE-2026-25646libpng: LIBPNG has a heap buffer overflow in png_set_quantize
HIGH8.1CVE-2026-28387openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-15467openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
HIGH8.0CVE-2025-23083nodejs: Node.js Worker Thread Exposure via Diagnostics Channel
HIGH8.0CVE-2025-30749openjdk: Better Glyph drawing (Oracle CPU 2025-07)
HIGH8.0CVE-2025-46762org.apache.parquet/parquet-avro: Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata
HIGH8.0CVE-2025-50059openjdk: Improve HTTP client header handling (Oracle CPU 2025-07)
HIGH8.0CVE-2025-50106openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07)
HIGH8.0CVE-2025-59375firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
HIGH8.0CVE-2025-64720libpng: LIBPNG buffer overflow
HIGH8.0CVE-2025-65018libpng: LIBPNG heap buffer overflow
HIGH8.0CVE-2025-66293libpng: LIBPNG out-of-bounds read in png_image_read_composite
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-21932openjdk: Enhance Handling of URIs (Oracle CPU 2026-01)
HIGH8.0CVE-2026-21945openjdk: Enhance Certificate Checking (Oracle CPU 2026-01)
HIGH8.0CVE-2026-27135nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-40200musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.8CVE-2026-22184zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility
HIGH7.8CVE-2026-22801libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
HIGH7.8CVE-2026-25210libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
HIGH7.5CVE-2019-16869netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers
HIGH7.5CVE-2021-22569protobuf-java: potential DoS in the parsing procedure for binary data
HIGH7.5CVE-2021-31684json-smart: Denial of Service in JSONParserByteArray function
HIGH7.5CVE-2022-3509protobuf-java: Textformat parsing issue leads to DoS
HIGH7.5CVE-2022-3510protobuf-java: Message-Type Extensions parsing issue leads to DoS
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2023-1370json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)
HIGH7.5CVE-2023-28118kaml has potential denial of service while parsing input with anchors and aliases
HIGH7.5CVE-2023-34054Reactor Netty HTTP Server denial of service vulnerability
HIGH7.5CVE-2023-34062reactor-netty-http: directory traversal vulnerability
HIGH7.5CVE-2023-34455snappy-java: Unchecked chunk length leads to DoS
HIGH7.5CVE-2023-43642snappy-java: Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact
HIGH7.5CVE-2023-52428nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
HIGH7.5CVE-2024-21634ion-java: ion-java: Ion Java StackOverflow vulnerability
HIGH7.5CVE-2024-47072com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
HIGH7.5CVE-2024-57699json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370)
HIGH7.5CVE-2024-7254protobuf: StackOverflow vulnerability in Protocol Buffers
HIGH7.5CVE-2025-24970io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
HIGH7.5CVE-2025-27553apache-commons-vfs: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT
HIGH7.5CVE-2025-41249org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2025-69421openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing
HIGH7.5CVE-2026-2100p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
HIGH7.5CVE-2026-28388openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing
HIGH7.5CVE-2026-28389openssl: OpenSSL: Denial of Service vulnerability in CMS processing
HIGH7.5CVE-2026-28390openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-41849spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
HIGH7.5CVE-2026-41850spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42440org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-45186libexpat: denial of service via crafted XML input
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
HIGH7.2CVE-2024-13009jetty-server: Jetty: Gzip Request Body Buffer Corruption
HIGH7.1CVE-2026-22695libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
MEDIUM7.5CVE-2025-27817org.apache.kafka: Kafka Client Arbitrary File Read SSRF
MEDIUM7.5CVE-2025-7962com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability
MEDIUM6.9CVE-2026-56132expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
MEDIUM6.9CVE-2026-56403libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
MEDIUM6.9CVE-2026-56404libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding
MEDIUM6.9CVE-2026-56405libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2024-29131commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
MEDIUM6.5CVE-2024-29133commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2025-67735netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.1CVE-2025-22227io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
MEDIUM5.9CVE-2023-34453snappy-java: Integer overflow in shuffle leads to DoS
MEDIUM5.9CVE-2023-34454snappy-java: Integer overflow in compress leads to DoS
MEDIUM5.9CVE-2024-8184org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
MEDIUM5.9CVE-2026-28208com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.9CVE-2026-50219expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
MEDIUM5.9CVE-2026-56412libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2022-3171protobuf-java: timeout in parser leads to DoS
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2023-2976guava: insecure temporary directory creation
MEDIUM5.5CVE-2024-35255azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity
MEDIUM5.5CVE-2024-47535netty: Denial of Service attack on windows app using Netty
MEDIUM5.5CVE-2024-58251In netstat in BusyBox through 1.37.0, local users can launch of networ ...
