Threats Tagged 'maven'
View all threats tagged with 'maven'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'maven'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-83557 is a deserialization vulnerability in FasterXML jackson-databind's default polymorphic type validator. The default validator denies polymorphic resolution only for nine specific unsafe base types but omits java.lang.Comparable, which is implemented by many classes. This omission allows applications using @JsonTypeInfo with Comparable-typed properties and no custom validator to accept type identifiers for any Comparable implementation, potentially enabling unsafe object creation such as java.io.File. The vulnerability affects multiple jackson-databind versions from 2.11.0 up to but excluding 3.2.2 in various ranges. No official patch or remediation guidance is provided in the input data. Join the discussion | CVE Database V5 | 09/28/2026, 20:44:25 UTC Added: 09/01/2026, 15:07:42 UTC |
0 CVE-2026-68497 is a high-severity denial of service vulnerability in FasterXML jackson-databind affecting versions >=2.0.0 <2.18.10, >=2.19.0 <2.21.6, >=2.22.0 <2.22.2, >=3.0.0 <3.1.6, and >=3.2.0 <3.2.2. It arises because the library deserializes JSON strings bound to javax.xml.datatype.Duration or XMLGregorianCalendar fields by passing them directly to JDK factory methods that parse numeric components with O(n²) complexity, without enforcing length limits on the string input. This allows an unauthenticated attacker to cause excessive CPU consumption and denial of service by submitting a specially crafted JSON string with very long numeric components. No polymorphic typing or special configuration is required to trigger this issue. Join the discussion | CVE Database V5 | 09/28/2026, 20:19:46 UTC Added: 09/11/2026, 16:02:55 UTC |
CVE-2026-19032 is a medium severity vulnerability in FasterXML jackson-databind that involves unsafe reflection via deserialization of java.nio.file.Path from untrusted JSON input. The vulnerability arises because the deserialization process resolves a URI scheme from attacker-controlled input and uses it to select a FileSystemProvider via Java's ServiceLoader mechanism without restricting schemes. While built-in providers do not perform network I/O or mounting, a third-party provider could potentially be triggered, leading to side effects. The issue affects multiple jackson-databind versions from 2.8.0 up to but excluding 3.2.2 in various version ranges. No direct code execution or data confidentiality impact is described, and the impact is bounded by the behavior of the selected FileSystemProvider. Join the discussion | CVE Database V5 | 09/28/2026, 20:19:19 UTC Added: 09/01/2026, 03:37:59 UTC |
0 CVE-2026-77310 is a Server-Side Request Forgery (SSRF) vulnerability in the jackson-databind library's deserialization of java.net.InetAddress. Unlike the previously fixed InetSocketAddress deserialization which avoids DNS resolution, the InetAddress deserialization still performs eager DNS lookups on attacker-controlled input. This can lead to DNS-based SSRF allowing out-of-band interaction or internal host enumeration via DNS queries during JSON deserialization. Join the discussion | CVE Database V5 | 09/28/2026, 20:17:41 UTC Added: 08/24/2026, 19:37:53 UTC |
0 Red Hat build of Apache Camel 4.18.4 for Spring Boot patch release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects (CVE-2026-15075) * jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision (CVE-2026-10050) * rhaf-camel-spring-boot-maven-repository.zip: Apache Qpid Proton-J: Denial of Service via unbounded type nesting (CVE-2026-66274) * jetty-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051) * sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation (CVE-2026-56624) * cxf-rt-transports-jms: Apache CXF: Remote Code Execution via unsafe deserialization of JMS ObjectMessage (CVE-2026-66909) * cxf-rt-rs-security-oauth2: Apache CXF: Authorization code replay due to flaw in DefaultEncryptingCodeDataProvider (CVE-2026-68079) * cxf-rt-rs-security-oauth2: Apache CXF: Authorization Code Replay via Race Condition (CVE-2026-57818) * cxf: Apache CXF: Authorization Code Substitution via missing c_hash validation (CVE-2026-57817) * camel: Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers (CVE-2026-46457) * camel: Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers (CVE-2026-46456) * camel: Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields (CVE-2026-48203) * camel-amqp: Apache Camel: Information disclosure via deserialization of untrusted data (CVE-2026-42527) * proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation (CVE-2026-66273) * proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching (CVE-2026-66257) * netty-codec-xml: Netty: Denial of Service via CPU Exhaustion in XmlFrameDecoder (CVE-2026-73507) * micrometer-core: Micrometer: Line-protocol and log injection via unsanitized input allows metric and log spoofing (CVE-2026-59296) * cxf-rt-rs-security-oauth2: Apache CXF: Security bypass due to improper handling of authorization parameters (CVE-2026-63687) * camel-knative: Apache Camel Knative: Header injection vulnerability allows server-side request forgery (CVE-2026-63621) * camel-main: Apache Camel: Improper authentication allows JWT bypass in Platform HTTP Main component (CVE-2026-66908) * netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration (CVE-2026-62243) * httpclient5-cache: Apache HttpComponents Client: Denial of Service due to connection leak (CVE-2026-64607) * jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) * zstd-jni: zstd-jni: Data corruption or denial of service via use-after-free vulnerability (CVE-2026-87825) * zstd-jni: zstd-jni: Use-After-Free vulnerability allows memory corruption and denial of service (CVE-2026-87877) * zstd-jni: zstd-jni: Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect (CVE-2026-87824) * zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795) * zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046) * jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing (CVE-2026-68497) * zstd-jni: zstd-jni: Denial of Service via out-of-bounds read in ZstdDictDecompress (CVE-2026-90560) * bcprov-jdk18on: Bouncy Castle for Java: Denial of Service via quadratic-time escaping of X.500 distinguished names (CVE-2026-58059) * bcprov-jdk18on: Bouncy Castle for Java: Cryptographic signature bypass in RSA PKCS#1 verification (CVE-2026-12860) * zstd-jni: luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing (CVE-2026-90852) * netty-transport-sctp: Netty: Denial of Service via SCTP memory exhaustion (CVE-2026-59902) * camel-mail: Apache Camel: Injected MIME headers can manipulate route behavior (CVE-2026-59230) * netty-handler: Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext (CVE-2026-75595) Join the discussion | GCVE Database | 09/24/2026, 19:56:44 UTC Added: 07/23/2026, 01:18:08 UTC |
0 Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the JVM heap is exhausted. The resulting java.lang.OutOfMemoryError is a fatal Scala error that is not ordinarily handled by scala.util.Try or cats.effect.IO, causing denial of service. This issue is fixed in version 1.7.0. Join the discussion | CVE Database V5 | 09/23/2026, 18:41:12 UTC Added: 09/23/2026, 19:48:28 UTC |
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start. A remote attacker who controls untrusted JSON input and its chunk sizes can exhaust CPU resources and cause denial of service in applications using AsyncParser. This issue is fixed in version 1.7.0. Join the discussion | CVE Database V5 | 09/23/2026, 18:39:01 UTC Added: 09/23/2026, 19:48:26 UTC |
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When anonymous access is enabled and topic ACLs restrict writes, a remote client can set an ACL-protected topic as the Last Will Topic during CONNECT and perform an abnormal client disconnect, causing the broker to inject attacker-controlled messages into a topic for which the client lacks write permission. This issue is fixed in version 0.18.1. Join the discussion | CVE Database V5 | 09/18/2026, 17:40:39 UTC Added: 09/18/2026, 17:47:19 UTC |
0 CVE-2026-54617 is a critical path traversal vulnerability in GravitLauncher, an open-source Minecraft launcher. Versions prior to 5.7.12 allow unauthenticated remote attackers to send specially crafted HTTP requests without a leading slash to the LaunchServer file server on port 9274. This flaw enables reading arbitrary files accessible to the LaunchServer process, including sensitive signing keys and credentials. Exploitation can lead to forged administrative tokens and full authentication bypass. The issue is fixed in version 5.7.12. Join the discussion | GCVE Database | 09/17/2026, 18:34:40 UTC Added: 07/02/2026, 22:56:46 UTC |
HAPI FHIR versions prior to 6.9.12 contain an improper input validation vulnerability in the SHCParser component. This flaw can cause an infinite loop when processing specially crafted Smart Health Card JWTs with a 'zip' header set to 'DEF' and an empty or truncated raw-DEFLATE payload. The infinite loop can indefinitely pin a JVM worker thread, potentially exhausting all validation workers under concurrent requests. This issue is fixed in version 6.9.12. Join the discussion | CVE Database V5 | 09/16/2026, 18:48:05 UTC Added: 09/16/2026, 19:02:13 UTC |
Showing 1 to 10 of 176 results