Apache Hop Security Vulnerability Scans
Last Updated: 14 Aug 2026 00:49:18
↑Development
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 1 |
| HIGH | 19 |
| MEDIUM | 23 |
| LOW | 2 |
Details for version: Development
CVE Details for Version: Development
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.1 | CVE-2023-44981 | zookeeper: Authorization Bypass in Apache ZooKeeper |
| HIGH | 8.2 | CVE-2022-46751 | apache-ivy: XML External Entity vulnerability |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-52999 | com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2025-67721 | aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-24308 | Apache ZooKeeper: Apache ZooKeeper: Information disclosure via improper handling of configuration values |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2026-40983 | micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests |
| HIGH | 7.5 | CVE-2026-40984 | micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-56740 | JLine is a Java library for handling console input. Prior to 3.30.14, ... |
| HIGH | 7.5 | CVE-2026-56741 | JLine is a Java library for handling console input. Prior to 3.30.14, ... |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.4 | CVE-2026-24281 | Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing |
| MEDIUM | 7.5 | CVE-2026-50193 | jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2026-54518 | jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 5.9 | CVE-2018-10237 | guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.5 | CVE-2023-2976 | guava: insecure temporary directory creation |
| MEDIUM | 5.5 | CVE-2026-34479 | org.apache.logging.log4j/log4j-1.2-api: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping |
| MEDIUM | 5.5 | CVE-2026-34481 | org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2024-23944 | Apache-ZooKeeper: Apache ZooKeeper: Information disclosure in persistent watcher handling |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-54516 | jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties |
| MEDIUM | 5.3 | CVE-2026-54517 | jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 4.0 | CVE-2025-49128 | com.fasterxml.jackson.core/jackson-core: Jackson-core Memory Disclosure via Source Snippet in JsonLocation |
| MEDIUM | 3.7 | CVE-2024-6763 | org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.3 | CVE-2020-8908 | guava: local information disclosure via temporary directory created with unsafe permissions |
↑2.18.1
Severity Breakdown
| Severity | Count |
|---|---|
| HIGH | 36 |
| MEDIUM | 52 |
| LOW | 2 |
Details for version: 2.18.1
CVE Details for Version: 2.18.1
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-11352 | curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability |
| HIGH | 8.0 | CVE-2026-11586 | curl: curl: Denial of Service via WebSocket PING flood |
| HIGH | 8.0 | CVE-2026-12064 | curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-47063 | openjdk: Enhance Jar handling (Oracle CPU 2026-07) |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-55851 | io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message |
| HIGH | 8.0 | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-56817 | io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | CVE-2026-8286 | curl: curl: Insecure connection establishment due to TLS configuration mismatch |
| HIGH | 8.0 | CVE-2026-8458 | curl: libcurl: Unauthorized connection reuse due to a logical error |
| HIGH | 8.0 | CVE-2026-8925 | curl: curl: Double-free vulnerability in SASL authentication |
| HIGH | 8.0 | CVE-2026-8927 | curl: Information disclosure due to uncleared proxy authentication state |
| HIGH | 8.0 | CVE-2026-9547 | curl: curl: Man-in-the-middle attack via SSH host key bypass |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2026-2100 | p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-44891 | io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56740 | JLine is a Java library for handling console input. Prior to 3.30.14, ... |
| HIGH | 7.5 | CVE-2026-56741 | JLine is a Java library for handling console input. Prior to 3.30.14, ... |
| HIGH | 7.5 | CVE-2026-56816 | Netty is a network application framework for development of protocol s ... |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.5 | CVE-2026-73507 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion |
| HIGH | 7.4 | CVE-2026-56820 | io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack |
| HIGH | 7.4 | CVE-2026-56821 | io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp |
| HIGH | 7.4 | CVE-2026-56822 | io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp |
| MEDIUM | 6.9 | CVE-2026-56132 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow |
| MEDIUM | 6.9 | CVE-2026-56403 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts |
| MEDIUM | 6.9 | CVE-2026-56404 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding |
| MEDIUM | 6.9 | CVE-2026-56405 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow |
| MEDIUM | 6.5 | CVE-2026-54518 | jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-56818 | io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59920 | io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.9 | CVE-2026-50219 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| MEDIUM | 5.9 | CVE-2026-56412 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2026-10051 | jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections |
| MEDIUM | 5.5 | CVE-2026-10536 | libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service |
| MEDIUM | 5.5 | CVE-2026-11564 | libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse |
| MEDIUM | 5.5 | CVE-2026-11856 | curl: curl: Information disclosure via incorrect Digest authentication header reuse |
| MEDIUM | 5.5 | CVE-2026-46917 | openjdk: Improve DTLS handshaking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-46968 | openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47021 | openjdk: Enhance XBM image support (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47027 | openjdk: Enhance Jar file processing (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-56131 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking |
| MEDIUM | 5.5 | CVE-2026-56406 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer |
| MEDIUM | 5.5 | CVE-2026-56407 | libexpat: libexpat: Arbitrary code execution due to integer overflow |
| MEDIUM | 5.5 | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... |
| MEDIUM | 5.5 | CVE-2026-56410 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. |
| MEDIUM | 5.5 | CVE-2026-56411 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-59919 | io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy |
| MEDIUM | 5.5 | CVE-2026-60147 | openjdk: Improve certification checking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-8924 | curl: curl: Cookie injection via malicious HTTP server using super cookies |
| MEDIUM | 5.5 | CVE-2026-8926 | curl: curl: Information disclosure via incorrect .netrc password lookup |
| MEDIUM | 5.5 | CVE-2026-8932 | libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse |
| MEDIUM | 5.5 | CVE-2026-9079 | libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials |
| MEDIUM | 5.5 | CVE-2026-9080 | libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback |
| MEDIUM | 5.5 | CVE-2026-9545 | libcurl: libcurl: Information disclosure via cached SSL session and early data |
| MEDIUM | 5.5 | CVE-2026-9546 | libcurl: libcurl: Information disclosure due to persistent Referer header |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-54516 | jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties |
| MEDIUM | 5.3 | CVE-2026-54517 | jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 5.3 | CVE-2026-8384 | jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| LOW | 2.0 | CVE-2026-47010 | openjdk: Enhance JPEG handling (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-47059 | openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) |
↑2.18.0
Severity Breakdown
| Severity | Count |
|---|---|
| HIGH | 47 |
| MEDIUM | 59 |
| LOW | 13 |
Details for version: 2.18.0
CVE Details for Version: 2.18.0
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-45447 | openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() |
| HIGH | 8.0 | CVE-2026-47063 | openjdk: Enhance Jar handling (Oracle CPU 2026-07) |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-55851 | io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message |
| HIGH | 8.0 | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-56817 | io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2026-2100 | p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-44250 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays |
| HIGH | 7.5 | CVE-2026-44890 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads |
| HIGH | 7.5 | CVE-2026-44891 | io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder |
| HIGH | 7.5 | CVE-2026-44892 | Netty is a network application framework for development of protocol s ... |
| HIGH | 7.5 | CVE-2026-44893 | netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message |
| HIGH | 7.5 | CVE-2026-44894 | netty-codec-classes-quic: Netty: Denial of Service amplification via improper QUIC token validation |
| HIGH | 7.5 | CVE-2026-45186 | libexpat: denial of service via crafted XML input |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-46340 | netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments |
| HIGH | 7.5 | CVE-2026-48006 | netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| HIGH | 7.5 | CVE-2026-48059 | netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers |
| HIGH | 7.5 | CVE-2026-48748 | netty: Netty: Denial of Service due to memory exhaustion in HTTP/3 codec |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-50011 | netty-codec-redis: Netty: Denial of Service via malicious Redis array header |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56740 | JLine is a Java library for handling console input. Prior to 3.30.14, ... |
| HIGH | 7.5 | CVE-2026-56741 | JLine is a Java library for handling console input. Prior to 3.30.14, ... |
| HIGH | 7.5 | CVE-2026-56816 | Netty is a network application framework for development of protocol s ... |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.5 | CVE-2026-5773 | curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse |
| HIGH | 7.5 | CVE-2026-6276 | curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers |
| HIGH | 7.5 | CVE-2026-73507 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion |
| HIGH | 7.4 | CVE-2026-56820 | io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack |
| HIGH | 7.4 | CVE-2026-56821 | io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp |
| HIGH | 7.4 | CVE-2026-56822 | io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp |
| MEDIUM | 6.9 | CVE-2026-56132 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow |
| MEDIUM | 6.9 | CVE-2026-56403 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts |
| MEDIUM | 6.9 | CVE-2026-56404 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding |
| MEDIUM | 6.9 | CVE-2026-56405 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2026-54518 | jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass |
| MEDIUM | 6.5 | CVE-2026-5545 | curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-56818 | io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59920 | io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.9 | CVE-2026-50219 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| MEDIUM | 5.9 | CVE-2026-56412 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2026-10051 | jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections |
| MEDIUM | 5.5 | CVE-2026-34182 | openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages |
| MEDIUM | 5.5 | CVE-2026-34183 | openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler |
| MEDIUM | 5.5 | CVE-2026-42764 | openssl: NULL pointer dereference in QUIC server initial packet handling |
| MEDIUM | 5.5 | CVE-2026-45445 | openssl: AES-OCB IV Ignored on EVP_Cipher() Path |
| MEDIUM | 5.5 | CVE-2026-46917 | openjdk: Improve DTLS handshaking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-46968 | openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47021 | openjdk: Enhance XBM image support (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47027 | openjdk: Enhance Jar file processing (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-4873 | curl: curl: Information disclosure due to incorrect TLS connection reuse |
| MEDIUM | 5.5 | CVE-2026-56131 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking |
| MEDIUM | 5.5 | CVE-2026-56406 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer |
| MEDIUM | 5.5 | CVE-2026-56407 | libexpat: libexpat: Arbitrary code execution due to integer overflow |
| MEDIUM | 5.5 | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... |
| MEDIUM | 5.5 | CVE-2026-56410 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. |
| MEDIUM | 5.5 | CVE-2026-56411 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-59919 | io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy |
| MEDIUM | 5.5 | CVE-2026-60147 | openjdk: Improve certification checking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-6253 | curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies |
| MEDIUM | 5.5 | CVE-2026-6429 | curl: libcurl: Credential leak via reused proxy connection during HTTP redirects |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-54516 | jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties |
| MEDIUM | 5.3 | CVE-2026-54517 | jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-7009 | curl: Curl: Certificate validation bypass due to OCSP stapling flaw |
| MEDIUM | 5.3 | CVE-2026-7168 | curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 5.3 | CVE-2026-8384 | jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications |
| MEDIUM | 4.8 | CVE-2026-50009 | Netty is a network application framework for development of protocol s ... |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| LOW | 2.0 | CVE-2026-34180 | openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. |
| LOW | 2.0 | CVE-2026-34181 | openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys |
| LOW | 2.0 | CVE-2026-41080 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML |
| LOW | 2.0 | CVE-2026-42766 | openssl: Possible NULL Dereference in Password-Based CMS Decryption |
| LOW | 2.0 | CVE-2026-42767 | openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption |
| LOW | 2.0 | CVE-2026-42768 | openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() |
| LOW | 2.0 | CVE-2026-42769 | openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate |
| LOW | 2.0 | CVE-2026-42770 | openssl: FFC-DH Peer Validation Uses Attacker-Supplied q |
| LOW | 2.0 | CVE-2026-45446 | openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes |
| LOW | 2.0 | CVE-2026-47010 | openjdk: Enhance JPEG handling (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-47059 | openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-7383 | openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing |
| LOW | 2.0 | CVE-2026-9076 | openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption |
↑2.17.0
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 10 |
| HIGH | 72 |
| MEDIUM | 88 |
| LOW | 22 |
Details for version: 2.17.0
CVE Details for Version: 2.17.0
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.8 | CVE-2026-31789 | openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing |
| CRITICAL | 9.8 | CVE-2026-41409 | Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix |
| CRITICAL | 9.8 | CVE-2026-41635 | Apache MINA: Apache MINA: Arbitrary code execution via classname allowlist bypass |
| CRITICAL | 9.8 | CVE-2026-42027 | Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest |
| CRITICAL | 9.8 | CVE-2026-42778 | Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409) |
| CRITICAL | 9.8 | CVE-2026-42779 | Apache MINA: Apache MINA: Arbitrary Code Execution via Classname Allowlist Bypass |
| CRITICAL | 9.8 | CVE-2026-47065 | mina: mina: Arbitrary Code Execution via Deserialization Bypass |
| CRITICAL | 9.5 | CVE-2025-14813 | bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly |
| CRITICAL | 9.1 | CVE-2026-40682 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing |
| CRITICAL | 8.1 | CVE-2026-8178 | Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.1 | CVE-2026-25646 | libpng: LIBPNG has a heap buffer overflow in png_set_quantize |
| HIGH | 8.1 | CVE-2026-28387 | openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-22016 | openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04) |
| HIGH | 8.0 | CVE-2026-27135 | nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-34282 | openjdk: Enhance TLS connection handling (Oracle CPU 2026-04) |
| HIGH | 8.0 | CVE-2026-40200 | musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort |
| HIGH | 8.0 | CVE-2026-45447 | openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() |
| HIGH | 8.0 | CVE-2026-47063 | openjdk: Enhance Jar handling (Oracle CPU 2026-07) |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-55851 | io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message |
| HIGH | 8.0 | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-56817 | io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.8 | CVE-2026-22184 | zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2026-1605 | org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests |
| HIGH | 7.5 | CVE-2026-2100 | p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters |
| HIGH | 7.5 | CVE-2026-28388 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing |
| HIGH | 7.5 | CVE-2026-28389 | openssl: OpenSSL: Denial of Service vulnerability in CMS processing |
| HIGH | 7.5 | CVE-2026-28390 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42440 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files |
| HIGH | 7.5 | CVE-2026-42577 | Netty is an asynchronous, event-driven network application framework. ... |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42582 | netty: io.netty/netty-codec-http3: Netty: Denial of Service due to improper length validation in header block decoding |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-44250 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays |
| HIGH | 7.5 | CVE-2026-44890 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads |
| HIGH | 7.5 | CVE-2026-44891 | io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder |
| HIGH | 7.5 | CVE-2026-44892 | Netty is a network application framework for development of protocol s ... |
| HIGH | 7.5 | CVE-2026-44893 | netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message |
| HIGH | 7.5 | CVE-2026-44894 | netty-codec-classes-quic: Netty: Denial of Service amplification via improper QUIC token validation |
| HIGH | 7.5 | CVE-2026-45186 | libexpat: denial of service via crafted XML input |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-46340 | netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments |
| HIGH | 7.5 | CVE-2026-48006 | netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| HIGH | 7.5 | CVE-2026-48059 | netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers |
| HIGH | 7.5 | CVE-2026-48748 | netty: Netty: Denial of Service due to memory exhaustion in HTTP/3 codec |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-50011 | netty-codec-redis: Netty: Denial of Service via malicious Redis array header |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56740 | JLine is a Java library for handling console input. Prior to 3.30.14, ... |
| HIGH | 7.5 | CVE-2026-56741 | JLine is a Java library for handling console input. Prior to 3.30.14, ... |
| HIGH | 7.5 | CVE-2026-56816 | Netty is a network application framework for development of protocol s ... |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.5 | CVE-2026-5773 | curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse |
| HIGH | 7.5 | CVE-2026-6276 | curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers |
| HIGH | 7.5 | CVE-2026-73507 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.4 | CVE-2026-56820 | io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack |
| HIGH | 7.4 | CVE-2026-56821 | io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp |
| HIGH | 7.4 | CVE-2026-56822 | io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| MEDIUM | 6.9 | CVE-2026-56132 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow |
| MEDIUM | 6.9 | CVE-2026-56403 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts |
| MEDIUM | 6.9 | CVE-2026-56404 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding |
| MEDIUM | 6.9 | CVE-2026-56405 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow |
| MEDIUM | 6.8 | CVE-2026-42586 | netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-5545 | curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-56818 | io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59920 | io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 5.9 | CVE-2026-28208 | com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.9 | CVE-2026-50219 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| MEDIUM | 5.9 | CVE-2026-56412 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2025-14017 | curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers |
| MEDIUM | 5.5 | CVE-2026-0636 | bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java |
| MEDIUM | 5.5 | CVE-2026-10051 | jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections |
| MEDIUM | 5.5 | CVE-2026-1965 | curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication |
| MEDIUM | 5.5 | CVE-2026-22013 | openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04) |
| MEDIUM | 5.5 | CVE-2026-22021 | openjdk: Enhance certificate chain validation (Oracle CPU 2026-04) |
| MEDIUM | 5.5 | CVE-2026-23865 | freetype: Information disclosure or denial of service via specially crafted font files |
| MEDIUM | 5.5 | CVE-2026-2673 | openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group |
| MEDIUM | 5.5 | CVE-2026-27171 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions |
| MEDIUM | 5.5 | CVE-2026-31790 | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key |
| MEDIUM | 5.5 | CVE-2026-32776 | libexpat: libexpat: Denial of Service due to NULL pointer dereference |
| MEDIUM | 5.5 | CVE-2026-32777 | libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing |
| MEDIUM | 5.5 | CVE-2026-32778 | libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition |
| MEDIUM | 5.5 | CVE-2026-33416 | libpng: libpng: Arbitrary code execution due to use-after-free vulnerability |
| MEDIUM | 5.5 | CVE-2026-33636 | libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion |
| MEDIUM | 5.5 | CVE-2026-34182 | openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages |
| MEDIUM | 5.5 | CVE-2026-34183 | openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-3783 | curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect |
| MEDIUM | 5.5 | CVE-2026-3784 | curl: curl: Unauthorized access due to improper HTTP proxy connection reuse |
| MEDIUM | 5.5 | CVE-2026-3805 | curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling |
| MEDIUM | 5.5 | CVE-2026-40930 | LIBPNG is a reference library for use in applications that process PNG ... |
| MEDIUM | 5.5 | CVE-2026-42764 | openssl: NULL pointer dereference in QUIC server initial packet handling |
| MEDIUM | 5.5 | CVE-2026-45445 | openssl: AES-OCB IV Ignored on EVP_Cipher() Path |
| MEDIUM | 5.5 | CVE-2026-46917 | openjdk: Improve DTLS handshaking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-46968 | openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47021 | openjdk: Enhance XBM image support (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-47027 | openjdk: Enhance Jar file processing (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-4873 | curl: curl: Information disclosure due to incorrect TLS connection reuse |
| MEDIUM | 5.5 | CVE-2026-56131 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking |
| MEDIUM | 5.5 | CVE-2026-56406 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer |
| MEDIUM | 5.5 | CVE-2026-56407 | libexpat: libexpat: Arbitrary code execution due to integer overflow |
| MEDIUM | 5.5 | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... |
| MEDIUM | 5.5 | CVE-2026-56410 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. |
| MEDIUM | 5.5 | CVE-2026-56411 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-59919 | io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy |
| MEDIUM | 5.5 | CVE-2026-60147 | openjdk: Improve certification checking (Oracle CPU 2026-07) |
| MEDIUM | 5.5 | CVE-2026-6042 | musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv |
| MEDIUM | 5.5 | CVE-2026-6253 | curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies |
| MEDIUM | 5.5 | CVE-2026-6429 | curl: libcurl: Credential leak via reused proxy connection during HTTP redirects |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-44248 | netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-7009 | curl: Curl: Certificate validation bypass due to OCSP stapling flaw |
| MEDIUM | 5.3 | CVE-2026-7168 | curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 5.3 | CVE-2026-8384 | jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications |
| MEDIUM | 4.8 | CVE-2026-50009 | Netty is a network application framework for development of protocol s ... |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| MEDIUM | 4.4 | CVE-2026-34757 | libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.0 | CVE-2025-14524 | curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token |
| LOW | 2.0 | CVE-2025-14819 | curl: libcurl: Improper certificate validation due to cached TLS settings reuse |
| LOW | 2.0 | CVE-2026-22007 | openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04) |
| LOW | 2.0 | CVE-2026-22018 | openjdk: Enhance Zip file reading (Oracle CPU 2026-04) |
| LOW | 2.0 | CVE-2026-32588 | Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes |
| LOW | 2.0 | CVE-2026-34180 | openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. |
| LOW | 2.0 | CVE-2026-34181 | openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys |
| LOW | 2.0 | CVE-2026-34268 | openjdk: Enhance key generation (Oracle CPU 2026-04) |
| LOW | 2.0 | CVE-2026-41080 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| LOW | 2.0 | CVE-2026-42766 | openssl: Possible NULL Dereference in Password-Based CMS Decryption |
| LOW | 2.0 | CVE-2026-42767 | openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption |
| LOW | 2.0 | CVE-2026-42768 | openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() |
| LOW | 2.0 | CVE-2026-42769 | openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate |
| LOW | 2.0 | CVE-2026-42770 | openssl: FFC-DH Peer Validation Uses Attacker-Supplied q |
| LOW | 2.0 | CVE-2026-45446 | openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes |
| LOW | 2.0 | CVE-2026-47010 | openjdk: Enhance JPEG handling (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-47059 | openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) |
| LOW | 2.0 | CVE-2026-7383 | openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing |
| LOW | 2.0 | CVE-2026-9076 | openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption |
↑2.16.0
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 10 |
| HIGH | 88 |
| MEDIUM | 89 |
| LOW | 32 |
Details for version: 2.16.0
CVE Details for Version: 2.16.0
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.8 | CVE-2026-31789 | openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing |
| CRITICAL | 9.8 | CVE-2026-41409 | Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix |
| CRITICAL | 9.8 | CVE-2026-41635 | Apache MINA: Apache MINA: Arbitrary code execution via classname allowlist bypass |
| CRITICAL | 9.8 | CVE-2026-42027 | Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest |
| CRITICAL | 9.8 | CVE-2026-42778 | Apache MINA: deserialization of untrusted data (incomplete fix for CVE-2026-41409) |
| CRITICAL | 9.8 | CVE-2026-42779 | Apache MINA: Apache MINA: Arbitrary Code Execution via Classname Allowlist Bypass |
| CRITICAL | 9.8 | CVE-2026-47065 | mina: mina: Arbitrary Code Execution via Deserialization Bypass |
| CRITICAL | 9.5 | CVE-2025-14813 | bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly |
| CRITICAL | 9.1 | CVE-2026-40682 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing |
| CRITICAL | 8.1 | CVE-2026-8178 | Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.1 | CVE-2025-59250 | JDBC Driver for SQL Server has improper input validation issue |
| HIGH | 8.1 | CVE-2026-25646 | libpng: LIBPNG has a heap buffer overflow in png_set_quantize |
| HIGH | 8.1 | CVE-2026-28387 | openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-15467 | openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing |
| HIGH | 8.0 | CVE-2025-64720 | libpng: LIBPNG buffer overflow |
| HIGH | 8.0 | CVE-2025-65018 | libpng: LIBPNG heap buffer overflow |
| HIGH | 8.0 | CVE-2025-66293 | libpng: LIBPNG out-of-bounds read in png_image_read_composite |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-21932 | openjdk: Enhance Handling of URIs (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-21945 | openjdk: Enhance Certificate Checking (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-22016 | openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04) |
| HIGH | 8.0 | CVE-2026-27135 | nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-34282 | openjdk: Enhance TLS connection handling (Oracle CPU 2026-04) |
| HIGH | 8.0 | CVE-2026-40200 | musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort |
| HIGH | 8.0 | CVE-2026-45447 | openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-55851 | io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message |
| HIGH | 8.0 | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-56817 | io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.8 | CVE-2026-22184 | zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility |
| HIGH | 7.8 | CVE-2026-22801 | libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API |
| HIGH | 7.8 | CVE-2026-25210 | libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation |
| HIGH | 7.5 | CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2023-1370 | json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) |
| HIGH | 7.5 | CVE-2023-28118 | kaml has potential denial of service while parsing input with anchors and aliases |
| HIGH | 7.5 | CVE-2023-52428 | nimbus-jose-jwt: large JWE p2c header value causes Denial of Service |
| HIGH | 7.5 | CVE-2024-21634 | ion-java: ion-java: Ion Java StackOverflow vulnerability |
| HIGH | 7.5 | CVE-2024-47072 | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream |
| HIGH | 7.5 | CVE-2025-41249 | org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2025-69421 | openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing |
| HIGH | 7.5 | CVE-2026-1605 | org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests |
| HIGH | 7.5 | CVE-2026-2100 | p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters |
| HIGH | 7.5 | CVE-2026-28388 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing |
| HIGH | 7.5 | CVE-2026-28389 | openssl: OpenSSL: Denial of Service vulnerability in CMS processing |
| HIGH | 7.5 | CVE-2026-28390 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-41849 | spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL |
| HIGH | 7.5 | CVE-2026-41850 | spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42440 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files |
| HIGH | 7.5 | CVE-2026-42577 | Netty is an asynchronous, event-driven network application framework. ... |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42582 | netty: io.netty/netty-codec-http3: Netty: Denial of Service due to improper length validation in header block decoding |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-44250 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays |
| HIGH | 7.5 | CVE-2026-44890 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads |
| HIGH | 7.5 | CVE-2026-44891 | io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder |
| HIGH | 7.5 | CVE-2026-44892 | Netty is a network application framework for development of protocol s ... |
| HIGH | 7.5 | CVE-2026-44893 | netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message |
| HIGH | 7.5 | CVE-2026-44894 | netty-codec-classes-quic: Netty: Denial of Service amplification via improper QUIC token validation |
| HIGH | 7.5 | CVE-2026-45186 | libexpat: denial of service via crafted XML input |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-46340 | netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments |
| HIGH | 7.5 | CVE-2026-48006 | netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| HIGH | 7.5 | CVE-2026-48059 | netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers |
| HIGH | 7.5 | CVE-2026-48748 | netty: Netty: Denial of Service due to memory exhaustion in HTTP/3 codec |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-50011 | netty-codec-redis: Netty: Denial of Service via malicious Redis array header |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56816 | Netty is a network application framework for development of protocol s ... |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.5 | CVE-2026-73507 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.4 | CVE-2026-56820 | io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack |
| HIGH | 7.4 | CVE-2026-56821 | io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp |
| HIGH | 7.4 | CVE-2026-56822 | io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| HIGH | 7.1 | CVE-2026-22695 | libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read |
| MEDIUM | 6.9 | CVE-2026-56132 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow |
| MEDIUM | 6.9 | CVE-2026-56403 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts |
| MEDIUM | 6.9 | CVE-2026-56404 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding |
| MEDIUM | 6.9 | CVE-2026-56405 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow |
| MEDIUM | 6.8 | CVE-2026-42586 | netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2025-67735 | netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-5545 | curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-56818 | io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59920 | io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 5.9 | CVE-2026-28208 | com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.9 | CVE-2026-50219 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| MEDIUM | 5.9 | CVE-2026-56412 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2024-35255 | azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity |
| MEDIUM | 5.5 | CVE-2024-58251 | In netstat in BusyBox through 1.37.0, local users can launch of networ ... |
| MEDIUM | 5.5 | CVE-2025-11187 | openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file |
| MEDIUM | 5.5 | CVE-2025-62408 | c-ares: c-ares: Denial of Service due to query termination after maximum attempts |
| MEDIUM | 5.5 | CVE-2025-64505 | libpng: LIBPNG heap buffer overflow via malformed palette index |
| MEDIUM | 5.5 | CVE-2025-64506 | libpng: LIBPNG heap buffer over-read |
| MEDIUM | 5.5 | CVE-2025-68161 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification |
| MEDIUM | 5.5 | CVE-2025-69419 | openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing |
| MEDIUM | 5.5 | CVE-2026-0636 | bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java |
| MEDIUM | 5.5 | CVE-2026-10051 | jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections |
| MEDIUM | 5.5 | CVE-2026-21925 | openjdk: Improve JMX connections (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-21933 | openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-22013 | openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04) |
| MEDIUM | 5.5 | CVE-2026-22021 | openjdk: Enhance certificate chain validation (Oracle CPU 2026-04) |
| MEDIUM | 5.5 | CVE-2026-23865 | freetype: Information disclosure or denial of service via specially crafted font files |
| MEDIUM | 5.5 | CVE-2026-2673 | openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group |
| MEDIUM | 5.5 | CVE-2026-27171 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions |
| MEDIUM | 5.5 | CVE-2026-31790 | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key |
| MEDIUM | 5.5 | CVE-2026-32776 | libexpat: libexpat: Denial of Service due to NULL pointer dereference |
| MEDIUM | 5.5 | CVE-2026-32777 | libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing |
| MEDIUM | 5.5 | CVE-2026-32778 | libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition |
| MEDIUM | 5.5 | CVE-2026-33416 | libpng: libpng: Arbitrary code execution due to use-after-free vulnerability |
| MEDIUM | 5.5 | CVE-2026-33636 | libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion |
| MEDIUM | 5.5 | CVE-2026-34182 | openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages |
| MEDIUM | 5.5 | CVE-2026-34183 | openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-42764 | openssl: NULL pointer dereference in QUIC server initial packet handling |
| MEDIUM | 5.5 | CVE-2026-45445 | openssl: AES-OCB IV Ignored on EVP_Cipher() Path |
| MEDIUM | 5.5 | CVE-2026-56131 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking |
| MEDIUM | 5.5 | CVE-2026-56406 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer |
| MEDIUM | 5.5 | CVE-2026-56407 | libexpat: libexpat: Arbitrary code execution due to integer overflow |
| MEDIUM | 5.5 | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... |
| MEDIUM | 5.5 | CVE-2026-56410 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. |
| MEDIUM | 5.5 | CVE-2026-56411 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-59919 | io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy |
| MEDIUM | 5.5 | CVE-2026-6042 | musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-41851 | Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation |
| MEDIUM | 5.3 | CVE-2026-44248 | netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 5.3 | CVE-2026-8384 | jetty: Eclipse Jetty: Path confusion vulnerability may lead to information disclosure in web applications |
| MEDIUM | 4.8 | CVE-2026-50009 | Netty is a network application framework for development of protocol s ... |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| MEDIUM | 4.4 | CVE-2026-34757 | libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability |
| MEDIUM | 4.3 | CVE-2021-39194 | Improper Handling of Missing Values in kaml |
| MEDIUM | 4.3 | CVE-2024-38808 | spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.7 | CVE-2026-41848 | spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher |
| LOW | 3.7 | CVE-2026-41852 | spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation |
| LOW | 3.3 | CVE-2025-46394 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ... |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.5 | CVE-2026-24515 | libexpat: libexpat null pointer dereference |
| LOW | 2.0 | CVE-2025-13151 | libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string |
| LOW | 2.0 | CVE-2025-15468 | openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling |
| LOW | 2.0 | CVE-2025-15469 | openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation |
| LOW | 2.0 | CVE-2025-66199 | openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression |
| LOW | 2.0 | CVE-2025-66453 | Rhino is an open-source implementation of JavaScript written entirely ... |
| LOW | 2.0 | CVE-2025-68160 | openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter |
| LOW | 2.0 | CVE-2025-69418 | openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls |
| LOW | 2.0 | CVE-2025-69420 | openssl: OpenSSL: Denial of Service via malformed TimeStamp Response |
| LOW | 2.0 | CVE-2026-22007 | openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04) |
| LOW | 2.0 | CVE-2026-22018 | openjdk: Enhance Zip file reading (Oracle CPU 2026-04) |
| LOW | 2.0 | CVE-2026-22795 | openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing |
| LOW | 2.0 | CVE-2026-22796 | openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification |
| LOW | 2.0 | CVE-2026-32588 | Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes |
| LOW | 2.0 | CVE-2026-34180 | openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. |
| LOW | 2.0 | CVE-2026-34181 | openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys |
| LOW | 2.0 | CVE-2026-34268 | openjdk: Enhance key generation (Oracle CPU 2026-04) |
| LOW | 2.0 | CVE-2026-41080 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| LOW | 2.0 | CVE-2026-42766 | openssl: Possible NULL Dereference in Password-Based CMS Decryption |
| LOW | 2.0 | CVE-2026-42767 | openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption |
| LOW | 2.0 | CVE-2026-42768 | openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() |
| LOW | 2.0 | CVE-2026-42769 | openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate |
| LOW | 2.0 | CVE-2026-42770 | openssl: FFC-DH Peer Validation Uses Attacker-Supplied q |
| LOW | 2.0 | CVE-2026-45446 | openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes |
| LOW | 2.0 | CVE-2026-7383 | openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing |
| LOW | 2.0 | CVE-2026-9076 | openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption |
↑2.15.0
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 8 |
| HIGH | 85 |
| MEDIUM | 100 |
| LOW | 39 |
Details for version: 2.15.0
CVE Details for Version: 2.15.0
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.8 | CVE-2025-54988 | org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA |
| CRITICAL | 9.8 | CVE-2026-31789 | openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing |
| CRITICAL | 9.8 | CVE-2026-42027 | Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest |
| CRITICAL | 9.5 | CVE-2025-14813 | bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly |
| CRITICAL | 9.5 | CVE-2025-66516 | tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected |
| CRITICAL | 9.1 | CVE-2025-58050 | pcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS |
| CRITICAL | 9.1 | CVE-2026-40682 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing |
| CRITICAL | 8.1 | CVE-2026-8178 | Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading |
| HIGH | 8.8 | CVE-2025-48734 | commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.1 | CVE-2025-59250 | JDBC Driver for SQL Server has improper input validation issue |
| HIGH | 8.1 | CVE-2026-25646 | libpng: LIBPNG has a heap buffer overflow in png_set_quantize |
| HIGH | 8.1 | CVE-2026-28387 | openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-15467 | openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing |
| HIGH | 8.0 | CVE-2025-59375 | firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing |
| HIGH | 8.0 | CVE-2025-59419 | io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection |
| HIGH | 8.0 | CVE-2025-64720 | libpng: LIBPNG buffer overflow |
| HIGH | 8.0 | CVE-2025-65018 | libpng: LIBPNG heap buffer overflow |
| HIGH | 8.0 | CVE-2025-66293 | libpng: LIBPNG out-of-bounds read in png_image_read_composite |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-21932 | openjdk: Enhance Handling of URIs (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-21945 | openjdk: Enhance Certificate Checking (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-22016 | openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04) |
| HIGH | 8.0 | CVE-2026-27135 | nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-34282 | openjdk: Enhance TLS connection handling (Oracle CPU 2026-04) |
| HIGH | 8.0 | CVE-2026-40200 | musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort |
| HIGH | 8.0 | CVE-2026-45447 | openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-55851 | io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message |
| HIGH | 8.0 | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-56817 | io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.8 | CVE-2026-22184 | zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility |
| HIGH | 7.8 | CVE-2026-22801 | libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API |
| HIGH | 7.8 | CVE-2026-25210 | libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation |
| HIGH | 7.5 | CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2023-1370 | json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) |
| HIGH | 7.5 | CVE-2023-28118 | kaml has potential denial of service while parsing input with anchors and aliases |
| HIGH | 7.5 | CVE-2023-52428 | nimbus-jose-jwt: large JWE p2c header value causes Denial of Service |
| HIGH | 7.5 | CVE-2024-21634 | ion-java: ion-java: Ion Java StackOverflow vulnerability |
| HIGH | 7.5 | CVE-2024-47072 | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream |
| HIGH | 7.5 | CVE-2025-41249 | org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2025-69421 | openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing |
| HIGH | 7.5 | CVE-2026-2100 | p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters |
| HIGH | 7.5 | CVE-2026-28388 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing |
| HIGH | 7.5 | CVE-2026-28389 | openssl: OpenSSL: Denial of Service vulnerability in CMS processing |
| HIGH | 7.5 | CVE-2026-28390 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-41849 | spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL |
| HIGH | 7.5 | CVE-2026-41850 | spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42440 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-44250 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays |
| HIGH | 7.5 | CVE-2026-44890 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads |
| HIGH | 7.5 | CVE-2026-44891 | io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder |
| HIGH | 7.5 | CVE-2026-44893 | netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message |
| HIGH | 7.5 | CVE-2026-45186 | libexpat: denial of service via crafted XML input |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-46340 | netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments |
| HIGH | 7.5 | CVE-2026-48006 | netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| HIGH | 7.5 | CVE-2026-48059 | netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-50011 | netty-codec-redis: Netty: Denial of Service via malicious Redis array header |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.5 | CVE-2026-73507 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.4 | CVE-2026-56820 | io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack |
| HIGH | 7.4 | CVE-2026-56821 | io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp |
| HIGH | 7.4 | CVE-2026-56822 | io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| HIGH | 7.2 | CVE-2024-13009 | jetty-server: Jetty: Gzip Request Body Buffer Corruption |
| HIGH | 7.1 | CVE-2026-22695 | libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read |
| MEDIUM | 7.5 | CVE-2025-7962 | com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability |
| MEDIUM | 6.9 | CVE-2026-56132 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow |
| MEDIUM | 6.9 | CVE-2026-56403 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts |
| MEDIUM | 6.9 | CVE-2026-56404 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding |
| MEDIUM | 6.9 | CVE-2026-56405 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow |
| MEDIUM | 6.8 | CVE-2026-42586 | netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2025-67735 | netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-5545 | curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-56818 | io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59920 | io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 5.9 | CVE-2024-8184 | org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| MEDIUM | 5.9 | CVE-2026-28208 | com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.9 | CVE-2026-50219 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| MEDIUM | 5.9 | CVE-2026-56412 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2024-35255 | azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity |
| MEDIUM | 5.5 | CVE-2024-58251 | In netstat in BusyBox through 1.37.0, local users can launch of networ ... |
| MEDIUM | 5.5 | CVE-2025-11187 | openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file |
| MEDIUM | 5.5 | CVE-2025-53057 | openjdk: Enhance certificate handling (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-53066 | openjdk: Enhance Path Factories (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-58057 | netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack |
| MEDIUM | 5.5 | CVE-2025-62408 | c-ares: c-ares: Denial of Service due to query termination after maximum attempts |
| MEDIUM | 5.5 | CVE-2025-64505 | libpng: LIBPNG heap buffer overflow via malformed palette index |
| MEDIUM | 5.5 | CVE-2025-64506 | libpng: LIBPNG heap buffer over-read |
| MEDIUM | 5.5 | CVE-2025-68161 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification |
| MEDIUM | 5.5 | CVE-2025-69419 | openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing |
| MEDIUM | 5.5 | CVE-2025-9086 | curl: libcurl: Curl out of bounds read for cookie path |
| MEDIUM | 5.5 | CVE-2025-9230 | openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap |
| MEDIUM | 5.5 | CVE-2025-9231 | openssl: Timing side-channel in SM2 algorithm on 64 bit ARM |
| MEDIUM | 5.5 | CVE-2026-0636 | bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java |
| MEDIUM | 5.5 | CVE-2026-21925 | openjdk: Improve JMX connections (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-21933 | openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-22013 | openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04) |
| MEDIUM | 5.5 | CVE-2026-22021 | openjdk: Enhance certificate chain validation (Oracle CPU 2026-04) |
| MEDIUM | 5.5 | CVE-2026-23865 | freetype: Information disclosure or denial of service via specially crafted font files |
| MEDIUM | 5.5 | CVE-2026-2673 | openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group |
| MEDIUM | 5.5 | CVE-2026-27171 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions |
| MEDIUM | 5.5 | CVE-2026-31790 | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key |
| MEDIUM | 5.5 | CVE-2026-32776 | libexpat: libexpat: Denial of Service due to NULL pointer dereference |
| MEDIUM | 5.5 | CVE-2026-32777 | libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing |
| MEDIUM | 5.5 | CVE-2026-32778 | libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition |
| MEDIUM | 5.5 | CVE-2026-33416 | libpng: libpng: Arbitrary code execution due to use-after-free vulnerability |
| MEDIUM | 5.5 | CVE-2026-33636 | libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion |
| MEDIUM | 5.5 | CVE-2026-34182 | openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages |
| MEDIUM | 5.5 | CVE-2026-34183 | openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-42764 | openssl: NULL pointer dereference in QUIC server initial packet handling |
| MEDIUM | 5.5 | CVE-2026-45445 | openssl: AES-OCB IV Ignored on EVP_Cipher() Path |
| MEDIUM | 5.5 | CVE-2026-56131 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking |
| MEDIUM | 5.5 | CVE-2026-56406 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer |
| MEDIUM | 5.5 | CVE-2026-56407 | libexpat: libexpat: Arbitrary code execution due to integer overflow |
| MEDIUM | 5.5 | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... |
| MEDIUM | 5.5 | CVE-2026-56410 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. |
| MEDIUM | 5.5 | CVE-2026-56411 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-59919 | io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy |
| MEDIUM | 5.5 | CVE-2026-6042 | musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints |
| MEDIUM | 5.3 | CVE-2023-26048 | jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() |
| MEDIUM | 5.3 | CVE-2023-40167 | jetty: Improper validation of HTTP/1 content-length |
| MEDIUM | 5.3 | CVE-2024-9823 | org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter |
| MEDIUM | 5.3 | CVE-2025-31672 | org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-41851 | Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation |
| MEDIUM | 5.3 | CVE-2026-44248 | netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| MEDIUM | 4.4 | CVE-2026-34757 | libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability |
| MEDIUM | 4.3 | CVE-2021-39194 | Improper Handling of Missing Values in kaml |
| MEDIUM | 4.3 | CVE-2024-38808 | spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| MEDIUM | 3.7 | CVE-2024-6763 | org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority |
| LOW | 3.9 | GHSA-58qw-p7qm-5rvh | Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.7 | CVE-2026-41848 | spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher |
| LOW | 3.7 | CVE-2026-41852 | spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation |
| LOW | 3.5 | CVE-2023-36479 | jetty: Improper addition of quotation marks to user inputs in CgiServlet |
| LOW | 3.3 | CVE-2025-46394 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ... |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.7 | CVE-2022-2047 | jetty-http: improver hostname input handling |
| LOW | 2.5 | CVE-2026-24515 | libexpat: libexpat null pointer dereference |
| LOW | 2.4 | CVE-2023-26049 | jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies |
| LOW | 2.0 | CVE-2025-10148 | curl: predictable WebSocket mask |
| LOW | 2.0 | CVE-2025-13151 | libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string |
| LOW | 2.0 | CVE-2025-15468 | openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling |
| LOW | 2.0 | CVE-2025-15469 | openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation |
| LOW | 2.0 | CVE-2025-58056 | netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions |
| LOW | 2.0 | CVE-2025-66199 | openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression |
| LOW | 2.0 | CVE-2025-66453 | Rhino is an open-source implementation of JavaScript written entirely ... |
| LOW | 2.0 | CVE-2025-68160 | openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter |
| LOW | 2.0 | CVE-2025-69418 | openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls |
| LOW | 2.0 | CVE-2025-69420 | openssl: OpenSSL: Denial of Service via malformed TimeStamp Response |
| LOW | 2.0 | CVE-2025-9232 | openssl: Out-of-bounds read in HTTP client no_proxy handling |
| LOW | 2.0 | CVE-2026-22007 | openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04) |
| LOW | 2.0 | CVE-2026-22018 | openjdk: Enhance Zip file reading (Oracle CPU 2026-04) |
| LOW | 2.0 | CVE-2026-22795 | openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing |
| LOW | 2.0 | CVE-2026-22796 | openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification |
| LOW | 2.0 | CVE-2026-32588 | Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes |
| LOW | 2.0 | CVE-2026-34180 | openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. |
| LOW | 2.0 | CVE-2026-34181 | openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys |
| LOW | 2.0 | CVE-2026-34268 | openjdk: Enhance key generation (Oracle CPU 2026-04) |
| LOW | 2.0 | CVE-2026-41080 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| LOW | 2.0 | CVE-2026-42766 | openssl: Possible NULL Dereference in Password-Based CMS Decryption |
| LOW | 2.0 | CVE-2026-42767 | openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption |
| LOW | 2.0 | CVE-2026-42768 | openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() |
| LOW | 2.0 | CVE-2026-42769 | openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate |
| LOW | 2.0 | CVE-2026-42770 | openssl: FFC-DH Peer Validation Uses Attacker-Supplied q |
| LOW | 2.0 | CVE-2026-45446 | openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes |
| LOW | 2.0 | CVE-2026-7383 | openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing |
| LOW | 2.0 | CVE-2026-9076 | openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption |
↑2.14.0
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 7 |
| HIGH | 86 |
| MEDIUM | 98 |
| LOW | 26 |
Details for version: 2.14.0
CVE Details for Version: 2.14.0
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.8 | CVE-2025-54988 | org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA |
| CRITICAL | 9.8 | CVE-2026-31789 | openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing |
| CRITICAL | 9.8 | CVE-2026-42027 | Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest |
| CRITICAL | 9.5 | CVE-2025-14813 | bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly |
| CRITICAL | 9.5 | CVE-2025-66516 | tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected |
| CRITICAL | 9.1 | CVE-2026-40682 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing |
| CRITICAL | 8.1 | CVE-2026-8178 | Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading |
| HIGH | 8.8 | CVE-2025-48734 | commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.2 | CVE-2025-49146 | pgjdbc: pgjdbc insecure authentication in channel binding |
| HIGH | 8.1 | CVE-2025-59250 | JDBC Driver for SQL Server has improper input validation issue |
| HIGH | 8.1 | CVE-2026-25646 | libpng: LIBPNG has a heap buffer overflow in png_set_quantize |
| HIGH | 8.1 | CVE-2026-28387 | openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-15467 | openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing |
| HIGH | 8.0 | CVE-2025-30749 | openjdk: Better Glyph drawing (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-50059 | openjdk: Improve HTTP client header handling (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-50106 | openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-59375 | firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing |
| HIGH | 8.0 | CVE-2025-59419 | io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection |
| HIGH | 8.0 | CVE-2025-64720 | libpng: LIBPNG buffer overflow |
| HIGH | 8.0 | CVE-2025-65018 | libpng: LIBPNG heap buffer overflow |
| HIGH | 8.0 | CVE-2025-66293 | libpng: LIBPNG out-of-bounds read in png_image_read_composite |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-21932 | openjdk: Enhance Handling of URIs (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-21945 | openjdk: Enhance Certificate Checking (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-27135 | nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-40200 | musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-55851 | io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message |
| HIGH | 8.0 | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-56817 | io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.8 | CVE-2026-22184 | zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility |
| HIGH | 7.8 | CVE-2026-22801 | libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API |
| HIGH | 7.8 | CVE-2026-25210 | libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation |
| HIGH | 7.5 | CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2023-1370 | json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) |
| HIGH | 7.5 | CVE-2023-28118 | kaml has potential denial of service while parsing input with anchors and aliases |
| HIGH | 7.5 | CVE-2023-52428 | nimbus-jose-jwt: large JWE p2c header value causes Denial of Service |
| HIGH | 7.5 | CVE-2024-21634 | ion-java: ion-java: Ion Java StackOverflow vulnerability |
| HIGH | 7.5 | CVE-2024-47072 | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream |
| HIGH | 7.5 | CVE-2025-41249 | org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2025-69421 | openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing |
| HIGH | 7.5 | CVE-2026-2100 | p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters |
| HIGH | 7.5 | CVE-2026-28388 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing |
| HIGH | 7.5 | CVE-2026-28389 | openssl: OpenSSL: Denial of Service vulnerability in CMS processing |
| HIGH | 7.5 | CVE-2026-28390 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-41849 | spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL |
| HIGH | 7.5 | CVE-2026-41850 | spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42440 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-44250 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays |
| HIGH | 7.5 | CVE-2026-44890 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads |
| HIGH | 7.5 | CVE-2026-44891 | io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder |
| HIGH | 7.5 | CVE-2026-44893 | netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message |
| HIGH | 7.5 | CVE-2026-45186 | libexpat: denial of service via crafted XML input |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-46340 | netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments |
| HIGH | 7.5 | CVE-2026-48006 | netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| HIGH | 7.5 | CVE-2026-48059 | netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-50011 | netty-codec-redis: Netty: Denial of Service via malicious Redis array header |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.5 | CVE-2026-73507 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.4 | CVE-2026-56820 | io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack |
| HIGH | 7.4 | CVE-2026-56821 | io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp |
| HIGH | 7.4 | CVE-2026-56822 | io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| HIGH | 7.2 | CVE-2024-13009 | jetty-server: Jetty: Gzip Request Body Buffer Corruption |
| HIGH | 7.1 | CVE-2026-22695 | libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read |
| MEDIUM | 7.5 | CVE-2025-27817 | org.apache.kafka: Kafka Client Arbitrary File Read SSRF |
| MEDIUM | 7.5 | CVE-2025-7962 | com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability |
| MEDIUM | 6.9 | CVE-2026-56132 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow |
| MEDIUM | 6.9 | CVE-2026-56403 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts |
| MEDIUM | 6.9 | CVE-2026-56404 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding |
| MEDIUM | 6.9 | CVE-2026-56405 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow |
| MEDIUM | 6.8 | CVE-2026-42586 | netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2025-67735 | netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-56818 | io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59920 | io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 6.1 | CVE-2025-22227 | io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects |
| MEDIUM | 5.9 | CVE-2024-8184 | org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| MEDIUM | 5.9 | CVE-2026-28208 | com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.9 | CVE-2026-50219 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| MEDIUM | 5.9 | CVE-2026-56412 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2023-2976 | guava: insecure temporary directory creation |
| MEDIUM | 5.5 | CVE-2024-35255 | azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity |
| MEDIUM | 5.5 | CVE-2024-58251 | In netstat in BusyBox through 1.37.0, local users can launch of networ ... |
| MEDIUM | 5.5 | CVE-2025-30754 | openjdk: Enhance TLS protocol support (Oracle CPU 2025-07) |
| MEDIUM | 5.5 | CVE-2025-4947 | libcurl: curl: QUIC certificate check skip with wolfSSL |
| MEDIUM | 5.5 | CVE-2025-4949 | org.eclipse.jgit: XXE vulnerability in Eclipse JGit |
| MEDIUM | 5.5 | CVE-2025-5025 | curl: libcurl: QUIC Certificate Pinning Bypass |
| MEDIUM | 5.5 | CVE-2025-53057 | openjdk: Enhance certificate handling (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-53066 | openjdk: Enhance Path Factories (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-5399 | curl: libcurl: WebSocket endless loop |
| MEDIUM | 5.5 | CVE-2025-58057 | netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack |
| MEDIUM | 5.5 | CVE-2025-62408 | c-ares: c-ares: Denial of Service due to query termination after maximum attempts |
| MEDIUM | 5.5 | CVE-2025-64505 | libpng: LIBPNG heap buffer overflow via malformed palette index |
| MEDIUM | 5.5 | CVE-2025-64506 | libpng: LIBPNG heap buffer over-read |
| MEDIUM | 5.5 | CVE-2025-68161 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification |
| MEDIUM | 5.5 | CVE-2025-69419 | openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing |
| MEDIUM | 5.5 | CVE-2025-9086 | curl: libcurl: Curl out of bounds read for cookie path |
| MEDIUM | 5.5 | CVE-2025-9230 | openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap |
| MEDIUM | 5.5 | CVE-2025-9231 | openssl: Timing side-channel in SM2 algorithm on 64 bit ARM |
| MEDIUM | 5.5 | CVE-2026-0636 | bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java |
| MEDIUM | 5.5 | CVE-2026-21925 | openjdk: Improve JMX connections (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-21933 | openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-27171 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions |
| MEDIUM | 5.5 | CVE-2026-31790 | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key |
| MEDIUM | 5.5 | CVE-2026-32776 | libexpat: libexpat: Denial of Service due to NULL pointer dereference |
| MEDIUM | 5.5 | CVE-2026-32777 | libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing |
| MEDIUM | 5.5 | CVE-2026-32778 | libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition |
| MEDIUM | 5.5 | CVE-2026-33416 | libpng: libpng: Arbitrary code execution due to use-after-free vulnerability |
| MEDIUM | 5.5 | CVE-2026-33636 | libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-56131 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking |
| MEDIUM | 5.5 | CVE-2026-56406 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer |
| MEDIUM | 5.5 | CVE-2026-56407 | libexpat: libexpat: Arbitrary code execution due to integer overflow |
| MEDIUM | 5.5 | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... |
| MEDIUM | 5.5 | CVE-2026-56410 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. |
| MEDIUM | 5.5 | CVE-2026-56411 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-59919 | io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy |
| MEDIUM | 5.5 | CVE-2026-6042 | musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints |
| MEDIUM | 5.3 | CVE-2023-26048 | jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() |
| MEDIUM | 5.3 | CVE-2023-40167 | jetty: Improper validation of HTTP/1 content-length |
| MEDIUM | 5.3 | CVE-2024-9823 | org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter |
| MEDIUM | 5.3 | CVE-2025-31672 | org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-41851 | Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation |
| MEDIUM | 5.3 | CVE-2026-44248 | netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| MEDIUM | 4.4 | CVE-2026-34757 | libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability |
| MEDIUM | 4.3 | CVE-2021-39194 | Improper Handling of Missing Values in kaml |
| MEDIUM | 4.3 | CVE-2024-38808 | spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| MEDIUM | 3.7 | CVE-2024-6763 | org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority |
| LOW | 3.9 | GHSA-58qw-p7qm-5rvh | Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.7 | CVE-2026-41848 | spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher |
| LOW | 3.7 | CVE-2026-41852 | spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation |
| LOW | 3.5 | CVE-2023-36479 | jetty: Improper addition of quotation marks to user inputs in CgiServlet |
| LOW | 3.3 | CVE-2020-8908 | guava: local information disclosure via temporary directory created with unsafe permissions |