MEDIUM5.5CVE-2024-8176libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat
MEDIUM5.5CVE-2025-21587openjdk: Better TLS connection support (Oracle CPU 2025-04)
MEDIUM5.5CVE-2025-25193netty: Denial of Service attack on windows app using Netty
MEDIUM5.5CVE-2025-30474Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...
MEDIUM5.5CVE-2025-30698openjdk: Enhance Buffered Image handling (Oracle CPU 2025-04)
MEDIUM5.5CVE-2025-30754openjdk: Enhance TLS protocol support (Oracle CPU 2025-07)
MEDIUM5.5CVE-2025-31344giflib: The giflib open-source component has a buffer overflow vulnerability
MEDIUM5.5CVE-2025-31498c-ares: c-ares has a use-after-free in read_answers()
MEDIUM5.5CVE-2025-4947libcurl: curl: QUIC certificate check skip with wolfSSL
MEDIUM5.5CVE-2025-4949org.eclipse.jgit: XXE vulnerability in Eclipse JGit
MEDIUM5.5CVE-2025-5025curl: libcurl: QUIC Certificate Pinning Bypass
MEDIUM5.5CVE-2025-53057openjdk: Enhance certificate handling (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-53066openjdk: Enhance Path Factories (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-5399curl: libcurl: WebSocket endless loop
MEDIUM5.5CVE-2025-58057netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
MEDIUM5.5CVE-2025-62408c-ares: c-ares: Denial of Service due to query termination after maximum attempts
MEDIUM5.5CVE-2025-64505libpng: LIBPNG heap buffer overflow via malformed palette index
MEDIUM5.5CVE-2025-64506libpng: LIBPNG heap buffer over-read
MEDIUM5.5CVE-2025-68161Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
MEDIUM5.5CVE-2025-69419openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
MEDIUM5.5CVE-2025-9086curl: libcurl: Curl out of bounds read for cookie path
MEDIUM5.5CVE-2025-9230openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
MEDIUM5.5CVE-2025-9231openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
MEDIUM5.5CVE-2026-21925openjdk: Improve JMX connections (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-21933openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-27171zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions
MEDIUM5.5CVE-2026-31790openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
MEDIUM5.5CVE-2026-32776libexpat: libexpat: Denial of Service due to NULL pointer dereference
MEDIUM5.5CVE-2026-32777libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
MEDIUM5.5CVE-2026-32778libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
MEDIUM5.5CVE-2026-33416libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
MEDIUM5.5CVE-2026-33636libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-56131libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
MEDIUM5.5CVE-2026-56406libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
MEDIUM5.5CVE-2026-56407libexpat: libexpat: Arbitrary code execution due to integer overflow
MEDIUM5.5CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...
MEDIUM5.5CVE-2026-56410libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
MEDIUM5.5CVE-2026-56411expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-6042musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.3CVE-2020-29582kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure
MEDIUM5.3CVE-2021-34429jetty: crafted URIs allow bypassing security constraints
MEDIUM5.3CVE-2022-24329kotlin: Not possible to lock dependencies for Multiplatform Gradle Projects
MEDIUM5.3CVE-2023-26048jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()
MEDIUM5.3CVE-2023-40167jetty: Improper validation of HTTP/1 content-length
MEDIUM5.3CVE-2024-9823org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
MEDIUM5.3CVE-2025-31672org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-41851Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
MEDIUM4.4CVE-2026-34757libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability
MEDIUM4.3CVE-2021-39194Improper Handling of Missing Values in kaml
MEDIUM4.3CVE-2024-38808spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
MEDIUM3.7CVE-2024-6763org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOW3.9GHSA-58qw-p7qm-5rvhEclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.7CVE-2026-41848spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher
LOW3.7CVE-2026-41852spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation
LOW3.5CVE-2023-36479jetty: Improper addition of quotation marks to user inputs in CgiServlet
LOW3.3CVE-2020-8908guava: local information disclosure via temporary directory created with unsafe permissions
LOW3.3CVE-2024-23454Apache Hadoop: Temporary File Local Information Disclosure
LOW3.3CVE-2025-27496Snowflake JDBC Driver client-side encryption key in DEBUG logs
LOW3.3CVE-2025-46394In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.7CVE-2022-2047jetty-http: improver hostname input handling
LOW2.5CVE-2026-24515libexpat: libexpat null pointer dereference
LOW2.4CVE-2023-26049jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies
LOW2.0CVE-2025-10148curl: predictable WebSocket mask
LOW2.0CVE-2025-13151libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
LOW2.0CVE-2025-15468openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling
LOW2.0CVE-2025-58056netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
LOW2.0CVE-2025-66199openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
LOW2.0CVE-2025-66453Rhino is an open-source implementation of JavaScript written entirely ...
