OSV-2026-324

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/maven-model/OSV-2026-324.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2026-324
Published
2026-02-28T00:03:36.847525Z
Modified
2026-02-28T00:03:36.847810Z
Summary
Security exception in java.base/java.util.Arrays.copyOfRange
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=488130836

Crash type: Security exception
Crash state:
java.base/java.util.Arrays.copyOfRange
java.base/java.lang.StringUTF16.newString
java.base/java.lang.StringBuilder.toString
References

Affected packages

OSS-Fuzz / maven-model

Package

Name
maven-model
Purl
pkg:generic/maven-model

Affected ranges

Type
GIT
Repo
https://github.com/apache/maven
Events

Affected versions

maven-4.*
maven-4.0.0-alpha-13
maven-4.0.0-beta-2
maven-4.0.0-beta-3
maven-4.0.0-beta-4
maven-4.0.0-beta-5
maven-4.0.0-rc-1
maven-4.0.0-rc-2
maven-4.0.0-rc-3
maven-4.0.0-rc-4
maven-4.0.0-rc-5

Ecosystem specific

{
    "severity": "LOW"
}

Database specific

introduced_range
"a3e8da805c7e8d743700f13924bd2aafe3fe6783:5029cc238ce5ce03b0fb431a278889f8b788c0a7"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/maven-model/OSV-2026-324.yaml"