| LOW | 3.3 | CVE-2025-46394 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ... |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.7 | CVE-2022-2047 | jetty-http: improver hostname input handling |
| LOW | 2.5 | CVE-2026-24515 | libexpat: libexpat null pointer dereference |
| LOW | 2.4 | CVE-2023-26049 | jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies |
| LOW | 2.0 | CVE-2025-10148 | curl: predictable WebSocket mask |
| LOW | 2.0 | CVE-2025-13151 | libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string |
| LOW | 2.0 | CVE-2025-15468 | openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling |
| LOW | 2.0 | CVE-2025-58056 | netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions |
| LOW | 2.0 | CVE-2025-66199 | openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression |
| LOW | 2.0 | CVE-2025-66453 | Rhino is an open-source implementation of JavaScript written entirely ... |
| LOW | 2.0 | CVE-2025-68160 | openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter |
| LOW | 2.0 | CVE-2025-69418 | openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls |
| LOW | 2.0 | CVE-2025-69420 | openssl: OpenSSL: Denial of Service via malformed TimeStamp Response |
| LOW | 2.0 | CVE-2025-9232 | openssl: Out-of-bounds read in HTTP client no_proxy handling |
| LOW | 2.0 | CVE-2026-22795 | openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing |
| LOW | 2.0 | CVE-2026-22796 | openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification |
| LOW | 2.0 | CVE-2026-32588 | Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes |
| LOW | 2.0 | CVE-2026-41080 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
↑2.13.0
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 7 |
| HIGH | 87 |
| MEDIUM | 98 |
| LOW | 26 |
Details for version: 2.13.0
CVE Details for Version: 2.13.0
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.8 | CVE-2025-54988 | org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA |
| CRITICAL | 9.8 | CVE-2026-31789 | openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing |
| CRITICAL | 9.8 | CVE-2026-42027 | Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest |
| CRITICAL | 9.5 | CVE-2025-14813 | bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly |
| CRITICAL | 9.5 | CVE-2025-66516 | tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected |
| CRITICAL | 9.1 | CVE-2026-40682 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing |
| CRITICAL | 8.1 | CVE-2026-8178 | Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading |
| HIGH | 8.8 | CVE-2025-48734 | commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.2 | CVE-2025-49146 | pgjdbc: pgjdbc insecure authentication in channel binding |
| HIGH | 8.1 | CVE-2025-59250 | JDBC Driver for SQL Server has improper input validation issue |
| HIGH | 8.1 | CVE-2026-25646 | libpng: LIBPNG has a heap buffer overflow in png_set_quantize |
| HIGH | 8.1 | CVE-2026-28387 | openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-15467 | openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing |
| HIGH | 8.0 | CVE-2025-30749 | openjdk: Better Glyph drawing (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-46762 | org.apache.parquet/parquet-avro: Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata |
| HIGH | 8.0 | CVE-2025-50059 | openjdk: Improve HTTP client header handling (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-50106 | openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-59375 | firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing |
| HIGH | 8.0 | CVE-2025-59419 | io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection |
| HIGH | 8.0 | CVE-2025-64720 | libpng: LIBPNG buffer overflow |
| HIGH | 8.0 | CVE-2025-65018 | libpng: LIBPNG heap buffer overflow |
| HIGH | 8.0 | CVE-2025-66293 | libpng: LIBPNG out-of-bounds read in png_image_read_composite |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-21932 | openjdk: Enhance Handling of URIs (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-21945 | openjdk: Enhance Certificate Checking (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-27135 | nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-40200 | musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-55851 | io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message |
| HIGH | 8.0 | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-56817 | io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.8 | CVE-2026-22184 | zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility |
| HIGH | 7.8 | CVE-2026-22801 | libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API |
| HIGH | 7.8 | CVE-2026-25210 | libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation |
| HIGH | 7.5 | CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2023-1370 | json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) |
| HIGH | 7.5 | CVE-2023-28118 | kaml has potential denial of service while parsing input with anchors and aliases |
| HIGH | 7.5 | CVE-2023-52428 | nimbus-jose-jwt: large JWE p2c header value causes Denial of Service |
| HIGH | 7.5 | CVE-2024-21634 | ion-java: ion-java: Ion Java StackOverflow vulnerability |
| HIGH | 7.5 | CVE-2024-47072 | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream |
| HIGH | 7.5 | CVE-2025-41249 | org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2025-69421 | openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing |
| HIGH | 7.5 | CVE-2026-2100 | p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters |
| HIGH | 7.5 | CVE-2026-28388 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing |
| HIGH | 7.5 | CVE-2026-28389 | openssl: OpenSSL: Denial of Service vulnerability in CMS processing |
| HIGH | 7.5 | CVE-2026-28390 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-41849 | spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL |
| HIGH | 7.5 | CVE-2026-41850 | spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42440 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-44250 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays |
| HIGH | 7.5 | CVE-2026-44890 | netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads |
| HIGH | 7.5 | CVE-2026-44891 | io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder |
| HIGH | 7.5 | CVE-2026-44893 | netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message |
| HIGH | 7.5 | CVE-2026-45186 | libexpat: denial of service via crafted XML input |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-46340 | netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments |
| HIGH | 7.5 | CVE-2026-48006 | netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator |
| HIGH | 7.5 | CVE-2026-48059 | netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-50011 | netty-codec-redis: Netty: Denial of Service via malicious Redis array header |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.5 | CVE-2026-73507 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.4 | CVE-2026-56820 | io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack |
| HIGH | 7.4 | CVE-2026-56821 | io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp |
| HIGH | 7.4 | CVE-2026-56822 | io.netty/netty-handler-ssl-ocsp: Netty: Time-of-check/time-of-use in netty-handler-ssl-ocsp |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| HIGH | 7.2 | CVE-2024-13009 | jetty-server: Jetty: Gzip Request Body Buffer Corruption |
| HIGH | 7.1 | CVE-2026-22695 | libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read |
| MEDIUM | 7.5 | CVE-2025-27817 | org.apache.kafka: Kafka Client Arbitrary File Read SSRF |
| MEDIUM | 7.5 | CVE-2025-7962 | com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability |
| MEDIUM | 6.9 | CVE-2026-56132 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow |
| MEDIUM | 6.9 | CVE-2026-56403 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts |
| MEDIUM | 6.9 | CVE-2026-56404 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding |
| MEDIUM | 6.9 | CVE-2026-56405 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow |
| MEDIUM | 6.8 | CVE-2026-42586 | netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2025-67735 | netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-56818 | io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59889 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| MEDIUM | 6.5 | CVE-2026-59920 | io.netty/netty-codec-stomp: Netty: Improper CR/LF neutralization in netty-codec-stomp |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.5 | GHSA-mhm7-754m-9p8w | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` |
| MEDIUM | 6.1 | CVE-2025-22227 | io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects |
| MEDIUM | 5.9 | CVE-2024-8184 | org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| MEDIUM | 5.9 | CVE-2026-28208 | com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.9 | CVE-2026-50219 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| MEDIUM | 5.9 | CVE-2026-56412 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2023-2976 | guava: insecure temporary directory creation |
| MEDIUM | 5.5 | CVE-2024-35255 | azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity |
| MEDIUM | 5.5 | CVE-2024-58251 | In netstat in BusyBox through 1.37.0, local users can launch of networ ... |
| MEDIUM | 5.5 | CVE-2025-30754 | openjdk: Enhance TLS protocol support (Oracle CPU 2025-07) |
| MEDIUM | 5.5 | CVE-2025-4947 | libcurl: curl: QUIC certificate check skip with wolfSSL |
| MEDIUM | 5.5 | CVE-2025-4949 | org.eclipse.jgit: XXE vulnerability in Eclipse JGit |
| MEDIUM | 5.5 | CVE-2025-5025 | curl: libcurl: QUIC Certificate Pinning Bypass |
| MEDIUM | 5.5 | CVE-2025-53057 | openjdk: Enhance certificate handling (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-53066 | openjdk: Enhance Path Factories (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-5399 | curl: libcurl: WebSocket endless loop |
| MEDIUM | 5.5 | CVE-2025-58057 | netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack |
| MEDIUM | 5.5 | CVE-2025-62408 | c-ares: c-ares: Denial of Service due to query termination after maximum attempts |
| MEDIUM | 5.5 | CVE-2025-64505 | libpng: LIBPNG heap buffer overflow via malformed palette index |
| MEDIUM | 5.5 | CVE-2025-64506 | libpng: LIBPNG heap buffer over-read |
| MEDIUM | 5.5 | CVE-2025-68161 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification |
| MEDIUM | 5.5 | CVE-2025-69419 | openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing |
| MEDIUM | 5.5 | CVE-2025-9086 | curl: libcurl: Curl out of bounds read for cookie path |
| MEDIUM | 5.5 | CVE-2025-9230 | openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap |
| MEDIUM | 5.5 | CVE-2025-9231 | openssl: Timing side-channel in SM2 algorithm on 64 bit ARM |
| MEDIUM | 5.5 | CVE-2026-0636 | bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java |
| MEDIUM | 5.5 | CVE-2026-21925 | openjdk: Improve JMX connections (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-21933 | openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-27171 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions |
| MEDIUM | 5.5 | CVE-2026-31790 | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key |
| MEDIUM | 5.5 | CVE-2026-32776 | libexpat: libexpat: Denial of Service due to NULL pointer dereference |
| MEDIUM | 5.5 | CVE-2026-32777 | libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing |
| MEDIUM | 5.5 | CVE-2026-32778 | libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition |
| MEDIUM | 5.5 | CVE-2026-33416 | libpng: libpng: Arbitrary code execution due to use-after-free vulnerability |
| MEDIUM | 5.5 | CVE-2026-33636 | libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-56131 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking |
| MEDIUM | 5.5 | CVE-2026-56406 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer |
| MEDIUM | 5.5 | CVE-2026-56407 | libexpat: libexpat: Arbitrary code execution due to integer overflow |
| MEDIUM | 5.5 | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... |
| MEDIUM | 5.5 | CVE-2026-56410 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. |
| MEDIUM | 5.5 | CVE-2026-56411 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-59919 | io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy |
| MEDIUM | 5.5 | CVE-2026-6042 | musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints |
| MEDIUM | 5.3 | CVE-2023-26048 | jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() |
| MEDIUM | 5.3 | CVE-2023-40167 | jetty: Improper validation of HTTP/1 content-length |
| MEDIUM | 5.3 | CVE-2024-9823 | org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter |
| MEDIUM | 5.3 | CVE-2025-31672 | org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-41851 | Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation |
| MEDIUM | 5.3 | CVE-2026-44248 | netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| MEDIUM | 4.4 | CVE-2026-34757 | libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability |
| MEDIUM | 4.3 | CVE-2021-39194 | Improper Handling of Missing Values in kaml |
| MEDIUM | 4.3 | CVE-2024-38808 | spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| MEDIUM | 3.7 | CVE-2024-6763 | org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority |
| LOW | 3.9 | GHSA-58qw-p7qm-5rvh | Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.7 | CVE-2026-41848 | spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher |
| LOW | 3.7 | CVE-2026-41852 | spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation |
| LOW | 3.5 | CVE-2023-36479 | jetty: Improper addition of quotation marks to user inputs in CgiServlet |
| LOW | 3.3 | CVE-2020-8908 | guava: local information disclosure via temporary directory created with unsafe permissions |
| LOW | 3.3 | CVE-2025-46394 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ... |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.7 | CVE-2022-2047 | jetty-http: improver hostname input handling |
| LOW | 2.5 | CVE-2026-24515 | libexpat: libexpat null pointer dereference |
| LOW | 2.4 | CVE-2023-26049 | jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies |
| LOW | 2.0 | CVE-2025-10148 | curl: predictable WebSocket mask |
| LOW | 2.0 | CVE-2025-13151 | libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string |
| LOW | 2.0 | CVE-2025-15468 | openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling |
| LOW | 2.0 | CVE-2025-58056 | netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions |
| LOW | 2.0 | CVE-2025-66199 | openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression |
| LOW | 2.0 | CVE-2025-66453 | Rhino is an open-source implementation of JavaScript written entirely ... |
| LOW | 2.0 | CVE-2025-68160 | openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter |
| LOW | 2.0 | CVE-2025-69418 | openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls |
| LOW | 2.0 | CVE-2025-69420 | openssl: OpenSSL: Denial of Service via malformed TimeStamp Response |
| LOW | 2.0 | CVE-2025-9232 | openssl: Out-of-bounds read in HTTP client no_proxy handling |
| LOW | 2.0 | CVE-2026-22795 | openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing |
| LOW | 2.0 | CVE-2026-22796 | openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification |
| LOW | 2.0 | CVE-2026-32588 | Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes |
| LOW | 2.0 | CVE-2026-41080 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
↑2.12.0
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 7 |
| HIGH | 86 |
| MEDIUM | 105 |
| LOW | 28 |
Details for version: 2.12.0
CVE Details for Version: 2.12.0
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.8 | CVE-2025-54988 | org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA |
| CRITICAL | 9.8 | CVE-2026-31789 | openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing |
| CRITICAL | 9.8 | CVE-2026-42027 | Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest |
| CRITICAL | 9.5 | CVE-2025-30065 | org.apache.parquet/parquet-avro: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata |
| CRITICAL | 9.5 | CVE-2025-66516 | tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected |
| CRITICAL | 9.1 | CVE-2026-40682 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing |
| CRITICAL | 8.1 | CVE-2026-8178 | Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading |
| HIGH | 8.9 | CVE-2024-25638 | dnsjava: Improper response validation allowing DNSSEC bypass |
| HIGH | 8.8 | CVE-2025-48734 | commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.2 | CVE-2025-49146 | pgjdbc: pgjdbc insecure authentication in channel binding |
| HIGH | 8.1 | CVE-2025-59250 | JDBC Driver for SQL Server has improper input validation issue |
| HIGH | 8.1 | CVE-2026-25646 | libpng: LIBPNG has a heap buffer overflow in png_set_quantize |
| HIGH | 8.1 | CVE-2026-28387 | openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-15467 | openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing |
| HIGH | 8.0 | CVE-2025-23083 | nodejs: Node.js Worker Thread Exposure via Diagnostics Channel |