LOW2.0CVE-2025-68160openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter
LOW2.0CVE-2025-69418openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
LOW2.0CVE-2025-69420openssl: OpenSSL: Denial of Service via malformed TimeStamp Response
LOW2.0CVE-2025-9232openssl: Out-of-bounds read in HTTP client no_proxy handling
LOW2.0CVE-2026-22795openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing
LOW2.0CVE-2026-22796openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification
LOW2.0CVE-2026-32588Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
LOW2.0CVE-2026-41080libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

2.11.0

Severity Breakdown

SeverityCount
CRITICAL7
HIGH90
MEDIUM110
LOW33

Details for version: 2.11.0

CVE Details for Version: 2.11.0

SeverityScoreCVE IDDescription
CRITICAL9.8CVE-2025-54988org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
CRITICAL9.8CVE-2026-31789openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
CRITICAL9.8CVE-2026-42027Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
CRITICAL9.5CVE-2025-30065org.apache.parquet/parquet-avro: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
CRITICAL9.5CVE-2025-66516tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
CRITICAL9.1CVE-2026-40682org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing
CRITICAL8.1CVE-2026-8178Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
HIGH8.9CVE-2024-25638dnsjava: Improper response validation allowing DNSSEC bypass
HIGH8.8CVE-2025-23015org.apache.cassandra:cassandra-all: Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
HIGH8.8CVE-2025-48734commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.2CVE-2025-49146pgjdbc: pgjdbc insecure authentication in channel binding
HIGH8.1CVE-2025-59250JDBC Driver for SQL Server has improper input validation issue
HIGH8.1CVE-2026-25646libpng: LIBPNG has a heap buffer overflow in png_set_quantize
HIGH8.1CVE-2026-28387openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2024-12797openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-15467openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
HIGH8.0CVE-2025-23083nodejs: Node.js Worker Thread Exposure via Diagnostics Channel
HIGH8.0CVE-2025-30749openjdk: Better Glyph drawing (Oracle CPU 2025-07)
HIGH8.0CVE-2025-46762org.apache.parquet/parquet-avro: Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata
HIGH8.0CVE-2025-50059openjdk: Improve HTTP client header handling (Oracle CPU 2025-07)
HIGH8.0CVE-2025-50106openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07)
HIGH8.0CVE-2025-59375firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
HIGH8.0CVE-2025-64720libpng: LIBPNG buffer overflow
HIGH8.0CVE-2025-65018libpng: LIBPNG heap buffer overflow
HIGH8.0CVE-2025-66293libpng: LIBPNG out-of-bounds read in png_image_read_composite
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-21932openjdk: Enhance Handling of URIs (Oracle CPU 2026-01)
HIGH8.0CVE-2026-21945openjdk: Enhance Certificate Checking (Oracle CPU 2026-01)
HIGH8.0CVE-2026-27135nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
HIGH8.0CVE-2026-33630c-ares: c-ares: Use-after-free / double-free in query-completion handling
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-40200musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
HIGH8.0CVE-2026-54291org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade
HIGH8.0CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.8CVE-2025-24789Snowflake JDBC allows an untrusted search path on Windows
HIGH7.8CVE-2026-22184zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility
HIGH7.8CVE-2026-22801libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
HIGH7.8CVE-2026-25210libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
HIGH7.5CVE-2019-16869netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers
HIGH7.5CVE-2021-22569protobuf-java: potential DoS in the parsing procedure for binary data
HIGH7.5CVE-2021-31684json-smart: Denial of Service in JSONParserByteArray function
HIGH7.5CVE-2022-3509protobuf-java: Textformat parsing issue leads to DoS
HIGH7.5CVE-2022-3510protobuf-java: Message-Type Extensions parsing issue leads to DoS
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2023-1370json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)
HIGH7.5CVE-2023-28118kaml has potential denial of service while parsing input with anchors and aliases
HIGH7.5CVE-2023-34054Reactor Netty HTTP Server denial of service vulnerability
HIGH7.5CVE-2023-34062reactor-netty-http: directory traversal vulnerability
HIGH7.5CVE-2023-34455snappy-java: Unchecked chunk length leads to DoS
HIGH7.5CVE-2023-43642snappy-java: Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact
HIGH7.5CVE-2023-52428nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
HIGH7.5CVE-2024-21634ion-java: ion-java: Ion Java StackOverflow vulnerability
HIGH7.5CVE-2024-47072com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
HIGH7.5CVE-2024-57699json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370)
HIGH7.5CVE-2024-7254protobuf: StackOverflow vulnerability in Protocol Buffers
HIGH7.5CVE-2025-24970io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
HIGH7.5CVE-2025-27553apache-commons-vfs: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT
HIGH7.5CVE-2025-41249org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2025-69421openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing
HIGH7.5CVE-2026-2100p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
HIGH7.5CVE-2026-28388openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing
HIGH7.5CVE-2026-28389openssl: OpenSSL: Denial of Service vulnerability in CMS processing
HIGH7.5CVE-2026-28390openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-41849spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
HIGH7.5CVE-2026-41850spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42440org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-45186libexpat: denial of service via crafted XML input
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
HIGH7.2CVE-2024-13009jetty-server: Jetty: Gzip Request Body Buffer Corruption
HIGH7.1CVE-2026-22695libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
HIGH7.0CVE-2025-26519musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write ...
