Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-qqj6-54q6-cxv6
  • Go/github.com/snowflakedb/gosnowflake
  • Go/github.com/snowflakedb/gosnowflake/v2
  • Maven/net.snowflake:snowflake-jdbc
  • Maven/net.snowflake:snowflake-jdbc-fips
  • Maven/net.snowflake:snowflake-jdbc-thin
  • ... 2 more
Snowflake drivers writes sensitive information to logs 6 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-rvm3-566m-v7fv
  • Maven/com.capacitorjs:core
  • SwiftURL/github.com/ionic-team/capacitor-swift-pm
  • npm/@capacitor/android
  • npm/@capacitor/ios
Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path 6 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-xm28-xvqc-gxxg
  • Maven/eu.copernik:copernik-xml-factory
Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution 3 days ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-7hhh-6rmp-j9qf
  • Maven/com.fasterxml.jackson.core:jackson-core
  • Maven/tools.jackson.core:jackson-core
jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS) 4 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-p6pp-m3f8-5c89
  • Maven/com.fasterxml.jackson.core:jackson-core
  • Maven/tools.jackson.core:jackson-core
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() 4 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-cxp5-3px4-pw24
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind quadratic forward-reference completion 5 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-wv8q-qhhj-9h54
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind retains every unknown raw type ID 5 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-gx83-3vf8-gh7j
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist) 28 Sep
  • Fix available
  • Severity - 5.6 (Medium)
GHSA-q4xh-88c3-wmh7
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS 28 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-wjgm-6hv5-3cvf
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution 28 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-vvgp-rfg2-7rr6
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization 28 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-cjx3-73hr-rpw7
  • Maven/org.http4s:http4s-scala-xml_2.12
  • Maven/org.http4s:http4s-scala-xml_2.13
  • Maven/org.http4s:http4s-scala-xml_3
http4s-scala-xml has an XML External Entity (XXE) processing issue 24 Sep
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-w4cm-gvhj-cgw6
  • Maven/org.typelevel:jawn-parser_2.12
  • Maven/org.typelevel:jawn-parser_2.13
  • Maven/org.typelevel:jawn-parser_3
Jawn: Quadratic parsing effort in AsyncParser 23 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-cc4v-rvgp-2pf3
  • Maven/org.typelevel:jawn-parser_2.12
  • Maven/org.typelevel:jawn-parser_2.13
  • Maven/org.typelevel:jawn-parser_3
Jawn: Uncontrolled nesting depth in JSON parser 23 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-ph9c-7hw9-vhhw
  • Maven/org.jline:jline-builtins
JLine: ReDoS in Nano Editor Regex Search Mode 23 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-r2xf-8xr9-62gw
  • Maven/org.jline:jline-builtins
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping 23 Sep
  • Fix available
  • Severity - 7.5 (High)