| HIGH | 8.0 | CVE-2025-30749 | openjdk: Better Glyph drawing (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-46762 | org.apache.parquet/parquet-avro: Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata |
| HIGH | 8.0 | CVE-2025-50059 | openjdk: Improve HTTP client header handling (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-50106 | openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-59375 | firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing |
| HIGH | 8.0 | CVE-2025-64720 | libpng: LIBPNG buffer overflow |
| HIGH | 8.0 | CVE-2025-65018 | libpng: LIBPNG heap buffer overflow |
| HIGH | 8.0 | CVE-2025-66293 | libpng: LIBPNG out-of-bounds read in png_image_read_composite |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-21932 | openjdk: Enhance Handling of URIs (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-21945 | openjdk: Enhance Certificate Checking (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-27135 | nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-40200 | musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.8 | CVE-2026-22184 | zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility |
| HIGH | 7.8 | CVE-2026-22801 | libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API |
| HIGH | 7.8 | CVE-2026-25210 | libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation |
| HIGH | 7.5 | CVE-2019-16869 | netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers |
| HIGH | 7.5 | CVE-2021-22569 | protobuf-java: potential DoS in the parsing procedure for binary data |
| HIGH | 7.5 | CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function |
| HIGH | 7.5 | CVE-2022-3509 | protobuf-java: Textformat parsing issue leads to DoS |
| HIGH | 7.5 | CVE-2022-3510 | protobuf-java: Message-Type Extensions parsing issue leads to DoS |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2023-1370 | json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) |
| HIGH | 7.5 | CVE-2023-28118 | kaml has potential denial of service while parsing input with anchors and aliases |
| HIGH | 7.5 | CVE-2023-34054 | Reactor Netty HTTP Server denial of service vulnerability |
| HIGH | 7.5 | CVE-2023-34062 | reactor-netty-http: directory traversal vulnerability |
| HIGH | 7.5 | CVE-2023-34455 | snappy-java: Unchecked chunk length leads to DoS |
| HIGH | 7.5 | CVE-2023-43642 | snappy-java: Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact |
| HIGH | 7.5 | CVE-2023-52428 | nimbus-jose-jwt: large JWE p2c header value causes Denial of Service |
| HIGH | 7.5 | CVE-2024-21634 | ion-java: ion-java: Ion Java StackOverflow vulnerability |
| HIGH | 7.5 | CVE-2024-47072 | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream |
| HIGH | 7.5 | CVE-2024-57699 | json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370) |
| HIGH | 7.5 | CVE-2024-7254 | protobuf: StackOverflow vulnerability in Protocol Buffers |
| HIGH | 7.5 | CVE-2025-24970 | io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine |
| HIGH | 7.5 | CVE-2025-27553 | apache-commons-vfs: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT |
| HIGH | 7.5 | CVE-2025-41249 | org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2025-69421 | openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing |
| HIGH | 7.5 | CVE-2026-2100 | p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters |
| HIGH | 7.5 | CVE-2026-28388 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing |
| HIGH | 7.5 | CVE-2026-28389 | openssl: OpenSSL: Denial of Service vulnerability in CMS processing |
| HIGH | 7.5 | CVE-2026-28390 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-41849 | spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL |
| HIGH | 7.5 | CVE-2026-41850 | spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42440 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-45186 | libexpat: denial of service via crafted XML input |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| HIGH | 7.2 | CVE-2024-13009 | jetty-server: Jetty: Gzip Request Body Buffer Corruption |
| HIGH | 7.1 | CVE-2026-22695 | libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read |
| MEDIUM | 7.5 | CVE-2025-27817 | org.apache.kafka: Kafka Client Arbitrary File Read SSRF |
| MEDIUM | 7.5 | CVE-2025-7962 | com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability |
| MEDIUM | 6.9 | CVE-2026-56132 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow |
| MEDIUM | 6.9 | CVE-2026-56403 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts |
| MEDIUM | 6.9 | CVE-2026-56404 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding |
| MEDIUM | 6.9 | CVE-2026-56405 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2024-29131 | commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator() |
| MEDIUM | 6.5 | CVE-2024-29133 | commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2025-67735 | netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.1 | CVE-2025-22227 | io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects |
| MEDIUM | 5.9 | CVE-2023-34453 | snappy-java: Integer overflow in shuffle leads to DoS |
| MEDIUM | 5.9 | CVE-2023-34454 | snappy-java: Integer overflow in compress leads to DoS |
| MEDIUM | 5.9 | CVE-2024-8184 | org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| MEDIUM | 5.9 | CVE-2026-28208 | com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.9 | CVE-2026-50219 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| MEDIUM | 5.9 | CVE-2026-56412 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2022-3171 | protobuf-java: timeout in parser leads to DoS |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2023-2976 | guava: insecure temporary directory creation |
| MEDIUM | 5.5 | CVE-2024-35255 | azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity |
| MEDIUM | 5.5 | CVE-2024-47535 | netty: Denial of Service attack on windows app using Netty |
| MEDIUM | 5.5 | CVE-2024-58251 | In netstat in BusyBox through 1.37.0, local users can launch of networ ... |
| MEDIUM | 5.5 | CVE-2024-8176 | libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat |
| MEDIUM | 5.5 | CVE-2025-21587 | openjdk: Better TLS connection support (Oracle CPU 2025-04) |
| MEDIUM | 5.5 | CVE-2025-25193 | netty: Denial of Service attack on windows app using Netty |
| MEDIUM | 5.5 | CVE-2025-30474 | Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ... |
| MEDIUM | 5.5 | CVE-2025-30698 | openjdk: Enhance Buffered Image handling (Oracle CPU 2025-04) |
| MEDIUM | 5.5 | CVE-2025-30754 | openjdk: Enhance TLS protocol support (Oracle CPU 2025-07) |
| MEDIUM | 5.5 | CVE-2025-31344 | giflib: The giflib open-source component has a buffer overflow vulnerability |
| MEDIUM | 5.5 | CVE-2025-31498 | c-ares: c-ares has a use-after-free in read_answers() |
| MEDIUM | 5.5 | CVE-2025-4947 | libcurl: curl: QUIC certificate check skip with wolfSSL |
| MEDIUM | 5.5 | CVE-2025-4949 | org.eclipse.jgit: XXE vulnerability in Eclipse JGit |
| MEDIUM | 5.5 | CVE-2025-5025 | curl: libcurl: QUIC Certificate Pinning Bypass |
| MEDIUM | 5.5 | CVE-2025-53057 | openjdk: Enhance certificate handling (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-53066 | openjdk: Enhance Path Factories (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-5399 | curl: libcurl: WebSocket endless loop |
| MEDIUM | 5.5 | CVE-2025-58057 | netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack |
| MEDIUM | 5.5 | CVE-2025-62408 | c-ares: c-ares: Denial of Service due to query termination after maximum attempts |
| MEDIUM | 5.5 | CVE-2025-64505 | libpng: LIBPNG heap buffer overflow via malformed palette index |
| MEDIUM | 5.5 | CVE-2025-64506 | libpng: LIBPNG heap buffer over-read |
| MEDIUM | 5.5 | CVE-2025-68161 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification |
| MEDIUM | 5.5 | CVE-2025-69419 | openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing |
| MEDIUM | 5.5 | CVE-2025-9086 | curl: libcurl: Curl out of bounds read for cookie path |
| MEDIUM | 5.5 | CVE-2025-9230 | openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap |
| MEDIUM | 5.5 | CVE-2025-9231 | openssl: Timing side-channel in SM2 algorithm on 64 bit ARM |
| MEDIUM | 5.5 | CVE-2026-21925 | openjdk: Improve JMX connections (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-21933 | openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-27171 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions |
| MEDIUM | 5.5 | CVE-2026-31790 | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key |
| MEDIUM | 5.5 | CVE-2026-32776 | libexpat: libexpat: Denial of Service due to NULL pointer dereference |
| MEDIUM | 5.5 | CVE-2026-32777 | libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing |
| MEDIUM | 5.5 | CVE-2026-32778 | libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition |
| MEDIUM | 5.5 | CVE-2026-33416 | libpng: libpng: Arbitrary code execution due to use-after-free vulnerability |
| MEDIUM | 5.5 | CVE-2026-33636 | libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-56131 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking |
| MEDIUM | 5.5 | CVE-2026-56406 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer |
| MEDIUM | 5.5 | CVE-2026-56407 | libexpat: libexpat: Arbitrary code execution due to integer overflow |
| MEDIUM | 5.5 | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... |
| MEDIUM | 5.5 | CVE-2026-56410 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. |
| MEDIUM | 5.5 | CVE-2026-56411 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-6042 | musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.3 | CVE-2020-29582 | kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure |
| MEDIUM | 5.3 | CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints |
| MEDIUM | 5.3 | CVE-2022-24329 | kotlin: Not possible to lock dependencies for Multiplatform Gradle Projects |
| MEDIUM | 5.3 | CVE-2023-26048 | jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() |
| MEDIUM | 5.3 | CVE-2023-40167 | jetty: Improper validation of HTTP/1 content-length |
| MEDIUM | 5.3 | CVE-2024-9823 | org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter |
| MEDIUM | 5.3 | CVE-2025-31672 | org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-41851 | Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| MEDIUM | 4.4 | CVE-2026-34757 | libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability |
| MEDIUM | 4.3 | CVE-2021-39194 | Improper Handling of Missing Values in kaml |
| MEDIUM | 4.3 | CVE-2024-38808 | spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| MEDIUM | 3.7 | CVE-2024-6763 | org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority |
| LOW | 3.9 | GHSA-58qw-p7qm-5rvh | Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.7 | CVE-2026-41848 | spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher |
| LOW | 3.7 | CVE-2026-41852 | spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation |
| LOW | 3.5 | CVE-2023-36479 | jetty: Improper addition of quotation marks to user inputs in CgiServlet |
| LOW | 3.3 | CVE-2020-8908 | guava: local information disclosure via temporary directory created with unsafe permissions |
| LOW | 3.3 | CVE-2024-23454 | Apache Hadoop: Temporary File Local Information Disclosure |
| LOW | 3.3 | CVE-2025-27496 | Snowflake JDBC Driver client-side encryption key in DEBUG logs |
| LOW | 3.3 | CVE-2025-46394 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ... |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.7 | CVE-2022-2047 | jetty-http: improver hostname input handling |
| LOW | 2.5 | CVE-2026-24515 | libexpat: libexpat null pointer dereference |
| LOW | 2.4 | CVE-2023-26049 | jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies |
| LOW | 2.0 | CVE-2025-10148 | curl: predictable WebSocket mask |
| LOW | 2.0 | CVE-2025-13151 | libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string |
| LOW | 2.0 | CVE-2025-15468 | openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling |
| LOW | 2.0 | CVE-2025-58056 | netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions |
| LOW | 2.0 | CVE-2025-66199 | openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression |
| LOW | 2.0 | CVE-2025-66453 | Rhino is an open-source implementation of JavaScript written entirely ... |
| LOW | 2.0 | CVE-2025-68160 | openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter |
| LOW | 2.0 | CVE-2025-69418 | openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls |
| LOW | 2.0 | CVE-2025-69420 | openssl: OpenSSL: Denial of Service via malformed TimeStamp Response |
| LOW | 2.0 | CVE-2025-9232 | openssl: Out-of-bounds read in HTTP client no_proxy handling |
| LOW | 2.0 | CVE-2026-22795 | openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing |
| LOW | 2.0 | CVE-2026-22796 | openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification |
| LOW | 2.0 | CVE-2026-32588 | Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes |
| LOW | 2.0 | CVE-2026-41080 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
↑2.11.0
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 7 |
| HIGH | 90 |
| MEDIUM | 110 |
| LOW | 33 |
Details for version: 2.11.0
CVE Details for Version: 2.11.0
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.8 | CVE-2025-54988 | org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA |
| CRITICAL | 9.8 | CVE-2026-31789 | openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing |
| CRITICAL | 9.8 | CVE-2026-42027 | Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest |
| CRITICAL | 9.5 | CVE-2025-30065 | org.apache.parquet/parquet-avro: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata |
| CRITICAL | 9.5 | CVE-2025-66516 | tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected |
| CRITICAL | 9.1 | CVE-2026-40682 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: XML External Entity (XXE) vulnerability via crafted dictionary parsing |
| CRITICAL | 8.1 | CVE-2026-8178 | Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading |
| HIGH | 8.9 | CVE-2024-25638 | dnsjava: Improper response validation allowing DNSSEC bypass |
| HIGH | 8.8 | CVE-2025-23015 | org.apache.cassandra:cassandra-all: Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions |
| HIGH | 8.8 | CVE-2025-48734 | commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.2 | CVE-2025-49146 | pgjdbc: pgjdbc insecure authentication in channel binding |
| HIGH | 8.1 | CVE-2025-59250 | JDBC Driver for SQL Server has improper input validation issue |
| HIGH | 8.1 | CVE-2026-25646 | libpng: LIBPNG has a heap buffer overflow in png_set_quantize |
| HIGH | 8.1 | CVE-2026-28387 | openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2024-12797 | openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-15467 | openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing |
| HIGH | 8.0 | CVE-2025-23083 | nodejs: Node.js Worker Thread Exposure via Diagnostics Channel |
| HIGH | 8.0 | CVE-2025-30749 | openjdk: Better Glyph drawing (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-46762 | org.apache.parquet/parquet-avro: Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata |
| HIGH | 8.0 | CVE-2025-50059 | openjdk: Improve HTTP client header handling (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-50106 | openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-59375 | firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing |
| HIGH | 8.0 | CVE-2025-64720 | libpng: LIBPNG buffer overflow |
| HIGH | 8.0 | CVE-2025-65018 | libpng: LIBPNG heap buffer overflow |
| HIGH | 8.0 | CVE-2025-66293 | libpng: LIBPNG out-of-bounds read in png_image_read_composite |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-21932 | openjdk: Enhance Handling of URIs (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-21945 | openjdk: Enhance Certificate Checking (Oracle CPU 2026-01) |
| HIGH | 8.0 | CVE-2026-27135 | nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination |
| HIGH | 8.0 | CVE-2026-33630 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-40200 | musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort |
| HIGH | 8.0 | CVE-2026-54291 | org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade |
| HIGH | 8.0 | CVE-2026-56408 | libexpat before 2.8.2 has an integer overflow in copyString. |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.8 | CVE-2025-24789 | Snowflake JDBC allows an untrusted search path on Windows |
| HIGH | 7.8 | CVE-2026-22184 | zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility |
| HIGH | 7.8 | CVE-2026-22801 | libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API |
| HIGH | 7.8 | CVE-2026-25210 | libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation |
| HIGH | 7.5 | CVE-2019-16869 | netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers |
| HIGH | 7.5 | CVE-2021-22569 | protobuf-java: potential DoS in the parsing procedure for binary data |
| HIGH | 7.5 | CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function |
| HIGH | 7.5 | CVE-2022-3509 | protobuf-java: Textformat parsing issue leads to DoS |
| HIGH | 7.5 | CVE-2022-3510 | protobuf-java: Message-Type Extensions parsing issue leads to DoS |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2023-1370 | json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) |
| HIGH | 7.5 | CVE-2023-28118 | kaml has potential denial of service while parsing input with anchors and aliases |
| HIGH | 7.5 | CVE-2023-34054 | Reactor Netty HTTP Server denial of service vulnerability |
| HIGH | 7.5 | CVE-2023-34062 | reactor-netty-http: directory traversal vulnerability |
| HIGH | 7.5 | CVE-2023-34455 | snappy-java: Unchecked chunk length leads to DoS |
| HIGH | 7.5 | CVE-2023-43642 | snappy-java: Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact |
| HIGH | 7.5 | CVE-2023-52428 | nimbus-jose-jwt: large JWE p2c header value causes Denial of Service |
| HIGH | 7.5 | CVE-2024-21634 | ion-java: ion-java: Ion Java StackOverflow vulnerability |
| HIGH | 7.5 | CVE-2024-47072 | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream |
| HIGH | 7.5 | CVE-2024-57699 | json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370) |
| HIGH | 7.5 | CVE-2024-7254 | protobuf: StackOverflow vulnerability in Protocol Buffers |
| HIGH | 7.5 | CVE-2025-24970 | io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine |
| HIGH | 7.5 | CVE-2025-27553 | apache-commons-vfs: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT |
| HIGH | 7.5 | CVE-2025-41249 | org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2025-69421 | openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing |
| HIGH | 7.5 | CVE-2026-2100 | p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters |
| HIGH | 7.5 | CVE-2026-28388 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing |
| HIGH | 7.5 | CVE-2026-28389 | openssl: OpenSSL: Denial of Service vulnerability in CMS processing |
| HIGH | 7.5 | CVE-2026-28390 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-41849 | spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL |
| HIGH | 7.5 | CVE-2026-41850 | spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42440 | org.apache.opennlp/opennlp-tools: Apache OpenNLP: Denial of Service via unbounded array allocation in crafted model files |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-45186 | libexpat: denial of service via crafted XML input |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| HIGH | 7.2 | CVE-2024-13009 | jetty-server: Jetty: Gzip Request Body Buffer Corruption |
| HIGH | 7.1 | CVE-2026-22695 | libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read |
| HIGH | 7.0 | CVE-2025-26519 | musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write ... |
| MEDIUM | 7.5 | CVE-2025-27817 | org.apache.kafka: Kafka Client Arbitrary File Read SSRF |
| MEDIUM | 7.5 | CVE-2025-7962 | com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability |
| MEDIUM | 6.9 | CVE-2026-56132 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow |
| MEDIUM | 6.9 | CVE-2026-56403 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts |
| MEDIUM | 6.9 | CVE-2026-56404 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding |
| MEDIUM | 6.9 | CVE-2026-56405 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2024-29131 | commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator() |
| MEDIUM | 6.5 | CVE-2024-29133 | commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2025-67735 | netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.1 | CVE-2025-22227 | io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects |
| MEDIUM | 5.9 | CVE-2023-34453 | snappy-java: Integer overflow in shuffle leads to DoS |
| MEDIUM | 5.9 | CVE-2023-34454 | snappy-java: Integer overflow in compress leads to DoS |
| MEDIUM | 5.9 | CVE-2024-27137 | org.apache.cassandra:cassandra-all: Apache Cassandra: unrestricted deserialization of JMX authentication credentials |
| MEDIUM | 5.9 | CVE-2024-8184 | org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| MEDIUM | 5.9 | CVE-2026-28208 | com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.9 | CVE-2026-50219 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| MEDIUM | 5.9 | CVE-2026-56412 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2022-3171 | protobuf-java: timeout in parser leads to DoS |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2023-2976 | guava: insecure temporary directory creation |
| MEDIUM | 5.5 | CVE-2024-12133 | libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS |
| MEDIUM | 5.5 | CVE-2024-35255 | azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity |
| MEDIUM | 5.5 | CVE-2024-47535 | netty: Denial of Service attack on windows app using Netty |
| MEDIUM | 5.5 | CVE-2024-58251 | In netstat in BusyBox through 1.37.0, local users can launch of networ ... |
| MEDIUM | 5.5 | CVE-2024-8176 | libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat |
| MEDIUM | 5.5 | CVE-2025-21502 | openjdk: Enhance array handling (Oracle CPU 2025-01) |
| MEDIUM | 5.5 | CVE-2025-21587 | openjdk: Better TLS connection support (Oracle CPU 2025-04) |
| MEDIUM | 5.5 | CVE-2025-25193 | netty: Denial of Service attack on windows app using Netty |
| MEDIUM | 5.5 | CVE-2025-30474 | Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ... |
| MEDIUM | 5.5 | CVE-2025-30698 | openjdk: Enhance Buffered Image handling (Oracle CPU 2025-04) |
| MEDIUM | 5.5 | CVE-2025-30754 | openjdk: Enhance TLS protocol support (Oracle CPU 2025-07) |
| MEDIUM | 5.5 | CVE-2025-31344 | giflib: The giflib open-source component has a buffer overflow vulnerability |
| MEDIUM | 5.5 | CVE-2025-31498 | c-ares: c-ares has a use-after-free in read_answers() |
| MEDIUM | 5.5 | CVE-2025-4947 | libcurl: curl: QUIC certificate check skip with wolfSSL |
| MEDIUM | 5.5 | CVE-2025-4949 | org.eclipse.jgit: XXE vulnerability in Eclipse JGit |
| MEDIUM | 5.5 | CVE-2025-5025 | curl: libcurl: QUIC Certificate Pinning Bypass |
| MEDIUM | 5.5 | CVE-2025-53057 | openjdk: Enhance certificate handling (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-53066 | openjdk: Enhance Path Factories (Oracle CPU 2025-10) |
| MEDIUM | 5.5 | CVE-2025-5399 | curl: libcurl: WebSocket endless loop |
| MEDIUM | 5.5 | CVE-2025-58057 | netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack |
| MEDIUM | 5.5 | CVE-2025-62408 | c-ares: c-ares: Denial of Service due to query termination after maximum attempts |
| MEDIUM | 5.5 | CVE-2025-64505 | libpng: LIBPNG heap buffer overflow via malformed palette index |
| MEDIUM | 5.5 | CVE-2025-64506 | libpng: LIBPNG heap buffer over-read |
| MEDIUM | 5.5 | CVE-2025-68161 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification |
| MEDIUM | 5.5 | CVE-2025-69419 | openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing |
| MEDIUM | 5.5 | CVE-2025-9086 | curl: libcurl: Curl out of bounds read for cookie path |
| MEDIUM | 5.5 | CVE-2025-9230 | openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap |
| MEDIUM | 5.5 | CVE-2025-9231 | openssl: Timing side-channel in SM2 algorithm on 64 bit ARM |
| MEDIUM | 5.5 | CVE-2026-21925 | openjdk: Improve JMX connections (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-21933 | openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01) |
| MEDIUM | 5.5 | CVE-2026-27171 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions |
| MEDIUM | 5.5 | CVE-2026-31790 | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key |
| MEDIUM | 5.5 | CVE-2026-32776 | libexpat: libexpat: Denial of Service due to NULL pointer dereference |
| MEDIUM | 5.5 | CVE-2026-32777 | libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing |
| MEDIUM | 5.5 | CVE-2026-32778 | libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition |
| MEDIUM | 5.5 | CVE-2026-33416 | libpng: libpng: Arbitrary code execution due to use-after-free vulnerability |
| MEDIUM | 5.5 | CVE-2026-33636 | libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-56131 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking |
| MEDIUM | 5.5 | CVE-2026-56406 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer |
| MEDIUM | 5.5 | CVE-2026-56407 | libexpat: libexpat: Arbitrary code execution due to integer overflow |
| MEDIUM | 5.5 | CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... |
| MEDIUM | 5.5 | CVE-2026-56410 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. |
| MEDIUM | 5.5 | CVE-2026-56411 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-6042 | musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.4 | CVE-2025-24860 | org.apache.cassandra:cassandra-all: Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions |
| MEDIUM | 5.3 | CVE-2020-29582 | kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure |
| MEDIUM | 5.3 | CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints |
| MEDIUM | 5.3 | CVE-2022-24329 | kotlin: Not possible to lock dependencies for Multiplatform Gradle Projects |
| MEDIUM | 5.3 | CVE-2023-26048 | jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() |
| MEDIUM | 5.3 | CVE-2023-40167 | jetty: Improper validation of HTTP/1 content-length |
| MEDIUM | 5.3 | CVE-2024-9823 | org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter |
| MEDIUM | 5.3 | CVE-2025-31672 | org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-41851 | Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation |
| MEDIUM | 5.3 | CVE-2026-45205 | commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 4.7 | CVE-2026-71497 | org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names |
| MEDIUM | 4.4 | CVE-2025-24790 | Snowflake JDBC uses insecure temporary credential cache file permissions |
| MEDIUM | 4.4 | CVE-2026-34757 | libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability |
| MEDIUM | 4.3 | CVE-2021-39194 | Improper Handling of Missing Values in kaml |
| MEDIUM | 4.3 | CVE-2024-38808 | spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| MEDIUM | 3.7 | CVE-2024-6763 | org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority |
| LOW | 3.9 | GHSA-58qw-p7qm-5rvh | Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.7 | CVE-2026-41848 | spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher |
| LOW | 3.7 | CVE-2026-41852 | spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation |
| LOW | 3.5 | CVE-2023-36479 | jetty: Improper addition of quotation marks to user inputs in CgiServlet |
| LOW | 3.3 | CVE-2020-8908 | guava: local information disclosure via temporary directory created with unsafe permissions |
| LOW | 3.3 | CVE-2024-23454 | Apache Hadoop: Temporary File Local Information Disclosure |
| LOW | 3.3 | CVE-2025-27496 | Snowflake JDBC Driver client-side encryption key in DEBUG logs |
| LOW | 3.3 | CVE-2025-46394 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ... |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.7 | CVE-2022-2047 | jetty-http: improver hostname input handling |
| LOW | 2.5 | CVE-2026-24515 | libexpat: libexpat null pointer dereference |
| LOW | 2.4 | CVE-2023-26049 | jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies |
| LOW | 2.0 | CVE-2024-11053 | curl: curl netrc password leak |
| LOW | 2.0 | CVE-2024-13176 | openssl: Timing side-channel in ECDSA signature computation |
| LOW | 2.0 | CVE-2025-0167 | When asked to use a `.netrc` file for credentials **and** to follow HT ... |
| LOW | 2.0 | CVE-2025-0665 | libcurl: Double Close of Eventfd in libcurl |
| LOW | 2.0 | CVE-2025-0725 | libcurl: Buffer Overflow in libcurl via zlib Integer Overflow |
| LOW | 2.0 | CVE-2025-10148 | curl: predictable WebSocket mask |
| LOW | 2.0 | CVE-2025-13151 | libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string |
| LOW | 2.0 | CVE-2025-15468 | openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling |
| LOW | 2.0 | CVE-2025-58056 | netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions |
| LOW | 2.0 | CVE-2025-66199 | openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression |
| LOW | 2.0 | CVE-2025-66453 | Rhino is an open-source implementation of JavaScript written entirely ... |
| LOW | 2.0 | CVE-2025-68160 | openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter |
| LOW | 2.0 | CVE-2025-69418 | openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls |
| LOW | 2.0 | CVE-2025-69420 | openssl: OpenSSL: Denial of Service via malformed TimeStamp Response |
| LOW | 2.0 | CVE-2025-9232 | openssl: Out-of-bounds read in HTTP client no_proxy handling |
| LOW | 2.0 | CVE-2026-22795 | openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing |
| LOW | 2.0 | CVE-2026-22796 | openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification |
| LOW | 2.0 | CVE-2026-32588 | Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes |
| LOW | 2.0 | CVE-2026-41080 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
↑2.10.0
Severity Breakdown
| Severity | Count |
|---|---|
| CRITICAL | 9 |
| HIGH | 83 |
| MEDIUM | 94 |
| LOW | 35 |
Details for version: 2.10.0
CVE Details for Version: 2.10.0
| Severity | Score | CVE ID | Description |
|---|---|---|---|
| CRITICAL | 9.8 | CVE-2021-37404 | hadoop-hdfs: Heap buffer overflow in Apache Hadoop libhdfs |
| CRITICAL | 9.8 | CVE-2022-25168 | hadoop: Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTar |
| CRITICAL | 9.8 | CVE-2024-47561 | apache-avro: Schema parsing may trigger Remote Code Execution (RCE) |
| CRITICAL | 9.8 | CVE-2025-54988 | org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA |
| CRITICAL | 9.8 | CVE-2026-31789 | openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing |
| CRITICAL | 9.5 | CVE-2025-30065 | org.apache.parquet/parquet-avro: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata |
| CRITICAL | 9.5 | CVE-2025-66516 | tika-core: tika-parsers: tika-parser-pdf-module: Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected |
| CRITICAL | 9.1 | CVE-2023-44981 | zookeeper: Authorization Bypass in Apache ZooKeeper |
| CRITICAL | 8.1 | CVE-2026-8178 | Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading |
| HIGH | 8.8 | CVE-2020-9492 | hadoop: WebHDFS client might send SPNEGO authorization header |
| HIGH | 8.8 | CVE-2025-23015 | org.apache.cassandra:cassandra-all: Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions |
| HIGH | 8.8 | CVE-2025-48734 | commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default |
| HIGH | 8.7 | CVE-2026-35554 | Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management |
| HIGH | 8.7 | CVE-2026-45674 | netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation |
| HIGH | 8.7 | CVE-2026-47691 | io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records |
| HIGH | 8.1 | CVE-2025-59250 | JDBC Driver for SQL Server has improper input validation issue |
| HIGH | 8.1 | CVE-2026-25646 | libpng: LIBPNG has a heap buffer overflow in png_set_quantize |
| HIGH | 8.1 | CVE-2026-28387 | openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication |
| HIGH | 8.1 | CVE-2026-44249 | netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation |
| HIGH | 8.1 | CVE-2026-54512 | jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass |
| HIGH | 8.1 | CVE-2026-54513 | jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution |
| HIGH | 8.0 | CVE-2024-12797 | openssl: RFC7250 handshakes with unauthenticated servers don't abort as expected |
| HIGH | 8.0 | CVE-2025-12183 | lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure |
| HIGH | 8.0 | CVE-2025-15467 | openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing |
| HIGH | 8.0 | CVE-2025-23083 | nodejs: Node.js Worker Thread Exposure via Diagnostics Channel |
| HIGH | 8.0 | CVE-2025-30749 | openjdk: Better Glyph drawing (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-46762 | org.apache.parquet/parquet-avro: Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata |
| HIGH | 8.0 | CVE-2025-50059 | openjdk: Improve HTTP client header handling (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-50106 | openjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07) |
| HIGH | 8.0 | CVE-2025-52999 | com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError |
| HIGH | 8.0 | CVE-2025-59375 | firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing |
| HIGH | 8.0 | CVE-2025-64720 | libpng: LIBPNG buffer overflow |
| HIGH | 8.0 | CVE-2025-65018 | libpng: LIBPNG heap buffer overflow |
| HIGH | 8.0 | CVE-2025-66293 | libpng: LIBPNG out-of-bounds read in png_image_read_composite |
| HIGH | 8.0 | CVE-2025-66566 | lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing |
| HIGH | 8.0 | CVE-2026-10050 | jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision |
| HIGH | 8.0 | CVE-2026-33871 | netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood |
| HIGH | 8.0 | CVE-2026-40200 | musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort |
| HIGH | 8.0 | CVE-2026-56745 | netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec |
| HIGH | 8.0 | CVE-2026-59901 | io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
| HIGH | 8.0 | GHSA-r7wm-3cxj-wff9 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) |
| HIGH | 7.8 | CVE-2025-24789 | Snowflake JDBC allows an untrusted search path on Windows |
| HIGH | 7.8 | CVE-2026-22184 | zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility |
| HIGH | 7.8 | CVE-2026-22801 | libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API |
| HIGH | 7.8 | CVE-2026-25210 | libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation |
| HIGH | 7.5 | CVE-2017-5637 | zookeeper: Incorrect input validation with wchp/wchc four letter words |
| HIGH | 7.5 | CVE-2018-8012 | zookeeper: No authentication or authorization is enforced when a server joins a quorum |
| HIGH | 7.5 | CVE-2019-16869 | netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers |
| HIGH | 7.5 | CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function |
| HIGH | 7.5 | CVE-2022-40150 | jettison: memory exhaustion via user-supplied XML or JSON data |
| HIGH | 7.5 | CVE-2022-41404 | org.ini4j: unspecified DoS |
| HIGH | 7.5 | CVE-2022-45685 | jettison: stack overflow in JSONObject() allows attackers to cause a Denial of Service (DoS) via crafted JSON data |
| HIGH | 7.5 | CVE-2022-45693 | jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos |
| HIGH | 7.5 | CVE-2023-1370 | json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) |
| HIGH | 7.5 | CVE-2023-1436 | jettison: Uncontrolled Recursion in JSONArray |
| HIGH | 7.5 | CVE-2023-28118 | kaml has potential denial of service while parsing input with anchors and aliases |
| HIGH | 7.5 | CVE-2023-34054 | Reactor Netty HTTP Server denial of service vulnerability |
| HIGH | 7.5 | CVE-2023-34062 | reactor-netty-http: directory traversal vulnerability |
| HIGH | 7.5 | CVE-2023-52428 | nimbus-jose-jwt: large JWE p2c header value causes Denial of Service |
| HIGH | 7.5 | CVE-2024-21634 | ion-java: ion-java: Ion Java StackOverflow vulnerability |
| HIGH | 7.5 | CVE-2024-47072 | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream |
| HIGH | 7.5 | CVE-2024-57699 | json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370) |
| HIGH | 7.5 | CVE-2024-7254 | protobuf: StackOverflow vulnerability in Protocol Buffers |
| HIGH | 7.5 | CVE-2025-24970 | io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine |
| HIGH | 7.5 | CVE-2025-27553 | apache-commons-vfs: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT |
| HIGH | 7.5 | CVE-2025-41249 | org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability |
| HIGH | 7.5 | CVE-2025-55163 | netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability |
| HIGH | 7.5 | CVE-2025-69421 | openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing |
| HIGH | 7.5 | CVE-2026-28388 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing |
| HIGH | 7.5 | CVE-2026-28389 | openssl: OpenSSL: Denial of Service vulnerability in CMS processing |
| HIGH | 7.5 | CVE-2026-28390 | openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing |
| HIGH | 7.5 | CVE-2026-33870 | io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values |
| HIGH | 7.5 | CVE-2026-41254 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize |
| HIGH | 7.5 | CVE-2026-41849 | spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL |
| HIGH | 7.5 | CVE-2026-41850 | spring-framework: Spring Framework: Denial of Service via specially crafted SpEL expressions |
| HIGH | 7.5 | CVE-2026-42198 | jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication |
| HIGH | 7.5 | CVE-2026-42579 | netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement |
| HIGH | 7.5 | CVE-2026-42583 | netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder |
| HIGH | 7.5 | CVE-2026-42587 | netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression |
| HIGH | 7.5 | CVE-2026-45186 | libexpat: denial of service via crafted XML input |
| HIGH | 7.5 | CVE-2026-45416 | netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake |
| HIGH | 7.5 | CVE-2026-45799 | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service |
| HIGH | 7.5 | CVE-2026-50010 | netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass |
| HIGH | 7.5 | CVE-2026-54399 | org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers |
| HIGH | 7.5 | CVE-2026-55831 | io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing |
| HIGH | 7.5 | CVE-2026-55833 | netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification |
| HIGH | 7.5 | CVE-2026-56819 | io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak |
| HIGH | 7.4 | CVE-2026-2332 | org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing |
| HIGH | 7.3 | CVE-2026-42584 | netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion |
| HIGH | 7.2 | CVE-2024-13009 | jetty-server: Jetty: Gzip Request Body Buffer Corruption |
| HIGH | 7.1 | CVE-2026-22695 | libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read |
| HIGH | 7.0 | CVE-2025-26519 | musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write ... |
| MEDIUM | 7.5 | CVE-2025-27817 | org.apache.kafka: Kafka Client Arbitrary File Read SSRF |
| MEDIUM | 7.5 | CVE-2025-7962 | com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability |
| MEDIUM | 7.5 | CVE-2026-50193 | jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing |
| MEDIUM | 6.8 | CVE-2026-45673 | netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs |
| MEDIUM | 6.5 | CVE-2022-40149 | jettison: parser crash by stackoverflow |
| MEDIUM | 6.5 | CVE-2024-29131 | commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator() |
| MEDIUM | 6.5 | CVE-2024-29133 | commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree |
| MEDIUM | 6.5 | CVE-2024-9681 | curl: HSTS subdomain overwrites parent cache entry |
| MEDIUM | 6.5 | CVE-2025-48924 | commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang |
| MEDIUM | 6.5 | CVE-2025-67735 | netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection |
| MEDIUM | 6.5 | CVE-2026-42580 | netty: Netty: Request smuggling via chunk size parser integer overflow |
| MEDIUM | 6.5 | CVE-2026-42585 | netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing |
| MEDIUM | 6.5 | CVE-2026-56746 | io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header |
| MEDIUM | 6.5 | CVE-2026-59888 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records |
| MEDIUM | 6.5 | CVE-2026-59949 | LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges |
| MEDIUM | 6.1 | CVE-2025-22227 | io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects |
| MEDIUM | 5.9 | CVE-2019-0201 | zookeeper: Information disclosure in Apache ZooKeeper |
| MEDIUM | 5.9 | CVE-2024-27137 | org.apache.cassandra:cassandra-all: Apache Cassandra: unrestricted deserialization of JMX authentication credentials |
| MEDIUM | 5.9 | CVE-2024-43382 | Snowflake JDBC Security Advisory |
| MEDIUM | 5.9 | CVE-2024-8184 | org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| MEDIUM | 5.9 | CVE-2026-28208 | com.github.junrar/junrar: Junrar: Remote code execution via path traversal when extracting crafted RAR archives |
| MEDIUM | 5.9 | CVE-2026-41245 | junrar: Junrar: Arbitrary file write via path traversal when extracting crafted RAR archives. |
| MEDIUM | 5.8 | CVE-2024-58103 | Wire has Uncontrolled Recursion on Nested Groups |
| MEDIUM | 5.8 | CVE-2025-53864 | com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT |
| MEDIUM | 5.8 | CVE-2026-42581 | netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers |
| MEDIUM | 5.7 | CVE-2026-59921 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| MEDIUM | 5.5 | CVE-2023-2976 | guava: insecure temporary directory creation |
| MEDIUM | 5.5 | CVE-2024-12133 | libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS |
| MEDIUM | 5.5 | CVE-2024-21208 | JDK: HTTP client improper handling of maxHeaderSize (8328286) |
| MEDIUM | 5.5 | CVE-2024-21210 | JDK: Array indexing integer overflow (8328544) |
| MEDIUM | 5.5 | CVE-2024-21217 | JDK: Unbounded allocation leads to out-of-memory error (8331446) |
| MEDIUM | 5.5 | CVE-2024-21235 | JDK: Integer conversion error leads to incorrect range check (8332644) |
| MEDIUM | 5.5 | CVE-2024-35255 | azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity |
| MEDIUM | 5.5 | CVE-2024-47535 | netty: Denial of Service attack on windows app using Netty |
| MEDIUM | 5.5 | CVE-2024-50602 | libexpat: expat: DoS via XML_ResumeParser |
| MEDIUM | 5.5 | CVE-2024-58251 | In netstat in BusyBox through 1.37.0, local users can launch of networ ... |
| MEDIUM | 5.5 | CVE-2024-8176 | libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat |
| MEDIUM | 5.5 | CVE-2025-21502 | openjdk: Enhance array handling (Oracle CPU 2025-01) |
| MEDIUM | 5.5 | CVE-2025-21587 | openjdk: Better TLS connection support (Oracle CPU 2025-04) |
| MEDIUM | 5.5 | CVE-2025-25193 | netty: Denial of Service attack on windows app using Netty |
| MEDIUM | 5.5 | CVE-2025-30474 | Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ... |
| MEDIUM | 5.5 | CVE-2025-30698 | openjdk: Enhance Buffered Image handling (Oracle CPU 2025-04) |
| MEDIUM | 5.5 | CVE-2025-30754 | openjdk: Enhance TLS protocol support (Oracle CPU 2025-07) |
| MEDIUM | 5.5 | CVE-2025-4947 | libcurl: curl: QUIC certificate check skip with wolfSSL |
| MEDIUM | 5.5 | CVE-2025-4949 | org.eclipse.jgit: XXE vulnerability in Eclipse JGit |
| MEDIUM | 5.5 | CVE-2025-5025 | curl: libcurl: QUIC Certificate Pinning Bypass |
| MEDIUM | 5.5 | CVE-2025-5399 | curl: libcurl: WebSocket endless loop |
| MEDIUM | 5.5 | CVE-2025-58057 | netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack |
| MEDIUM | 5.5 | CVE-2025-64505 | libpng: LIBPNG heap buffer overflow via malformed palette index |
| MEDIUM | 5.5 | CVE-2025-64506 | libpng: LIBPNG heap buffer over-read |
| MEDIUM | 5.5 | CVE-2025-68161 | Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification |
| MEDIUM | 5.5 | CVE-2025-69419 | openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing |
| MEDIUM | 5.5 | CVE-2025-9086 | curl: libcurl: Curl out of bounds read for cookie path |
| MEDIUM | 5.5 | CVE-2025-9230 | openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap |
| MEDIUM | 5.5 | CVE-2025-9231 | openssl: Timing side-channel in SM2 algorithm on 64 bit ARM |
| MEDIUM | 5.5 | CVE-2026-27171 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions |
| MEDIUM | 5.5 | CVE-2026-31790 | openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key |
| MEDIUM | 5.5 | CVE-2026-32776 | libexpat: libexpat: Denial of Service due to NULL pointer dereference |
| MEDIUM | 5.5 | CVE-2026-32777 | libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing |
| MEDIUM | 5.5 | CVE-2026-32778 | libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition |
| MEDIUM | 5.5 | CVE-2026-33416 | libpng: libpng: Arbitrary code execution due to use-after-free vulnerability |
| MEDIUM | 5.5 | CVE-2026-33636 | libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion |
| MEDIUM | 5.5 | CVE-2026-34477 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification |
| MEDIUM | 5.5 | CVE-2026-34478 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames |
| MEDIUM | 5.5 | CVE-2026-34480 | org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging |
| MEDIUM | 5.5 | CVE-2026-59898 | io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
| MEDIUM | 5.5 | CVE-2026-59899 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
| MEDIUM | 5.5 | CVE-2026-59900 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 |
| MEDIUM | 5.5 | CVE-2026-6042 | musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv |
| MEDIUM | 5.5 | GHSA-72hv-8253-57qq | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| MEDIUM | 5.4 | CVE-2025-24860 | org.apache.cassandra:cassandra-all: Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions |
| MEDIUM | 5.3 | CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints |
| MEDIUM | 5.3 | CVE-2023-26048 | jetty-server: OutOfMemoryError for large multipart without filename read via request.getParameter() |
| MEDIUM | 5.3 | CVE-2023-40167 | jetty: Improper validation of HTTP/1 content-length |
| MEDIUM | 5.3 | CVE-2024-9823 | org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter |
| MEDIUM | 5.3 | CVE-2025-31672 | org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names |
| MEDIUM | 5.3 | CVE-2026-33558 | Apache Kafka exposes sensitive information in its DEBUG logs |
| MEDIUM | 5.3 | CVE-2026-41417 | netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection |
| MEDIUM | 5.3 | CVE-2026-41851 | Spring Framework: Spring Framework: Denial of Service via unbounded cache growth in SpEL evaluation |
| MEDIUM | 5.3 | CVE-2026-45292 | opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage |
| MEDIUM | 5.3 | CVE-2026-47244 | netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams |
| MEDIUM | 5.3 | CVE-2026-48043 | netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak |
| MEDIUM | 5.3 | CVE-2026-50020 | netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder |
| MEDIUM | 5.3 | CVE-2026-50560 | netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling |
| MEDIUM | 5.3 | CVE-2026-54514 | jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution |
| MEDIUM | 5.3 | CVE-2026-54515 | jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified |
| MEDIUM | 5.3 | CVE-2026-6790 | jetty: Jetty: Improper Host header validation can lead to request routing issues |
| MEDIUM | 5.3 | CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| MEDIUM | 4.4 | CVE-2025-24790 | Snowflake JDBC uses insecure temporary credential cache file permissions |
| MEDIUM | 4.4 | CVE-2026-34757 | libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability |
| MEDIUM | 4.3 | CVE-2021-39194 | Improper Handling of Missing Values in kaml |
| MEDIUM | 4.3 | CVE-2024-38808 | spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression |
| MEDIUM | 4.0 | CVE-2026-45536 | netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling |
| MEDIUM | 3.7 | CVE-2024-6763 | org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority |
| LOW | 3.9 | GHSA-58qw-p7qm-5rvh | Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations |
| LOW | 3.7 | CVE-2025-11143 | org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing |
| LOW | 3.7 | CVE-2026-41848 | spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher |
| LOW | 3.7 | CVE-2026-41852 | spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation |
| LOW | 3.5 | CVE-2023-36479 | jetty: Improper addition of quotation marks to user inputs in CgiServlet |
| LOW | 3.3 | CVE-2020-8908 | guava: local information disclosure via temporary directory created with unsafe permissions |
| LOW | 3.3 | CVE-2024-23454 | Apache Hadoop: Temporary File Local Information Disclosure |
| LOW | 3.3 | CVE-2025-27496 | Snowflake JDBC Driver client-side encryption key in DEBUG logs |
| LOW | 3.3 | CVE-2025-46394 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ... |
| LOW | 3.3 | CVE-2026-3293 | snowflake-jdbc: snowflake-jdbc: Denial of Service via inefficient regular expression processing |
| LOW | 2.7 | CVE-2022-2047 | jetty-http: improver hostname input handling |
| LOW | 2.5 | CVE-2026-24515 | libexpat: libexpat null pointer dereference |
| LOW | 2.4 | CVE-2023-26049 | jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies |
| LOW | 2.0 | CVE-2024-11053 | curl: curl netrc password leak |
| LOW | 2.0 | CVE-2024-13176 | openssl: Timing side-channel in ECDSA signature computation |
| LOW | 2.0 | CVE-2024-21211 | JDK: Compiler unspecified vulnerability (CPU Oct 2024) |
| LOW | 2.0 | CVE-2024-9143 | openssl: Low-level invalid GF(2^m) parameters lead to OOB memory access |
| LOW | 2.0 | CVE-2025-0167 | When asked to use a `.netrc` file for credentials **and** to follow HT ... |
| LOW | 2.0 | CVE-2025-0665 | libcurl: Double Close of Eventfd in libcurl |
| LOW | 2.0 | CVE-2025-0725 | libcurl: Buffer Overflow in libcurl via zlib Integer Overflow |
| LOW | 2.0 | CVE-2025-10148 | curl: predictable WebSocket mask |
| LOW | 2.0 | CVE-2025-13151 | libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string |
| LOW | 2.0 | CVE-2025-15468 | openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling |
| LOW | 2.0 | CVE-2025-58056 | netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions |
| LOW | 2.0 | CVE-2025-66199 | openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression |
| LOW | 2.0 | CVE-2025-66453 | Rhino is an open-source implementation of JavaScript written entirely ... |
| LOW | 2.0 | CVE-2025-68160 | openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter |
| LOW | 2.0 | CVE-2025-69418 | openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls |
| LOW | 2.0 | CVE-2025-69420 | openssl: OpenSSL: Denial of Service via malformed TimeStamp Response |
| LOW | 2.0 | CVE-2025-9232 | openssl: Out-of-bounds read in HTTP client no_proxy handling |
| LOW | 2.0 | CVE-2026-22795 | openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing |
| LOW | 2.0 | CVE-2026-22796 | openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification |
| LOW | 2.0 | CVE-2026-32588 | Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes |
| LOW | 2.0 | CVE-2026-41080 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML |
| LOW | 2.0 | CVE-2026-42578 | netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |