Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-cxp5-3px4-pw24
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind quadratic forward-reference completion 10 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-wv8q-qhhj-9h54
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind retains every unknown raw type ID 10 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-gx83-3vf8-gh7j
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist) 2 days ago
  • Fix available
  • Severity - 5.6 (Medium)
GHSA-q4xh-88c3-wmh7
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS 2 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-wjgm-6hv5-3cvf
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution 2 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-vvgp-rfg2-7rr6
  • Maven/com.fasterxml.jackson.core:jackson-databind
  • Maven/tools.jackson.core:jackson-databind
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization 2 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-cjx3-73hr-rpw7
  • Maven/org.http4s:http4s-scala-xml_2.12
  • Maven/org.http4s:http4s-scala-xml_2.13
  • Maven/org.http4s:http4s-scala-xml_3
http4s-scala-xml has an XML External Entity (XXE) processing issue 6 days ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-w4cm-gvhj-cgw6
  • Maven/org.typelevel:jawn-parser_2.12
  • Maven/org.typelevel:jawn-parser_2.13
  • Maven/org.typelevel:jawn-parser_3
Jawn: Quadratic parsing effort in AsyncParser 23 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-cc4v-rvgp-2pf3
  • Maven/org.typelevel:jawn-parser_2.12
  • Maven/org.typelevel:jawn-parser_2.13
  • Maven/org.typelevel:jawn-parser_3
Jawn: Uncontrolled nesting depth in JSON parser 23 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-ph9c-7hw9-vhhw
  • Maven/org.jline:jline-builtins
JLine: ReDoS in Nano Editor Regex Search Mode 23 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-r2xf-8xr9-62gw
  • Maven/org.jline:jline-builtins
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping 23 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-5q95-hrpc-m3w3
  • Maven/org.jline:jline-reader
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable 23 Sep
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-5f42-97gr-vfhq
  • Maven/io.moquette:moquette-broker
Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug 23 Sep
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-m9c2-85gv-8xr5
  • Maven/org.graylog2:graylog2-server
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards 22 Sep
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-7952-gx68-cjqr
  • Maven/net.sf.mpxj:mpxj
  • NuGet/MPXJ.Net
  • NuGet/net.sf.mpxj
  • NuGet/net.sf.mpxj-for-csharp
  • NuGet/net.sf.mpxj-for-vb
  • ... 2 more
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers 22 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-5vvx-3h34-f3gj
  • Maven/net.sf.mpxj:mpxj
  • NuGet/MPXJ.Net
  • NuGet/net.sf.mpxj
  • NuGet/net.sf.mpxj-for-csharp
  • NuGet/net.sf.mpxj-for-vb
  • ... 2 more
MPXJ: XXE Vulnerability in MerlinReader 22 Sep
  • Fix available
  • Severity - 7.5 (High)