maven
OSS Librariespackage-ecosystem
Latest CVEs
The 15 most recently published vulnerabilities affecting maven.
- GHSA-fp43-vj7g-pg92OmniFaces: Forged combined-resource IDs and related output/push boundaries
- GHSA-7ppr-r889-mcf2blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
- GHSA-46q4-43ph-c6frblaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
- GHSA-mhvj-jhpq-885vblaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
- GHSA-p279-2cqp-84jgOpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
- GHSA-68r5-9hpg-7qw9OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
- GHSA-v74w-7mr3-4qg3Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
- GHSA-mfg7-5gfp-c4w3Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
- GHSA-464c-974j-9xm6AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
- GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
- GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
- GHSA-x8mg-6r4p-87pfArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
- GHSA-vwjc-v7x7-cm6gArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
- GHSA-x9f9-r4m8-9xc2ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
- GHSA-48qw-824m-86prArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read