MEDIUM7.5CVE-2025-27817org.apache.kafka: Kafka Client Arbitrary File Read SSRF
MEDIUM7.5CVE-2025-7962com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability
MEDIUM6.9CVE-2026-56132expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
MEDIUM6.9CVE-2026-56403libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
MEDIUM6.9CVE-2026-56404libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding
MEDIUM6.9CVE-2026-56405libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2024-29131commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
MEDIUM6.5CVE-2024-29133commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2025-67735netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.1CVE-2025-22227io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
MEDIUM5.9CVE-2023-34453snappy-java: Integer overflow in shuffle leads to DoS
MEDIUM5.9CVE-2023-34454snappy-java: Integer overflow in compress leads to DoS
MEDIUM5.9CVE-2024-27137org.apache.cassandra:cassandra-all: Apache Cassandra: unrestricted deserialization of JMX authentication credentials
MEDIUM5.9CVE-2024-8184org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
MEDIUM5.9CVE-2026-28208com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.9CVE-2026-50219expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
MEDIUM5.9CVE-2026-56412libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2022-3171protobuf-java: timeout in parser leads to DoS
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2023-2976guava: insecure temporary directory creation
MEDIUM5.5CVE-2024-12133libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS
MEDIUM5.5CVE-2024-35255azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity
MEDIUM5.5CVE-2024-47535netty: Denial of Service attack on windows app using Netty
MEDIUM5.5CVE-2024-58251In netstat in BusyBox through 1.37.0, local users can launch of networ ...
MEDIUM5.5CVE-2024-8176libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat
MEDIUM5.5CVE-2025-21502openjdk: Enhance array handling (Oracle CPU 2025-01)
MEDIUM5.5CVE-2025-21587openjdk: Better TLS connection support (Oracle CPU 2025-04)
MEDIUM5.5CVE-2025-25193netty: Denial of Service attack on windows app using Netty
MEDIUM5.5CVE-2025-30474Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...
MEDIUM5.5CVE-2025-30698openjdk: Enhance Buffered Image handling (Oracle CPU 2025-04)
MEDIUM5.5CVE-2025-30754openjdk: Enhance TLS protocol support (Oracle CPU 2025-07)
MEDIUM5.5CVE-2025-31344giflib: The giflib open-source component has a buffer overflow vulnerability
MEDIUM5.5CVE-2025-31498c-ares: c-ares has a use-after-free in read_answers()
MEDIUM5.5CVE-2025-4947libcurl: curl: QUIC certificate check skip with wolfSSL
MEDIUM5.5CVE-2025-4949org.eclipse.jgit: XXE vulnerability in Eclipse JGit
MEDIUM5.5CVE-2025-5025curl: libcurl: QUIC Certificate Pinning Bypass
MEDIUM5.5CVE-2025-53057openjdk: Enhance certificate handling (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-53066openjdk: Enhance Path Factories (Oracle CPU 2025-10)
MEDIUM5.5CVE-2025-5399curl: libcurl: WebSocket endless loop
MEDIUM5.5CVE-2025-58057netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
MEDIUM5.5CVE-2025-62408c-ares: c-ares: Denial of Service due to query termination after maximum attempts
MEDIUM5.5CVE-2025-64505libpng: LIBPNG heap buffer overflow via malformed palette index
MEDIUM5.5CVE-2025-64506libpng: LIBPNG heap buffer over-read
MEDIUM5.5CVE-2025-68161Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
MEDIUM5.5CVE-2025-69419openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
MEDIUM5.5CVE-2025-9086curl: libcurl: Curl out of bounds read for cookie path
MEDIUM5.5CVE-2025-9230openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
MEDIUM5.5CVE-2025-9231openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
MEDIUM5.5CVE-2026-21925openjdk: Improve JMX connections (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-21933openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01)
MEDIUM5.5CVE-2026-27171zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions
MEDIUM5.5CVE-2026-31790openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
MEDIUM5.5CVE-2026-32776libexpat: libexpat: Denial of Service due to NULL pointer dereference
MEDIUM5.5CVE-2026-32777libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
MEDIUM5.5CVE-2026-32778libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
MEDIUM5.5CVE-2026-33416libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
MEDIUM5.5CVE-2026-33636libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-56131libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
MEDIUM5.5CVE-2026-56406libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
MEDIUM5.5CVE-2026-56407libexpat: libexpat: Arbitrary code execution due to integer overflow
MEDIUM5.5CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output ...
MEDIUM5.5CVE-2026-56410libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
MEDIUM5.5CVE-2026-56411expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-6042musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.4CVE-2025-24860org.apache.cassandra:cassandra-all: Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions
MEDIUM5.3CVE-2020-29582kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure
MEDIUM5.3CVE-2021-34429jetty: crafted URIs allow bypassing security constraints
MEDIUM5.3CVE-2022-24329kotlin: Not possible to lock dependencies for Multiplatform Gradle Projects
MEDIUM5.3CVE-2023-26048jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()
MEDIUM5.3CVE-2023-40167jetty: Improper validation of HTTP/1 content-length
MEDIUM5.3CVE-2024-9823org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
MEDIUM5.3CVE-2025-31672org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-41851Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation
MEDIUM5.3CVE-2026-45205commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM4.7CVE-2026-71497org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
MEDIUM4.4CVE-2025-24790Snowflake JDBC uses insecure temporary credential cache file permissions
MEDIUM4.4CVE-2026-34757libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability
MEDIUM4.3CVE-2021-39194Improper Handling of Missing Values in kaml
MEDIUM4.3CVE-2024-38808spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
MEDIUM3.7CVE-2024-6763org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOW3.9GHSA-58qw-p7qm-5rvhEclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.7CVE-2026-41848spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher
LOW3.7CVE-2026-41852spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation
LOW3.5CVE-2023-36479jetty: Improper addition of quotation marks to user inputs in CgiServlet
LOW3.3CVE-2020-8908guava: local information disclosure via temporary directory created with unsafe permissions
LOW3.3CVE-2024-23454Apache Hadoop: Temporary File Local Information Disclosure
LOW3.3CVE-2025-27496Snowflake JDBC Driver client-side encryption key in DEBUG logs
LOW3.3CVE-2025-46394In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.7CVE-2022-2047jetty-http: improver hostname input handling
LOW2.5CVE-2026-24515libexpat: libexpat null pointer dereference
LOW2.4CVE-2023-26049jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies
LOW2.0CVE-2024-11053curl: curl netrc password leak
LOW2.0CVE-2024-13176openssl: Timing side-channel in ECDSA signature computation
LOW2.0CVE-2025-0167When asked to use a `.netrc` file for credentials **and** to follow HT ...
LOW2.0CVE-2025-0665libcurl: Double Close of Eventfd in libcurl
LOW2.0CVE-2025-0725libcurl: Buffer Overflow in libcurl via zlib Integer Overflow
LOW2.0CVE-2025-10148curl: predictable WebSocket mask
LOW2.0CVE-2025-13151libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
LOW2.0CVE-2025-15468openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling
LOW2.0CVE-2025-58056netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
LOW2.0CVE-2025-66199openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
LOW2.0CVE-2025-66453Rhino is an open-source implementation of JavaScript written entirely ...
LOW2.0CVE-2025-68160openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter
LOW2.0CVE-2025-69418openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
LOW2.0CVE-2025-69420openssl: OpenSSL: Denial of Service via malformed TimeStamp Response
LOW2.0CVE-2025-9232openssl: Out-of-bounds read in HTTP client no_proxy handling
LOW2.0CVE-2026-22795openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing
LOW2.0CVE-2026-22796openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification
LOW2.0CVE-2026-32588Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
LOW2.0CVE-2026-41080libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

2.10.0

Severity Breakdown

SeverityCount
CRITICAL9
HIGH83
MEDIUM94
LOW35

Details for version: 2.10.0

CVE Details for Version: 2.10.0

SeverityScoreCVE IDDescription
CRITICAL9.8CVE-2021-37404hadoop-hdfs: Heap buffer overflow in Apache Hadoop libhdfs
CRITICAL9.8CVE-2022-25168hadoop: Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTar
CRITICAL9.8CVE-2024-47561apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
CRITICAL9.8CVE-2025-54988org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
CRITICAL9.8CVE-2026-31789openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing
CRITICAL9.5CVE-2025-30065org.apache.parquet/parquet-avro: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
CRITICAL9.5CVE-2025-66516tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
CRITICAL9.1CVE-2023-44981zookeeper: Authorization Bypass in Apache ZooKeeper
CRITICAL8.1CVE-2026-8178Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
HIGH8.8CVE-2020-9492hadoop: WebHDFS client might send SPNEGO authorization header
HIGH8.8CVE-2025-23015org.apache.cassandra:cassandra-all: Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
HIGH8.8CVE-2025-48734commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default
HIGH8.7CVE-2026-35554Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
HIGH8.7CVE-2026-45674netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
HIGH8.7CVE-2026-47691io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
HIGH8.1CVE-2025-59250JDBC Driver for SQL Server has improper input validation issue
HIGH8.1CVE-2026-25646libpng: LIBPNG has a heap buffer overflow in png_set_quantize
HIGH8.1CVE-2026-28387openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication
HIGH8.1CVE-2026-44249netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
HIGH8.1CVE-2026-54512jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
HIGH8.1CVE-2026-54513jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
HIGH8.0CVE-2024-12797openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected
HIGH8.0CVE-2025-12183lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure
HIGH8.0CVE-2025-15467openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
HIGH8.0CVE-2025-23083nodejs: Node.js Worker Thread Exposure via Diagnostics Channel
HIGH8.0CVE-2025-30749openjdk: Better Glyph drawing (Oracle CPU 2025-07)
HIGH8.0CVE-2025-46762org.apache.parquet/parquet-avro: Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata
HIGH8.0CVE-2025-50059openjdk: Improve HTTP client header handling (Oracle CPU 2025-07)
HIGH8.0CVE-2025-50106openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07)
HIGH8.0CVE-2025-52999com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError
HIGH8.0CVE-2025-59375firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
HIGH8.0CVE-2025-64720libpng: LIBPNG buffer overflow
HIGH8.0CVE-2025-65018libpng: LIBPNG heap buffer overflow
HIGH8.0CVE-2025-66293libpng: LIBPNG out-of-bounds read in png_image_read_composite
HIGH8.0CVE-2025-66566lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
HIGH8.0CVE-2026-10050jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision
HIGH8.0CVE-2026-33871netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
HIGH8.0CVE-2026-40200musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
HIGH8.0CVE-2026-56745netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
HIGH8.0CVE-2026-59901io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)
HIGH8.0GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
HIGH7.8CVE-2025-24789Snowflake JDBC allows an untrusted search path on Windows
HIGH7.8CVE-2026-22184zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility
HIGH7.8CVE-2026-22801libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
HIGH7.8CVE-2026-25210libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
HIGH7.5CVE-2017-5637zookeeper: Incorrect input validation with wchp/wchc four letter words
HIGH7.5CVE-2018-8012zookeeper: No authentication or authorization is enforced when a server joins a quorum
HIGH7.5CVE-2019-16869netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers
HIGH7.5CVE-2021-31684json-smart: Denial of Service in JSONParserByteArray function
HIGH7.5CVE-2022-40150jettison: memory exhaustion via user-supplied XML or JSON data
HIGH7.5CVE-2022-41404org.ini4j: unspecified DoS
HIGH7.5CVE-2022-45685jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data
HIGH7.5CVE-2022-45693jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos
HIGH7.5CVE-2023-1370json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)
HIGH7.5CVE-2023-1436jettison: Uncontrolled Recursion in JSONArray
HIGH7.5CVE-2023-28118kaml has potential denial of service while parsing input with anchors and aliases
HIGH7.5CVE-2023-34054Reactor Netty HTTP Server denial of service vulnerability
HIGH7.5CVE-2023-34062reactor-netty-http: directory traversal vulnerability
HIGH7.5CVE-2023-52428nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
HIGH7.5CVE-2024-21634ion-java: ion-java: Ion Java StackOverflow vulnerability
HIGH7.5CVE-2024-47072com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
HIGH7.5CVE-2024-57699json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370)
HIGH7.5CVE-2024-7254protobuf: StackOverflow vulnerability in Protocol Buffers
HIGH7.5CVE-2025-24970io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
HIGH7.5CVE-2025-27553apache-commons-vfs: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT
HIGH7.5CVE-2025-41249org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
HIGH7.5CVE-2025-55163netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
HIGH7.5CVE-2025-69421openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing
HIGH7.5CVE-2026-28388openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing
HIGH7.5CVE-2026-28389openssl: OpenSSL: Denial of Service vulnerability in CMS processing
HIGH7.5CVE-2026-28390openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
HIGH7.5CVE-2026-33870io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
HIGH7.5CVE-2026-41254Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
HIGH7.5CVE-2026-41849spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
HIGH7.5CVE-2026-41850spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions
HIGH7.5CVE-2026-42198jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication
HIGH7.5CVE-2026-42579netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
HIGH7.5CVE-2026-42583netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
HIGH7.5CVE-2026-42587netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
HIGH7.5CVE-2026-45186libexpat: denial of service via crafted XML input
HIGH7.5CVE-2026-45416netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
HIGH7.5CVE-2026-45799Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HIGH7.5CVE-2026-50010netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
HIGH7.5CVE-2026-54399org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
HIGH7.5CVE-2026-55831io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
HIGH7.5CVE-2026-55833netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
HIGH7.5CVE-2026-56819io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
HIGH7.4CVE-2026-2332org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
HIGH7.3CVE-2026-42584netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
HIGH7.2CVE-2024-13009jetty-server: Jetty: Gzip Request Body Buffer Corruption
HIGH7.1CVE-2026-22695libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
HIGH7.0CVE-2025-26519musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write ...
