Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-9272-wg2r-7xmx
  • Maven/org.yamcs:yamcs-core
Yamcs has DOM XSS in Extension Routing 28 Aug
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-55566
  • github.com/yamcs/yamcs
Yamcs: DOM XSS in Extension Routing 28 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-c64q-hj4j-375f
  • Maven/org.yamcs:yamcs-core
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) 28 Aug
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2026-55565
  • github.com/yamcs/yamcs
Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) 28 Aug
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-73mf-m39p-wpm9
  • Maven/org.yamcs:yamcs-core
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) 28 Aug
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-55559
  • github.com/yamcs/yamcs
Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) 28 Aug
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-9jg3-g3wh-w9pj
  • Maven/org.yamcs:yamcs-core
Yamcs has Unauthenticated Directory Traversal 28 Aug
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-55552
  • github.com/yamcs/yamcs
Yamcs: Unauthenticated Directory Traversal 28 Aug
  • Fix available
  • Severity - 7.5 (High)
GHSA-rxpg-wjf8-qv9c
  • Maven/org.yamcs:yamcs-core
Yamcs has Reflected XSS in the URL of the Authorize Endpoint 28 Aug
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-55549
  • github.com/yamcs/yamcs
Yamcs: Reflected XSS in the URL of the Authorize Endpoint 28 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-8xjq-pr36-ccgf
  • Maven/org.yamcs:yamcs-core
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets 28 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-cvw4-55pp-3hfq
  • Maven/org.yamcs:yamcs-core
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration 28 Aug
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-55547
  • github.com/yamcs/yamcs
Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration 28 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-fwww-cp23-7f5g
  • Maven/org.yamcs:yamcs-core
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce 28 Aug
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-55545
  • github.com/yamcs/yamcs
Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enforce 28 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-962x-ccwf-8x6p
  • Maven/org.yamcs:yamcs-core
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities 28 Aug
  • Fix available
  • Severity - 8.8 (High)