MEDIUM7.5CVE-2025-27817org.apache.kafka: Kafka Client Arbitrary File Read SSRF
MEDIUM7.5CVE-2025-7962com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability
MEDIUM7.5CVE-2026-50193jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing
MEDIUM6.8CVE-2026-45673netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
MEDIUM6.5CVE-2022-40149jettison: parser crash by stackoverflow
MEDIUM6.5CVE-2024-29131commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
MEDIUM6.5CVE-2024-29133commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
MEDIUM6.5CVE-2024-9681curl: HSTS subdomain overwrites parent cache entry
MEDIUM6.5CVE-2025-48924commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
MEDIUM6.5CVE-2025-67735netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
MEDIUM6.5CVE-2026-42580netty: Netty: Request smuggling via chunk size parser integer overflow
MEDIUM6.5CVE-2026-42585netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
MEDIUM6.5CVE-2026-56746io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
MEDIUM6.5CVE-2026-59888com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records
MEDIUM6.5CVE-2026-59949LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
MEDIUM6.1CVE-2025-22227io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects
MEDIUM5.9CVE-2019-0201zookeeper: Information disclosure in Apache ZooKeeper
MEDIUM5.9CVE-2024-27137org.apache.cassandra:cassandra-all: Apache Cassandra: unrestricted deserialization of JMX authentication credentials
MEDIUM5.9CVE-2024-43382Snowflake JDBC Security Advisory
MEDIUM5.9CVE-2024-8184org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
MEDIUM5.9CVE-2026-28208com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives
MEDIUM5.9CVE-2026-41245junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives.
MEDIUM5.8CVE-2024-58103Wire has Uncontrolled Recursion on Nested Groups
MEDIUM5.8CVE-2025-53864com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
MEDIUM5.8CVE-2026-42581netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
MEDIUM5.7CVE-2026-59921io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
MEDIUM5.5CVE-2023-2976guava: insecure temporary directory creation
MEDIUM5.5CVE-2024-12133libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS
MEDIUM5.5CVE-2024-21208JDK: HTTP client improper handling of maxHeaderSize (8328286)
MEDIUM5.5CVE-2024-21210JDK: Array indexing integer overflow (8328544)
MEDIUM5.5CVE-2024-21217JDK: Unbounded allocation leads to out-of-memory error (8331446)
MEDIUM5.5CVE-2024-21235JDK: Integer conversion error leads to incorrect range check (8332644)
MEDIUM5.5CVE-2024-35255azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity
MEDIUM5.5CVE-2024-47535netty: Denial of Service attack on windows app using Netty
MEDIUM5.5CVE-2024-50602libexpat: expat: DoS via XML_ResumeParser
MEDIUM5.5CVE-2024-58251In netstat in BusyBox through 1.37.0, local users can launch of networ ...
MEDIUM5.5CVE-2024-8176libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat
MEDIUM5.5CVE-2025-21502openjdk: Enhance array handling (Oracle CPU 2025-01)
MEDIUM5.5CVE-2025-21587openjdk: Better TLS connection support (Oracle CPU 2025-04)
MEDIUM5.5CVE-2025-25193netty: Denial of Service attack on windows app using Netty
MEDIUM5.5CVE-2025-30474Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...
MEDIUM5.5CVE-2025-30698openjdk: Enhance Buffered Image handling (Oracle CPU 2025-04)
MEDIUM5.5CVE-2025-30754openjdk: Enhance TLS protocol support (Oracle CPU 2025-07)
MEDIUM5.5CVE-2025-4947libcurl: curl: QUIC certificate check skip with wolfSSL
MEDIUM5.5CVE-2025-4949org.eclipse.jgit: XXE vulnerability in Eclipse JGit
MEDIUM5.5CVE-2025-5025curl: libcurl: QUIC Certificate Pinning Bypass
MEDIUM5.5CVE-2025-5399curl: libcurl: WebSocket endless loop
MEDIUM5.5CVE-2025-58057netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
MEDIUM5.5CVE-2025-64505libpng: LIBPNG heap buffer overflow via malformed palette index
MEDIUM5.5CVE-2025-64506libpng: LIBPNG heap buffer over-read
MEDIUM5.5CVE-2025-68161Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
MEDIUM5.5CVE-2025-69419openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
MEDIUM5.5CVE-2025-9086curl: libcurl: Curl out of bounds read for cookie path
MEDIUM5.5CVE-2025-9230openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
MEDIUM5.5CVE-2025-9231openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
MEDIUM5.5CVE-2026-27171zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions
MEDIUM5.5CVE-2026-31790openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key
MEDIUM5.5CVE-2026-32776libexpat: libexpat: Denial of Service due to NULL pointer dereference
MEDIUM5.5CVE-2026-32777libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
MEDIUM5.5CVE-2026-32778libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
MEDIUM5.5CVE-2026-33416libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
MEDIUM5.5CVE-2026-33636libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
MEDIUM5.5CVE-2026-34477org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
MEDIUM5.5CVE-2026-34478org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
MEDIUM5.5CVE-2026-34480org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
MEDIUM5.5CVE-2026-59898io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)
MEDIUM5.5CVE-2026-59899io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
MEDIUM5.5CVE-2026-59900io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
MEDIUM5.5CVE-2026-6042musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv
MEDIUM5.5GHSA-72hv-8253-57qqjackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
MEDIUM5.4CVE-2025-24860org.apache.cassandra:cassandra-all: Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions
MEDIUM5.3CVE-2021-34429jetty: crafted URIs allow bypassing security constraints
MEDIUM5.3CVE-2023-26048jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter()
MEDIUM5.3CVE-2023-40167jetty: Improper validation of HTTP/1 content-length
MEDIUM5.3CVE-2024-9823org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
MEDIUM5.3CVE-2025-31672org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
MEDIUM5.3CVE-2026-33558Apache Kafka exposes sensitive information in its DEBUG logs
MEDIUM5.3CVE-2026-41417netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
MEDIUM5.3CVE-2026-41851Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation
MEDIUM5.3CVE-2026-45292opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
MEDIUM5.3CVE-2026-47244netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
MEDIUM5.3CVE-2026-48043netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
MEDIUM5.3CVE-2026-50020netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
MEDIUM5.3CVE-2026-50560netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
MEDIUM5.3CVE-2026-54514jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution
MEDIUM5.3CVE-2026-54515jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified
MEDIUM5.3CVE-2026-6790jetty: Jetty: Improper Host header validation can lead to request routing issues
MEDIUM5.3CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
MEDIUM4.4CVE-2025-24790Snowflake JDBC uses insecure temporary credential cache file permissions
MEDIUM4.4CVE-2026-34757libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability
MEDIUM4.3CVE-2021-39194Improper Handling of Missing Values in kaml
MEDIUM4.3CVE-2024-38808spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression
MEDIUM4.0CVE-2026-45536netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
MEDIUM3.7CVE-2024-6763org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
LOW3.9GHSA-58qw-p7qm-5rvhEclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
LOW3.7CVE-2025-11143org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing
LOW3.7CVE-2026-41848spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher
LOW3.7CVE-2026-41852spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation
LOW3.5CVE-2023-36479jetty: Improper addition of quotation marks to user inputs in CgiServlet
LOW3.3CVE-2020-8908guava: local information disclosure via temporary directory created with unsafe permissions
LOW3.3CVE-2024-23454Apache Hadoop: Temporary File Local Information Disclosure
LOW3.3CVE-2025-27496Snowflake JDBC Driver client-side encryption key in DEBUG logs
LOW3.3CVE-2025-46394In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...
LOW3.3CVE-2026-3293snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing
LOW2.7CVE-2022-2047jetty-http: improver hostname input handling
LOW2.5CVE-2026-24515libexpat: libexpat null pointer dereference
LOW2.4CVE-2023-26049jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies
LOW2.0CVE-2024-11053curl: curl netrc password leak
LOW2.0CVE-2024-13176openssl: Timing side-channel in ECDSA signature computation
LOW2.0CVE-2024-21211JDK: Compiler unspecified vulnerability (CPU Oct 2024)
LOW2.0CVE-2024-9143openssl: Low-level invalid GF(2^m) parameters lead to OOB memory access
LOW2.0CVE-2025-0167When asked to use a `.netrc` file for credentials **and** to follow HT ...
LOW2.0CVE-2025-0665libcurl: Double Close of Eventfd in libcurl
LOW2.0CVE-2025-0725libcurl: Buffer Overflow in libcurl via zlib Integer Overflow
LOW2.0CVE-2025-10148curl: predictable WebSocket mask
LOW2.0CVE-2025-13151libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
LOW2.0CVE-2025-15468openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling
LOW2.0CVE-2025-58056netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
LOW2.0CVE-2025-66199openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
LOW2.0CVE-2025-66453Rhino is an open-source implementation of JavaScript written entirely ...
LOW2.0CVE-2025-68160openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter
LOW2.0CVE-2025-69418openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
LOW2.0CVE-2025-69420openssl: OpenSSL: Denial of Service via malformed TimeStamp Response
LOW2.0CVE-2025-9232openssl: Out-of-bounds read in HTTP client no_proxy handling
LOW2.0CVE-2026-22795openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing
LOW2.0CVE-2026-22796openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification
LOW2.0CVE-2026-32588Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
LOW2.0CVE-2026-41080libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
LOW2.0CVE-2026-42578netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation