CVE-2026-4636
published 2026-04-02CVE-2026-4636: A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the…
PriorityP351high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.35%
26.9th percentile
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_keycloak | — | — |
| redhat | build_of_keycloak | — | — |
| redhat | build_of_keycloak | — | — |
| redhat | build_of_keycloak | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
ghsa·2026-04-02
CVE-2026-4636 [HIGH] CWE-551 Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.
OSV
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
osv·2026-04-02
CVE-2026-4636 [HIGH] Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.
Red Hat
keycloak: Keycloak: UMA policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
vendor_redhat·2026-04-02·CVSS 8.1
CVE-2026-4636 [HIGH] CWE-551 keycloak: Keycloak: UMA policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
keycloak: Keycloak: UMA policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to inc
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0707 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-0707 [MEDIUM] CVE-2026-0707 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0707 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of the "Bearer" authentication scheme. It accepts non-standard characters (such as tabs) as separators and tolerates case variations that deviate from RFC 6750 specifications.
Source : NVD
## 5.3
Score
Published January 8, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.keycloak:keycloak-parent
Sources
NVD
Maven Severity MEDIUM No Fix Added at: Jan 11, 2026
## Get a
Wiz
CVE-2025-14559 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-14559 [MEDIUM] CVE-2025-14559 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14559 :
Java vulnerability analysis and mitigation
A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vulnerability in the Token Exchange implementation when a privileged client invokes the token exchange flow.
Source : NVD
## 6.5
Score
Published January 21, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak
keycloak-fips
Sources
NVD
Chaing
Wiz
CVE-2026-22187 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-22187 [MEDIUM] CVE-2026-22187 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22187 :
Java vulnerability analysis and mitigation
Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing. The loci.formats.Memoizer class automatically loads and deserializes memo files associated with images without validation, integrity checks, or trust enforcement. An attacker who can supply a crafted .bfmemo file alongside an image can trigger deserialization of untrusted data, which may result in denial of service, logic manipulation, or potentially remote code execution in environments where suitable gadget chains are present on the classpath.
Source : NVD
## 6.8
Score
Published January 7, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Java
Wiz
CVE-2025-65482 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2025-65482 [CRITICAL] CVE-2025-65482 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-65482 :
Java vulnerability analysis and mitigation
An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.
Source : NVD
## 9.8
Score
Published January 20, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 24.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
fr.opensagres.xdocreport:fr.opensagres.xdocreport.document
Sources
NVD
Maven Severity CRITICAL Has Fix Added at: Jan 22, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on wha
Wiz
CVE-2025-66675 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-66675 [HIGH] CVE-2025-66675 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66675 :
Java vulnerability analysis and mitigation
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.
This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3.
Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
It's related to https://cve.org/CVERecord?id=CVE-2025-64775 - this CVE addresses missing affected version 6.7.4
Source : NVD
## 8.2
Score
Published December 10, 2025
Severity HIGH
CNA Score 8.2
Affected Technologies
Java
Apache Struts
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 31.5
Exploitation Probability (EPSS) 0.1
Affected package
Wiz
CVE-2026-22743 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-22743 [HIGH] CVE-2026-22743 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22743 :
Java vulnerability analysis and mitigation
metadata.
Source : NVD
## 7.5
Score
Published March 27, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
org.springframework.ai:spring-ai-neo4j-store
Sources
NVD
Maven Severity HIGH Has Fix Added at: Mar 29, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE
Wiz
CVE-2025-14518 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-14518 [MEDIUM] CVE-2025-14518 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14518 :
Java vulnerability analysis and mitigation
A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Source : NVD
## 5.3
Score
Published December 11, 2025
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.8
Exploitation Probability (EPSS) N/A
Affect
Wiz
CVE-2026-3121 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3121 [MEDIUM] CVE-2026-3121 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3121 :
Java vulnerability analysis and mitigation
manage-clients
manage-permissions
Source : NVD
## 7.2
Score
Published March 26, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:redhat:jboss_enterprise_application_platform
org.keycloak:keycloak-services
Sources
Maven Severity MEDIUM Has Fix Added at: Mar 29, 2026
MinimOS Severity HIGH Has Fix Added at: Mar 31, 2026
Linux Severity HIGH No Fix Added at: Apr 02, 2026
Windows Severity HIGH No Fix Added at: Apr 02, 2026
Linux Severity HIGH No Fix Added at: Apr 05, 2026
Wiz
CVE-2025-66472 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-66472 [MEDIUM] CVE-2025-66472 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66472 :
Java vulnerability analysis and mitigation
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates are vulnerable to a reflected XSS attack through a deletion confirmation message. The attacker-supplied script is executed when the victim clicks the "No" button. This issue is fixed in versions 16.10.10 and 17.4.2 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates.
Source : NVD
## 6.5
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Re
Wiz
CVE-2026-28369 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-28369 [HIGH] CVE-2026-28369 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28369 :
Java vulnerability analysis and mitigation
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
Source : NVD
## 9.1
Score
Published March 27, 2026
Severity CRITICAL
CNA Score 8.7
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploit
Wiz
CVE-2025-65090 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-65090 [MEDIUM] CVE-2025-65090 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-65090 :
Java vulnerability analysis and mitigation
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has been patched in version 2.4.6.
Source : NVD
## 5.3
Score
Published January 10, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.xwiki.contrib:macro-fullcalendar-pom
Sources
NVD
Maven Severit
Wiz
CVE-2025-66249 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2025-66249 [MEDIUM] CVE-2025-66249 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66249 :
Java vulnerability analysis and mitigation
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy.
This issue affects Apache Livy: from 0.3.0 before 0.9.0.
The vulnerability can only be exploited with non-default Apache Livy Server settings. If the configuration value "livy.file.local-dir-whitelist" is set to a non-default value, the directory checking can be bypassed.
Users are recommended to upgrade to version 0.9.0, which fixes the issue.
Source : NVD
## 6.3
Score
Published March 13, 2026
Severity MEDIUM
CNA Score 6.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.9
Exploitati
Wiz
CVE-2025-14778 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-14778 [MEDIUM] CVE-2025-14778 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14778 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionService (UMA Protection API). When updating or deleting a UMA policy associated with multiple resources, the authorization check only verifies the caller's ownership against the first resource in the policy's list. This allows a user (Owner A) who owns one resource (RA) to update a shared policy and modify authorization rules for other resources (e.g., RB) in that same policy, even if those other resources are owned by a different user (Owner B). This constitutes a horizontal privilege escalation.
Source : NVD
## 5.4
Score
Published February 9, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Ja
Wiz
CVE-2025-68390 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.9
CVE-2025-68390 [MEDIUM] CVE-2025-68390 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68390 :
Java vulnerability analysis and mitigation
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.
Source : NVD
## 4.9
Score
Published December 18, 2025
Severity MEDIUM
CNA Score 4.9
Affected Technologies
Java
Elasticsearch
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 39.5
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
ruby4.0-elasticsearch
sonarqube
Sources
NVD
Chainguard Has Fix Added at: Dec 24, 2025
Maven Severity MEDIUM Has Fix Added a
Wiz
CVE-2026-4282 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-4282 [HIGH] CVE-2026-4282 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4282 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.
Source : NVD
## 7.4
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.4
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak-fips-26.5
keycloak
Sources
NVD
Chainguard Has Fix Add
Wiz
CVE-2025-14082 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.7
CVE-2025-14082 [LOW] CVE-2025-14082 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14082 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint.
Source : NVD
## 2.7
Score
Published December 10, 2025
Severity LOW
CNA Score 2.7
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.keycloak:keycloak-services
keycloak
Sources
NVD
Maven Severity LOW Has Fix Added at: Dec 11, 2025
MinimOS Severity LOW Has Fix Added at: Jan 18
Wiz
CVE-2024-29371 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2024-29371 [HIGH] CVE-2024-29371 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-29371 :
Java vulnerability analysis and mitigation
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
Source : NVD
## 7.5
Score
Published December 17, 2025
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Wolfi
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
apache-nifi
apache-pulsar
Sources
NVD
Chainguard Has Fix Added at: Dec 22
Wiz
CVE-2026-23794 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-23794 [MEDIUM] CVE-2026-23794 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23794 :
Java vulnerability analysis and mitigation
Reflected XSS in Apache Syncope's Enduser Login page.
An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
Source : NVD
## 6.8
Score
Published February 3, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.apache.syncope.client.idrepo
Wiz
CVE-2025-68703 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2025-68703 [HIGH] CVE-2025-68703 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68703 :
Java vulnerability analysis and mitigation
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with the same password will have the same derived key. This vulnerability is fixed in 2.2.
Source : NVD
## 8.7
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
net.gleske:jervis
Sources
NVD
Maven Severity HIGH Has Fix Added at: Jan 13, 2026
## Get a CVE risk assessment
Get a prioritized
Wiz
CVE-2026-23907 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-23907 [MEDIUM] CVE-2026-23907 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23907 :
Java vulnerability analysis and mitigation
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.
The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because
the filename that is obtained from
PDComplexFileSpecification.getFilename() is appended to the extraction path.
Users who have copied this example into their production code should
review it to ensure that the extraction path is acceptable. The example
has been changed accordingly, now the initial path and the extraction
paths are converted into canonical paths and it is verified that
extraction path contains the initial path. The documentation has also
been adjusted.
Source : NVD
## 5.3
Score
Published Marc
Wiz
CVE-2025-13881 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.7
CVE-2025-13881 [LOW] CVE-2025-13881 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13881 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
Source : NVD
## 2.7
Score
Published February 2, 2026
Severity LOW
CNA Score 2.7
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak-fips
org.keycloak:keycloak-services
Sources
NVD
Maven Severity LOW Has Fix Added at: Feb 03, 2026
MinimOS Severity LOW Has Fix Added at: Feb 04, 20
Wiz
CVE-2026-24656 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.7
CVE-2026-24656 [LOW] CVE-2026-24656 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24656 :
Java vulnerability analysis and mitigation
Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.
The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.
It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS.
NB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue.
This issue affects Apache Karaf Decanter before 2.12.0.
Users are recommended to upgrade to version 2.12.0, which fixes the issue.
Source : NVD
## 3.7
Score
Published January 26, 2026
Severity LOW
CNA Score 3.7
Affected T
Wiz
CVE-2026-3429 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.2
CVE-2026-3429 [MEDIUM] CVE-2026-3429 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3429 :
Java vulnerability analysis and mitigation
A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential without first proving possession of that factor. The attacker can then register their own MFA device, effectively taking full control of the account. This weakness undermines the intended protection provided by multi-factor authentication.
Source : NVD
## 4.2
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 4.2
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CIS
Wiz
CVE-2025-59059 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2025-59059 [CRITICAL] CVE-2025-59059 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59059 :
Java vulnerability analysis and mitigation
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0.
Users are recommended to upgrade to version 2.8.0, which fixes this issue.
Source : NVD
## 9.8
Score
Published March 3, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 64.4
Exploitation Probability (EPSS) 0.5
Affected packages and libraries
ranger
org.apache.ranger:ranger-plugins-common
Sources
NVD
Alpine 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity CRITICAL No Fix Added at: Mar 08, 2026
Wiz
CVE-2026-33166 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-33166 [HIGH] CVE-2026-33166 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33166 :
Java vulnerability analysis and mitigation
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vulnerable to an arbitrary file read via path traversal when processing test results. An attacker can craft a malicious result file (-result.json, -container.json, or .plist) that points an attachment source to a sensitive file on the host system. During report generation, Allure will resolve these paths and include the sensitive files in the final report. Version 2.38.0 fixes the issue.
Source : NVD
## 8.6
Score
Published March 20, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA K
Wiz
CVE-2025-47411 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-47411 [HIGH] CVE-2025-47411 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-47411 :
Java vulnerability analysis and mitigation
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator.
This vulnerability allows an attacker to gain administrative control over the application by manipulating JWT tokens, which can lead to data tampering, unauthorized access and other security issues.
This issue affects Apache StreamPipes: through 0.97.0.
Users are recommended to upgrade to version 0.98.0, which fixes the issue.
Source : NVD
## 8.1
Score
Published January 1, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Rele
Wiz
CVE-2026-23903 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-23903 [MEDIUM] CVE-2026-23903 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23903 :
Java vulnerability analysis and mitigation
Authentication Bypass by Alternate Name vulnerability in Apache Shiro.
This issue affects Apache Shiro: before 2.0.7.
Users are recommended to upgrade to version 2.0.7, which fixes the issue.
The issue only effects static files. If static files are served from a case-insensitive filesystem,
such as default macOS setup, static files may be accessed by varying the case of the filename in the request.
If only lower-case (common default) filters are present in Shiro, they may be bypassed this way.
Shiro 2.0.7 and later has a new parameters to remediate this issue
shiro.ini: filterChainResolver.caseInsensitive = true
application.propertie: shiro.caseInsensitive=true
Shiro 3.0.0 and later (upcoming) makes this the default.
So
Wiz
CVE-2026-1622 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2026-1622 [MEDIUM] CVE-2026-1622 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1622 :
Java vulnerability analysis and mitigation
Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local log files.
The "obfuscate_literals" option in the query logs does not redact error information, exposing unredacted data in the query log when a customer writes a query that fails. It can allow a user with legitimate access to the local log files to obtain information they are not authorised to see. If this user is also in a position to run queries and trigger errors, this vulnerability can potentially help them to infer information they are not authorised to see through their intended database access.
We recommend upgrading to versions 2026.01.3 (o
Wiz
CVE-2026-24128 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-24128 [MEDIUM] CVE-2026-24128 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24128 :
Java vulnerability analysis and mitigation
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-milestone-2 through 16.10.11, 17.0.0-rc-1 through 17.4.4, and 17.5.0-rc-1 through 17.7.0 contain a reflected Cross-site Scripting (XSS) vulnerability, which allows an attacker to craft a malicious URL and execute arbitrary actions with the same privileges as the victim. If the victim has administrative or programming rights, those rights can be exploited to gain full access to the XWiki installation. This issue has been patched in versions 17.8.0-rc-1, 17.4.5 and 16.10.12. To workaround, the patch can be applied manually, only a single line in templates/logging_macros.vm needs to be changed, no restart is requ
Wiz
CVE-2026-2742 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-2742 [MEDIUM] CVE-2026-2742 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2742 :
Java vulnerability analysis and mitigation
An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.1, applications using Spring Security due to inconsistent path pattern matching of reserved framework paths.
Accessing the /VAADIN endpoint without a trailing slash bypasses security filters, and allowing unauthenticated users to trigger framework initialization and create sessions without proper authorization.
Users of affected versions using Spring Security should upgrade as follows: 14.0.0-14.14.0 upgrade to 14.14.1, 23.0.0-23.6.6 to 23.6.7, 24.0.0 - 24.9.7 to 24.9.8, and 25.0.0-25.0.1 upgrade to 25.0.2 or newer.
Please note that Vaadin versions 10-13 and 15-22 are no longer
Wiz
CVE-2026-33001 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-33001 [HIGH] CVE-2026-33001 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33001 :
Java vulnerability analysis and mitigation
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.
Source : NVD
## 8.8
Score
Published March 18, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 30.7
Wiz
CVE-2026-3270 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-3270 [MEDIUM] CVE-2026-3270 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3270 :
Java vulnerability analysis and mitigation
A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-probe-core/src/main/java/psiprobe/tools/Whois.java of the component Whois. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Source : NVD
## 5.3
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.6
Exploitation Probability (EPSS) N/A
Wiz
CVE-2025-68384 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-68384 [MEDIUM] CVE-2025-68384 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68384 :
Java vulnerability analysis and mitigation
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.
Source : NVD
## 6.5
Score
Published December 18, 2025
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Java
Elasticsearch
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
elasticsearch-9.1
elasticsearch-9.2
Sources
NVD
Chainguard Has Fix Added at: Jan 07, 2026
Maven Severity MEDI
Wiz
CVE-2025-67640 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.0
CVE-2025-67640 [MEDIUM] CVE-2025-67640 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67640 :
Java vulnerability analysis and mitigation
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.
Source : NVD
## 5
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.0
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 27.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
org.jenkins-ci.plugins:git-client
jenkins
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16,
Wiz
CVE-2025-70952 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-70952 [HIGH] CVE-2025-70952 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-70952 :
Java vulnerability analysis and mitigation
pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 52.1
Exploitation Probability (EPSS) 0.3
Affected packages and libraries
libpf4j-java
org.pf4j:pf4j
Sources
NVD
Debian 12, 13, 14 Severity HIGH No Fix Added at: Mar 29, 2026
Echo Severity HIGH No Fix Added
Wiz
CVE-2025-15022 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2025-15022 [MEDIUM] CVE-2025-15022 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15022 :
Java vulnerability analysis and mitigation
Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS) if caption content is derived from user input.
In Vaadin Framework 7 and 8, the Action class is a general-purpose class that may be used by multiple components. The fixed versions sanitize captions by default and provide an API to explicitly enable HTML content mode for backwards compatibility.
In Vaadin 23 and newer, the Action class is only used by the Spreadsheet component. The fixed versions sanitize HTML using Jsoup with a relaxed safelist.
Vaadin 14 is not affected as Spreadsheet component was not supported.
Users of affected versions should apply the following mitigation or upgrade. Releases that
Wiz
CVE-2025-14083 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.7
CVE-2025-14083 [LOW] CVE-2025-14083 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14083 :
Java vulnerability analysis and mitigation
A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.
Source : NVD
## 2.7
Score
Published January 21, 2026
Severity LOW
CNA Score 2.7
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.keycloak:keycloak-services
keycloak
Sources
NVD
Maven Severity LOW No Fix Added at: Jan 22, 2026
MinimOS Severity LOW Has Fix Added at: Feb 02, 2026
## Get a CVE risk as
Wiz
CVE-2025-61916 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.9
CVE-2025-61916 [HIGH] CVE-2025-61916 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61916 :
Java vulnerability analysis and mitigation
Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into spinnaker pipelines via helm or other methods to extract things LIKE idmsv1 authentication data. This also includes calling internal spinnaker API's via a get and similar endpoints. Further, depending upon the artifact in question, auth data may be exposed to arbitrary endpoints (e.g. GitHub auth headers) leading to credentials exposure. To trigger this, a spinnaker installation MUST have two things. The first is an artifact enabled that allows user input.
Wiz
CVE-2026-4634 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-4634 [HIGH] CVE-2026-4634 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4634 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.
Source : NVD
## 7.5
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
keycloak-fips-26.5
org.key
Wiz
CVE-2026-3293 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2026-3293 [MEDIUM] CVE-2026-3293 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3293 :
Java vulnerability analysis and mitigation
A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executing a manipulation of the argument nonProxyHosts can lead to inefficient regular expression complexity. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 5fb0a8a318a2ed87f4022a1f56e742424ba94052. A patch should be applied to remediate this issue.
Source : NVD
## 4.8
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 4.8
Affected Technologies
Java
Has Public Exploit Yes
Ha
Wiz
CVE-2026-34237 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.1
CVE-2026-34237 [MEDIUM] CVE-2026-34237 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34237 :
Java vulnerability analysis and mitigation
MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 1.0.1 and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 1.0.1 and 1.1.1.
Source : NVD
## 6.1
Score
Published March 31, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
io.modelcontextprotocol.sdk:mcp-core
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Mar 31, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in
Wiz
CVE-2025-67638 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2025-67638 [MEDIUM] CVE-2025-67638 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67638 :
Java vulnerability analysis and mitigation
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Source : NVD
## 4.3
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.jenkins-ci.main:jenkins-core
cpe:2.3:a:jenkins:jenkins
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, edge Severity MEDIUM No Fix Added at:
Wiz
CVE-2025-68698 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2025-68698 [HIGH] CVE-2025-68698 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68698 :
Java vulnerability analysis and mitigation
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding). This vulnerability is fixed in 2.2.
Source : NVD
## 8.7
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
net.gleske:jervis
Sources
NVD
Maven Severity HIGH Has Fix Added at: Jan 13, 2026
## Get a CVE risk
Wiz
CVE-2026-0976 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.7
CVE-2026-0976 [LOW] CVE-2026-0976 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0976 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filtering. This could expose administrative or sensitive endpoints that operators believe are not externally reachable.
Source : NVD
## 3.7
Score
Published January 15, 2026
Severity LOW
CNA Score 3.7
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitati
Wiz
CVE-2026-0871 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.9
CVE-2026-0871 [MEDIUM] CVE-2026-0871 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0871 :
Java vulnerability analysis and mitigation
manage-users
Source : NVD
## 4.9
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak
keycloak-fips
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Mar 02, 2026
MinimOS Severity MEDIUM Has Fix Added at: Mar 02, 2026
Nix Severity MEDIUM Has Fix Added at: Mar 08, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vulnerabilities:
Wiz
CVE-2026-22732 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2026-22732 [CRITICAL] CVE-2026-22732 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22732 :
Java vulnerability analysis and mitigation
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:
: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
Source : NVD
## 9.1
Score
Published March 19, 2026
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.1
Exploitation Probability (EPSS
Wiz
CVE-2016-15057 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.9
CVE-2016-15057 [CRITICAL] CVE-2016-15057 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2016-15057 :
Java vulnerability analysis and mitigation
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum.
This issue affects Apache Continuum: all versions.
Attackers with access to the installations REST API can use this to invoke arbitrary commands on the server.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Source : NVD
## 9.9
Score
Published January 26, 2026
Severity CRITICAL
CNA Score 9.9
Affected Technologies
Java
Apache Continuum
Wiz
CVE-2026-1002 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-1002 [MEDIUM] CVE-2026-1002 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1002 :
Java vulnerability analysis and mitigation
The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted request URI.
The issue comes from an improper implementation of the C. rule of section 5.2.4 of RFC3986 and is fixed in Vert.x Core component (used by Vert.x Web): https://github.com/eclipse-vertx/vert.x/pull/5895
Steps to reproduce
Given a file served by the static handler, craft an URI that introduces a string like bar%2F..%2F after the last / char to deny the access to the URI with an HTTP 404 response. For example https://example.com/foo/index.html can be denied with https://example.com/foo/bar%2F..%2Findex.html
Mitgation
Disabling Static Handler cache fixes the issue.
Sta
Wiz
CVE-2025-29847 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-29847 [HIGH] CVE-2025-29847 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-29847 :
Java vulnerability analysis and mitigation
A vulnerability in Apache Linkis.
Problem Description
When using the JDBC engine and da
When using the JDBC engine and data source functionality, if the URL parameter configured on the frontend has undergone multiple rounds of URL encoding, it may bypass the system's checks. This bypass can trigger a vulnerability that allows unauthorized access to system files via JDBC parameters.
Scope of Impact
This issue affects Apache Linkis: from 1.3.0 through 1.7.0.
Severity level
moderate
Solution
Continuously check if the connection information contains the "%" character; if it does, perform URL decoding.
Users are recommended to upgrade to version 1.8.0, which fixes the issue.
More questions about this vulnerability can be di
Wiz
CVE-2026-22742 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-22742 [HIGH] CVE-2026-22742 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22742 :
Java vulnerability analysis and mitigation
Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended internal or external destinations.
This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
Source : NVD
## 8.6
Score
Published March 27, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.3
Exploitation Probability (EPSS) N/A
Affec
Wiz
CVE-2026-4325 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-4325 [HIGH] CVE-2026-4325 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4325 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This could lead to unauthorized access or account compromise.
Source : NVD
## 5.3
Score
Published April 2, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.keycloak:keycloak-services
keyclo
Wiz
CVE-2026-22744 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-22744 [HIGH] CVE-2026-22744 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22744 :
Java vulnerability analysis and mitigation
In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
Source : NVD
## 7.5
Score
Published March 27, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.springframework.ai:spring-ai-redis-store
Sources
NVD
Maven Severi
Wiz
CVE-2024-5986 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2024-5986 [CRITICAL] CVE-2024-5986 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-5986 :
Java vulnerability analysis and mitigation
/3/Parse
/3/Frames/framename/export
Source : NVD
## 9.1
Score
Published February 2, 2026
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Java
H2O
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 33.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
h2o
ai.h2o:h2o-core
Sources
NVD
Maven Severity CRITICAL No Fix Added at: Feb 03, 2026
pip Severity CRITICAL No Fix Added at: Feb 03, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vulnerabilities:
CVE ID
Severity
Score
Techno
Wiz
CVE-2026-33871 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-33871 [HIGH] CVE-2026-33871 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33871 :
Java vulnerability analysis and mitigation
CONTINUATION
CONTINUATION
Source : NVD
## 8.7
Score
Published March 27, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Java
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.9
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
strimzi-kafka-operator-0.50
infinispan-15.2
Sources
NVD
Chainguard Has Fix Added at: Mar 29, 2026
Debian 11, 12, 13, 14 Severity HIGH No Fix Added at: Mar 29, 2026
Echo Severity HIGH No Fix Added at: Mar 29, 2026
Maven Severity HIGH Has Fix Added at: Mar 29, 2026
MinimOS Severity HIGH Has Fix Added at: Mar 29, 2026
Wolfi Has Fix Added at: Mar 29, 2026
##
Wiz
CVE-2026-32948 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2026-32948 [MEDIUM] CVE-2026-32948 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32948 :
Java vulnerability analysis and mitigation
sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Process("cmd", "/c", ...) to run VCS commands (git, hg, svn). The URI fragment (branch, tag, revision) is user-controlled via the build definition and passed to these commands without validation. Because cmd /c interprets &, |, and ; as command separators, a malicious fragment can execute arbitrary commands. This issue has been patched in version 1.12.7.
Source : NVD
## 6.7
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 6.7
Affected Technologies
Java
sbt
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPS
Wiz
CVE-2025-60012 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2025-60012 [MEDIUM] CVE-2025-60012 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-60012 :
Java vulnerability analysis and mitigation
Malicious configuration can lead to unauthorized file access in Apache Livy.
This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later.
A request that includes a Spark configuration value supported from Apache Spark version 3.1 can lead to users gaining access to files they do not have permissions to.
For the vulnerability to be exploitable, the user needs to have access to Apache Livy's REST or JDBC interface and be able to send requests with arbitrary Spark configuration values.
Users are recommended to upgrade to version 0.9.0 or later, which fixes the issue.
Source : NVD
## 6.3
Score
Published March 13, 2026
Severity MEDIUM
CNA Score 6.3
Affected Technologies
Java
Has Publi
Wiz
CVE-2026-0858 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2026-0858 [MEDIUM] CVE-2026-0858 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0858 :
Java vulnerability analysis and mitigation
Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG.
Source : NVD
## 5.1
Score
Published January 16, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
Java
PlantUML
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
plantuml
net.so
Wiz
CVE-2026-25903 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-25903 [HIGH] CVE-2026-25903 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25903 :
Java vulnerability analysis and mitigation
Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required to add the annotated component to the flow configuration, but framework authorization did not check restricted status when updating a component previously added. The missing authorization requires a more privileged user to add a restricted component to the flow configuration, but permits a less privileged user to make property configuration changes. Apache NiFi installations that do not implement different levels of authorization for Restricted components are not sub
Wiz
CVE-2025-66473 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2025-66473 [HIGH] CVE-2025-66473 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66473 :
Java vulnerability analysis and mitigation
XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any limits for the number of items that can be requested in a single request at the moment. Depending on the number of pages in the wiki and the memory configuration, this can lead to slowness and unavailability of the wiki. As an example, the /rest/wikis/xwiki/spaces resource returns all spaces on the wiki by default, which are basically all pages. This issue is fixed in versions 17.4.4 and 16.10.11.
Source : NVD
## 8.7
Score
Published December 10, 2025
Severity HIGH
CNA Score 8.7
Affected Technologies
Java
Has Public Exploit No
Has CISA KE
Wiz
CVE-2026-33870 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-33870 [HIGH] CVE-2026-33870 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33870 :
Java vulnerability analysis and mitigation
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
Wiz Threat Research note: This vulnerability's initial access potential has been overridden to FALSE by the Wiz Research team, as it is not confirmed to allow RCE.
Source : NVD
## 7.5
Score
Published March 27, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Wolfi
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (
Wiz
CVE-2026-34360 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2026-34360 [MEDIUM] CVE-2026-34360 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34360 :
Java vulnerability analysis and mitigation
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and makes server-side HTTP requests to it without any hostname, scheme, or domain validation. An unauthenticated attacker with network access to the validator can probe internal network services, cloud metadata endpoints, and map network topology through error-based information leakage. With explore=true (the default for this code path), each request triggers multiple outbound HTTP calls, amplifying reconnaissance capability. This issue has been patched in version 6.9.4.
Source : NVD
## 5.8
Sc
Wiz
CVE-2026-28208 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-28208 [MEDIUM] CVE-2026-28208 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28208 :
Java vulnerability analysis and mitigation
LocalFolderExtractor
Source : NVD
## 5.9
Score
Published February 26, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 35.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
com.github.junrar:junrar
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Mar 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-
Wiz
CVE-2026-33002 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-33002 [HIGH] CVE-2026-33002 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33002 :
Java vulnerability analysis and mitigation
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.
Source : NVD
## 7.5
Score
Published March 18, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:jenkins:jenkins
Wiz
CVE-2026-24734 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-24734 [HIGH] CVE-2026-24734 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24734 :
Java vulnerability analysis and mitigation
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.
When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.
This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected.
Apache Tomcat Native users are recommende
Wiz
CVE-2026-33012 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-33012 [HIGH] CVE-2026-33012 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33012 :
Java vulnerability analysis and mitigation
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an unbounded ConcurrentHashMap cache with no eviction policy in its DefaultHtmlErrorResponseBodyProvider. If the application throws an exception whose message may be influenced by an attacker, (for example, including request query value parameters) it could be used by remote attackers to cause an unbounded heap growth and OutOfMemoryError, leading to DoS. This issue has been fixed in version 4.10.7.
Source : NVD
## 7.5
Score
Published March 20, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
Wiz
CVE-2026-23906 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-23906 [CRITICAL] CVE-2026-23906 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23906 :
Java vulnerability analysis and mitigation
Affected Products and Versions
Apache Druid
Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0)
Prerequisites: * druid-basic-security extension enabled
LDAP authenticator configured
Underlying LDAP server permits anonymous bind
Vulnerability Description
An authentication bypass vulnerability exists in Apache Druid when using the druid-basic-security extension with LDAP authentication. If the underlying LDAP server is configured to allow anonymous
binds, an attacker can bypass authentication by providing an existing username with an empty password. This allows unauthorized access to otherwise restricted Druid resources without valid credentials.
The vulnerability stems from improper validation of LDAP au
Wiz
CVE-2025-13590 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2025-13590 [CRITICAL] CVE-2025-13590 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13590 :
Java vulnerability analysis and mitigation
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution.
By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.
Source : NVD
## 7.2
Score
Published February 19, 2026
Severity HIGH
CNA Score 9.1
Affected Technologies
Java
WSO2 API Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:wso2:api_manager
org.wso2.carbon.a
Wiz
CVE-2026-1035 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.1
CVE-2026-1035 [LOW] CVE-2026-1035 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1035 :
Java vulnerability analysis and mitigation
A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.
Source : NVD
## 3.1
Score
Published January 21, 2026
Severity LOW
CNA Score 3.1
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Explo
Wiz
CVE-2025-67636 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2025-67636 [MEDIUM] CVE-2025-67636 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67636 :
Java vulnerability analysis and mitigation
A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.
Source : NVD
## 4.3
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 48.1
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
org.jenkins-ci.main:jenkins-core
cpe:2.3:a:jenkins:jenkins
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, edge Severity MEDIUM No Fix Added at: Dec 18, 2025
Alpine 3.22, 3.23
Wiz
CVE-2026-1770 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.5
CVE-2026-1770 [MEDIUM] CVE-2026-1770 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1770 :
Java vulnerability analysis and mitigation
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain RCE (Remote Code Execution).
Source : NVD
## 4.5
Score
Published February 2, 2026
Severity MEDIUM
CNA Score 4.5
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.craftercms:craftercms
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Feb 03, 2
Wiz
CVE-2025-67643 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2025-67643 [MEDIUM] CVE-2025-67643 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67643 :
Java vulnerability analysis and mitigation
Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/Configure permission to retrieve files present on the Jenkins controller workspace directory.
Source : NVD
## 4.3
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 85.6
Exploitation Probability (EPSS) 2.6
Affected packages and libraries
org.jenkinsci.plugins:pipeline-reporter-by-redpen
Sources
NVD
Maven Severity ME
Wiz
CVE-2026-1529 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-1529 [HIGH] CVE-2026-1529 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1529 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.
Source : NVD
## 8.1
Score
Published February 9, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Java
Keycloak
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.keycloak:keycloak-services
Wiz
CVE-2026-3260 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-3260 [MEDIUM] CVE-2026-3260 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3260 :
Java vulnerability analysis and mitigation
getParameterMap()
Source : NVD
## 5.9
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Java
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 71
Exploitation Probability (EPSS) 0.7
Affected packages and libraries
undertow
moditect
Sources
NVD
Debian 14 Severity MEDIUM No Fix Added at: Mar 26, 2026
Maven Severity MEDIUM Has Fix Added at: Mar 29, 2026
Red Hat 8, 9, 10 Severity MEDIUM No Fix Added at: Mar 24, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vu
Wiz
CVE-2026-22186 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.6
CVE-2026-22186 [MEDIUM] CVE-2026-22186 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22186 :
Java vulnerability analysis and mitigation
Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilderFactory when processing Leica XML-based metadata files, allowing external entity expansion and external DTD loading. A crafted metadata file can trigger outbound network requests (SSRF), access local system resources where readable, or cause a denial of service during XML parsing.
Source : NVD
## 4.6
Score
Published January 7, 2026
Severity MEDIUM
CNA Score 4.6
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation
Wiz
CVE-2025-11143 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.7
CVE-2025-11143 [LOW] CVE-2025-11143 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-11143 :
Java vulnerability analysis and mitigation
The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.
Source : NVD
## 6.5
Score
Published March 5, 2026
Severity MEDIUM
CNA Score 3.7
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 27.9
Exploitation Probability (EPSS) 0.1
Affected packages
Wiz
CVE-2026-2603 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-2603 [HIGH] CVE-2026-2603 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2603 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.
Source : NVD
## 8.1
Score
Published March 18, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 38.4
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
org.keycloak:keycloak-server-spi-pr
Wiz
CVE-2026-26000 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-26000 [MEDIUM] CVE-2026-26000 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26000 :
Java vulnerability analysis and mitigation
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area leading to a malicious page. This vulnerability is fixed in 17.9.0, 17.4.6, and 16.10.13.
Source : NVD
## 5.3
Score
Published February 12, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.xwiki.platform:xwiki-platform-web
Sources
NVD
Maven Severity ME
Wiz
CVE-2026-25534 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.9
CVE-2026-25534 [HIGH] CVE-2026-25534 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25534 :
Java vulnerability analysis and mitigation
## Impact
Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on parsing. This led to a bypass of the previous CVE (CVE-2025-61916) through the use of carefully crafted URLs. Note, Spinnaker found this not just in that CVE, but in the existing URL validations in Orca fromUrl expression handling. This CVE impacts BOTH artifacts as a result.
## Patches
This has been merged and will be available in versions 2025.4.1, 2025.3.1, 2025.2.4 and 2026.0.0.
## Workarounds
You can disable the various artifacts on this system to work around these limits.
Source : NVD
## 9.1
Score
Publ
Wiz
CVE-2026-22444 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-22444 [HIGH] CVE-2026-22444 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22444 :
Java vulnerability analysis and mitigation
The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths that should be disallowed by Solr's "allowPaths" security setting https://https://solr.apache.org/guide/solr/latest/configuration-guide/configuring-solr-xml.html#the-solr-element . These read-only accesses can allow users to create cores using unexpected configsets if any are accessible via the filesystem. On Windows systems configured to allow UNC paths this can additionally cause disclosure of NTLM "user" hashes.
Solr deployments are subject to this vulnerability if they meet the following criteria:
Solr is running in its "sta
Wiz
CVE-2026-3269 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-3269 [MEDIUM] CVE-2026-3269 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3269 :
Java vulnerability analysis and mitigation
A flaw has been found in psi-probe PSI Probe up to 5.3.0. The impacted element is the function handleRequestInternal of the file psi-probe-core/src/main/java/psiprobe/controllers/sessions/ExpireSessionsController.java of the component Session Handler. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Source : NVD
## 5.3
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (
Wiz
CVE-2026-24807 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-24807 [MEDIUM] CVE-2026-24807 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24807 :
Java vulnerability analysis and mitigation
Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/util modules). This vulnerability is associated with program files SeekableOutputStream.Java.
This issue affects quick-media: before v1.0.
Source : NVD
## 5.3
Score
Published January 27, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
com.github.liuyueyi.media:batik-codec-fix
Sources
NVD
Maven Severity MEDIUM No Fi
Wiz
CVE-2025-66614 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2025-66614 [CRITICAL] CVE-2025-66614 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66614 :
Java vulnerability analysis and mitigation
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected.
Tomcat did not validate that the host name provided via the SNI
extension was the same as the host name provided in the HTTP host header
field. If Tomcat was configured with more than one virtual host and the
TLS configuration for one of those hosts did not require client
certificate authentication but another one did, it was possible for a
client to bypass the client certificate authentication by sending
Wiz
CVE-2025-14969 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2025-14969 [MEDIUM] CVE-2025-14969 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14969 :
Java vulnerability analysis and mitigation
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.
Source : NVD
## 4.3
Score
Published January 26, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.hibernate.reactive:hibernate-reactive-core
Sources
NVD
M
Wiz
CVE-2026-22022 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-22022 [HIGH] CVE-2026-22022 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22022 :
Java vulnerability analysis and mitigation
Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to insufficiently strict input validation in those components. Only deployments that meet all of the following criteria are impacted by this vulnerability:
Use of Solr's "RuleBasedAuthorizationPlugin"
A RuleBasedAuthorizationPlugin config (see security.json) that specifies multiple "roles"
A RuleBasedAuthorizationPlugin permission list (see security.json) that uses one or more of the following pre-defined permission rules: "config-read", "config-edit", "schema-read", "metrics-read", or "security-read".
A RuleBasedAuthorizationPlugin permission list t
Wiz
CVE-2026-4874 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-4874 [HIGH] CVE-2026-4874 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4874 :
Java vulnerability analysis and mitigation
client_session_host
backchannel.logout.url
application.session.host
Source : NVD
## 3.1
Score
Published March 26, 2026
Severity LOW
CNA Score 3.1
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak-fips-26.5
cpe:2.3:a:redhat:jboss_enterprise_application_platform
Sources
Chainguard Has Fix Added at: Apr 05, 2026
Maven Severity LOW No Fix Added at: Mar 29, 2026
MinimOS Severity LOW Has Fix Added at: Apr 02, 2026
Linux Severity LOW No Fix Added at: Apr 02, 2026
Windows Severity LOW No Fix Added at: Apr 0
Wiz
CVE-2025-54947 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2025-54947 [CRITICAL] CVE-2025-54947 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-54947 :
Java vulnerability analysis and mitigation
In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access.
This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.
Users are recommended to upgrade to version 2.1.7, which fixes the issue.
Source : NVD
## 9.8
Score
Published December 12, 2025
Severity CRITICAL
CNA Score 5.3
Affected Te
Wiz
CVE-2025-14763 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2025-14763 [MEDIUM] CVE-2025-14763 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14763 :
Java vulnerability analysis and mitigation
Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record.
To mitigate this issue, upgrade Amazon S3 Encryption Client for Java to version 4.0.0 or later.
Source : NVD
## 6
Score
Published December 17, 2025
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Java
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
apache
Wiz
CVE-2026-22739 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-22739 [HIGH] CVE-2026-22739 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22739 :
Java vulnerability analysis and mitigation
Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.
Source : NVD
## 8.6
Score
Published March 24, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 93.6
Exploitation Probability (EPSS) 11.6
Affected pack
Wiz
CVE-2025-68493 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-68493 [HIGH] CVE-2025-68493 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68493 :
Java vulnerability analysis and mitigation
Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users are recommended to upgrade to version 6.1.1, which fixes the issue.
Source : NVD
## 8.1
Score
Published January 11, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Java
Apache Struts
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
javapackages-tools:201801::guice-testlib
javapackages-tools:201801::guice-bom
Sources
Maven Severity HIGH Has Fix Added at: Jan 14, 2026
Wiz
CVE-2026-28368 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-28368 [HIGH] CVE-2026-28368 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28368 :
Java vulnerability analysis and mitigation
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
Source : NVD
## 9.1
Score
Published March 27, 2026
Severity CRITICAL
CNA Score 8.7
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 29.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
pki-deps:10.6::res
Wiz
CVE-2026-1486 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-1486 [HIGH] CVE-2026-1486 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1486 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP's signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.
Source : NVD
## 8.8
Score
Published February 9, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
Wiz
CVE-2025-66169 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-66169 [MEDIUM] CVE-2025-66169 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66169 :
Java vulnerability analysis and mitigation
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
Source : NVD
## 5.3
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.apache.camel:camel-neo4j
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Jan 15, 2026
## Get a C
Wiz
CVE-2026-2575 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-2575 [MEDIUM] CVE-2026-2575 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2575 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and subsequent process termination. This vulnerability allows an attacker to disrupt the availability of the service.
Source : NVD
## 5.3
Score
Published March 18, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.4
Exploitation Probability (EPSS) N/A
Wiz
CVE-2025-67735 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-67735 [MEDIUM] CVE-2025-67735 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67735 :
Java vulnerability analysis and mitigation
io.netty.handler.codec.http.HttpRequestEncoder
HttpRequestEncoder
HttpRequestEncoder
Source : NVD
## 6.5
Score
Published December 16, 2025
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Java
Keycloak
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
elasticsearch-8.19
neo4j-2025.09
Sources
NVD
Chainguard Has Fix Added at: Dec 18, 2025
Debian 11, 12, 13, 14 Severity MEDIUM Has Fix Added at: Dec 18, 2025
Echo Severity MEDIUM Has Fix Added at: Dec 18, 2025
Maven Severity MEDIUM Has Fix Added at: Dec 16, 2025
MinimOS Severity MEDIUM Has Fi
Wiz
GHSA-72hv-8253-57qq Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-72hv-8253-57qq Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-72hv-8253-57qq :
Java vulnerability analysis and mitigation
## Summary
jackson-core
maxNumberLength
StreamReadConstraints
## Details
NonBlockingUtf8JsonParserBase
_finishNumberIntegralPart
TextBuffer
_valueComplete()
resetInt()
resetFloat()
resetInt()
resetFloat()
ParserBase
validateIntegerLength()
validateFPLength()
maxNumberLength
## PoC
The following JUnit 5 test demonstrates the vulnerability. It shows that the async parser accepts a 5,000-digit number, whereas the limit should be 1,000.
package tools.jackson.core.unittest.dos;
import java.nio.charset.StandardCharsets;
import org.junit.jupiter.api.Test;
import tools.jackson.core.*;
import tools.jackson.core.exc.StreamConstraintsException;
import tools.jackson.core.json.JsonFactory;
import tools.jackson
Wiz
CVE-2026-32642 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.3
CVE-2026-32642 [LOW] CVE-2026-32642 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32642 :
Java vulnerability analysis and mitigation
Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized to create the corresponding address. When the OpenWire connection is closed the address is removed.
This issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apach
Wiz
CVE-2025-66560 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2025-66560 [MEDIUM] CVE-2025-66560 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66560 :
Java vulnerability analysis and mitigation
Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerability exists in the HTTP layer of Quarkus REST related to response handling. When a response is being written, the framework waits for previously written response chunks to be fully transmitted before proceeding. If the client connection is dropped during this waiting period, the associated worker thread is never released and becomes permanently blocked. Under sustained or repeated occurrences, this can exhaust the available worker threads, leading to degraded performance, or complete unavailability of the application. This issue has been patched in versions 3.31.0, 3.27.2, and 3.
Wiz
CVE-2025-66518 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-66518 [HIGH] CVE-2025-66518 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66518 :
Java vulnerability analysis and mitigation
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config.
This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2.
Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.
Source : NVD
## 8.8
Score
Published January 5, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.apache.kyuubi:kyuubi-server_2.12
Sources
NVD
Wiz
CVE-2025-53960 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2025-53960 [MEDIUM] CVE-2025-53960 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-53960 :
Java vulnerability analysis and mitigation
When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An attacker can exploit this vulnerability to perform offline brute-force attacks on the user's password using a captured JWT, or to arbitrarily forge identity tokens for the user if the password is already known, ultimately leading to complete account takeover.
This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.
Users are recommended to upgrade to version 2.1.7, which fixes the issue.
Source : NVD
## 5.9
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release
Wiz
CVE-2026-4628 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-4628 [HIGH] CVE-2026-4628 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4628 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false restriction. This occurs due to incomplete enforcement of access control checks on PUT operations to the resource_set endpoint. This issue enables unauthorized modification of protected resources, impacting data integrity.
Source : NVD
## 4.3
Score
Published March 23, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.9
Exploitation Pr
Wiz
CVE-2025-11537 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.0
CVE-2025-11537 [MEDIUM] CVE-2025-11537 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-11537 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.
Source : NVD
## 5
Score
Published February 10, 2026
Severity MEDIUM
CNA Score 5.0
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affec
Wiz
CVE-2025-67641 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-67641 [MEDIUM] CVE-2025-67641 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67641 :
Java vulnerability analysis and mitigation
javascript:
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 8.0
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
jenkins
io.jenkins.plugins:coverage
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, edge Severity MEDIUM No Fix Added at: Dec 18, 2025
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Maven Severity HIGH Has Fix Added at: Dec 11, 2025
Nix Severity MEDIUM No Fix Added at: Dec 18, 2025
## Get a CVE risk asses
Wiz
CVE-2026-24713 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-24713 [CRITICAL] CVE-2026-24713 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24713 :
Java vulnerability analysis and mitigation
Improper Input Validation vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.
Source : NVD
## 9.8
Score
Published March 9, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.apache.iotdb:iotdb-core
Sources
NVD
Maven Severity CRITICAL Has Fix Added at: Mar 11, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your clo
Wiz
CVE-2025-68701 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2025-68701 [HIGH] CVE-2025-68701 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68701 :
Java vulnerability analysis and mitigation
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses deterministic AES IV derivation from a passphrase. This vulnerability is fixed in 2.2.
Source : NVD
## 8.7
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
net.gleske:jervis
Sources
NVD
Maven Severity HIGH Has Fix Added at: Jan 13, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable,
Wiz
CVE-2025-68280 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-68280 [MEDIUM] CVE-2025-68280 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68280 :
Java vulnerability analysis and mitigation
Improper Restriction of XML External Entity Reference vulnerability in Apache SIS.
It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file reveals to the attacker the content of a local file on the server running Apache SIS. This vulnerability impacts the following SIS services:
Reading of GeoTIFF files having the GEO_METADATA tag defined by the Defense Geospatial Information Working Group (DGIWG).
Parsing of ISO 19115 metadata in XML format.
Parsing of Coordinate Reference Systems defined in the GML format.
Parsing of files in GPS Exchange Format (GPX).
This issue affects Apache SIS from versions 0.4 through 1.5 inclusive. Users are recommended to upgrade to version 1.6, which will f
Wiz
CVE-2026-27446 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2026-27446 [CRITICAL] CVE-2026-27446 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27446 :
Java vulnerability analysis and mitigation
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in message injection into any queue and/or message exfiltration from any queue via the rogue broker. This impacts environments that allow both:
incoming Core protocol connections from untrusted sources to the broker
outgoing Core protocol connections from the broker to untrusted targets
This issue affects:
Apache Artemis from 2.50.0 through 2.51.0
Apache ActiveMQ Artemis from 2.11.0 through 2.44.0.
Users
Wiz
CVE-2026-3047 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-3047 [HIGH] CVE-2026-3047 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3047 :
Java vulnerability analysis and mitigation
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.
Source : NVD
## 8.8
Score
Published March 5, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 66.6
Exploitation Probability (EPSS) 0.5
Affecte
Wiz
CVE-2025-70974 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2025-70974 [CRITICAL] CVE-2025-70974 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-70974 :
Java vulnerability analysis and mitigation
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload located elsewhere in that JSON document. This was exploited in the wild in 2023 through 2025. NOTE: this issue exists because of an incomplete fix for CVE-2017-18349. Also, a later bypass is covered by CVE-2022-25845.
Source : NVD
## 10
Score
Published January 9, 2026
Severity CRITICAL
CNA Score 10.0
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA
Wiz
CVE-2026-3190 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-3190 [MEDIUM] CVE-2026-3190 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3190 :
Java vulnerability analysis and mitigation
uma_protection
uma_protection
Source : NVD
## 4.3
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.keycloak:keycloak-model-jpa
org.keycloak:keycloak-server-spi-private
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Mar 29, 2026
MinimOS Severity MEDIUM Has Fix Added at: Mar 31, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vu
Wiz
CVE-2026-23552 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2026-23552 [CRITICAL] CVE-2026-23552 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23552 :
Java vulnerability analysis and mitigation
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.
The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation.
This issue affects Apache Camel: from 4.15.0 before 4.18.0.
Users are recommended to upgrade to version 4.18.0, which fixes the issue.
Source : NVD
## 9.1
Score
Published February 23, 2026
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitatio
Wiz
CVE-2025-67639 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.5
CVE-2025-67639 [LOW] CVE-2025-67639 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67639 :
Java vulnerability analysis and mitigation
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.
Source : NVD
## 3.5
Score
Published December 10, 2025
Severity LOW
CNA Score 3.5
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
jenkins
cpe:2.3:a:jenkins:jenkins
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, edge Severity LOW No Fix Added at: Dec 21, 2025
Alpine 3.22, 3.23 Severity LOW No Fix Ad
Wiz
CVE-2025-26866 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-26866 [HIGH] CVE-2025-26866 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-26866 :
Java vulnerability analysis and mitigation
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks.
Users are recommended to upgrade to version 1.7.0, which fixes the issue.
Source : NVD
## 8.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 8.8
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 82.1
Exploitation Probability (EPSS) 1.7
Affected packages and libra
Wiz
CVE-2026-2741 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.3
CVE-2026-2741 [LOW] CVE-2026-2741 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2741 :
Java vulnerability analysis and mitigation
Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, 15.0.0 through 23.6.6, 24.0.0 through 24.9.8, and 25.0.0 through 25.0.2.
Vaadin’s build process can automatically download and extract Node.js if it is not installed locally. If an attacker can intercept or control this download via DNS hijacking, a MITM attack, a compromised mirror, or a supply chain attack, they can serve a malicious archive containing path traversal sequences that write files outside the intended extraction directory.
Users of affected versions should use a globally preinstalled Node.js version compatible with their Vaadin version, or upgrade as follows: 14.2
Wiz
CVE-2026-1518 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.7
CVE-2026-1518 [LOW] CVE-2026-1518 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1518 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services.
Source : NVD
## 2.7
Score
Published February 2, 2026
Severity LOW
CNA Score 2.7
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.keycloak:keycloak-parent
Sources
NVD
Maven Severity LOW No Fix Added at: Feb 03, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable,
Wiz
CVE-2026-24281 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-24281 [HIGH] CVE-2026-24281 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24281 :
Java vulnerability analysis and mitigation
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
Source : NVD
## 7.4
Score
Published March 7, 2026
Severity HIGH
CNA Score 5.9
Affected Technologies
Java
Apache Solr
Has Public Ex
Wiz
CVE-2025-67637 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2025-67637 [MEDIUM] CVE-2025-67637 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67637 :
Java vulnerability analysis and mitigation
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Source : NVD
## 4.3
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
jenkins-2.504
jenkins-2.516
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, edge
Wiz
CVE-2026-2733 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.8
CVE-2026-2733 [LOW] CVE-2026-2733 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2733 :
Java vulnerability analysis and mitigation
A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client “Enabled” setting to OFF does not fully prevent access. As a result, previously valid credentials can still be used to obtain authentication tokens. This weakens administrative controls and could allow unintended access to container registry resources.
Source : NVD
## 3.8
Score
Published February 19, 2026
Severity LOW
CNA Score 3.8
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (E
Wiz
CVE-2025-59060 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-59060 [MEDIUM] CVE-2025-59060 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59060 :
Java vulnerability analysis and mitigation
Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0.
Users are recommended to upgrade to version 2.8.0, which fixes this issue.
Source : NVD
## 5.3
Score
Published March 3, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 33.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
org.apache.ranger:ranger-nifi-registry-plugin
ranger
Sources
NVD
Alpine 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM No Fix Added
Wiz
CVE-2025-65091 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2025-65091 [CRITICAL] CVE-2025-65091 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-65091 :
Java vulnerability analysis and mitigation
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been patched in version 2.4.5.
Source : NVD
## 10
Score
Published January 10, 2026
Severity CRITICAL
CNA Score 10.0
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 43.3
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
org.xwiki.contrib:macro-fullcalendar-pom
Sources
NVD
Maven Severity CR
Wiz
CVE-2025-12543 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.6
CVE-2025-12543 [CRITICAL] CVE-2025-12543 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12543 :
Java vulnerability analysis and mitigation
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.
Source : NVD
## 9.6
Score
Published January 7, 2026
Severity CRITICAL
CNA Score 9.6
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.7
Exploitation Probability (EPSS) N/A
Affected packages a
Wiz
CVE-2026-28338 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-28338 [MEDIUM] CVE-2026-28338 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28338 :
Java vulnerability analysis and mitigation
vbhtml
yahtml
vbhtml
yahtml
html
Source : NVD
## 6.1
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Java
NixOS
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
pmd
net.sourceforge.pmd:pmd-core
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Mar 02, 2026
Homebrew Severity MEDIUM Has Fix Added at: Mar 04, 2026
Nix Severity MEDIUM Has Fix Added at: Mar 04, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
Wiz
CVE-2026-22729 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-22729 [HIGH] CVE-2026-22729 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22729 :
Java vulnerability analysis and mitigation
A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated into JSONPath queries without proper escaping, enabling attackers to inject arbitrary JSONPath logic and access unauthorized documents.
This vulnerability affects applications using vector stores that extend AbstractFilterExpressionConverter for multi-tenant isolation, role-based access control, or document filtering based on metadata.
The vulnerability occurs when user-supplied values in filter expressions are not escaped before being inserted into JSONPath queries. S
Wiz
CVE-2025-33042 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2025-33042 [HIGH] CVE-2025-33042 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-33042 :
Java vulnerability analysis and mitigation
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas.
This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0.
Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.
Source : NVD
## 7.3
Score
Published February 13, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
apache-pulsar
logstash-9.1
Sources
NVD
Alpine 3.18, 3.1
Wiz
CVE-2025-27821 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2025-27821 [HIGH] CVE-2025-27821 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-27821 :
Java vulnerability analysis and mitigation
Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client.
This issue affects Apache Hadoop: from 3.2.0 before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Source : NVD
## 7.3
Score
Published January 26, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Java
Hadoop
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:apache:hadoop
hadoop
Sources
Maven Severity HIGH Has Fix Added at: Jan 27, 2026
Homebrew Severity HIGH Has Fix Added at: Jan 28, 2026
Nix Severity HIGH Has Fix Added at:
Wiz
CVE-2026-1337 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 1.1
CVE-2026-1337 [LOW] CVE-2026-1337 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1337 :
Java vulnerability analysis and mitigation
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01.
Proof of concept exploit: https://github.com/JoakimBulow/CVE-2026-1337
Source : NVD
## 1.1
Score
Published February 6, 2026
Severity LOW
CNA Score 1.1
Affected Technologies
Java
Neo4j
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.2
Exploitation Probability (EPSS) N/A
Wiz
CVE-2026-33728 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2026-33728 [CRITICAL] CVE-2026-33728 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33728 :
Java vulnerability analysis and mitigation
-javaagent
-Dcom.sun.management.jmxremote.port
DD_INTEGRATION_RMI_ENABLED=false
Source : NVD
## 9.3
Score
Published March 27, 2026
Severity CRITICAL
CNA Score 9.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 73.2
Exploitation Probability (EPSS) 0.8
Affected packages and libraries
com.datadoghq:dd-java-agent
Sources
NVD
Maven Severity CRITICAL Has Fix Added at: Mar 29, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vulnerabilities:
CVE ID
Severity
Score
Technologies
Wiz
CVE-2026-2666 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2026-2666 [MEDIUM] CVE-2026-2666 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2666 :
Java vulnerability analysis and mitigation
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.
Source : NVD
## 5.1
Score
Published February 18, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
net.mingsoft:ms-mcms
Sources
NVD
Maven Severity LOW No Fix A
Wiz
CVE-2025-68702 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2025-68702 [HIGH] CVE-2025-68702 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68702 :
Java vulnerability analysis and mitigation
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(32, '0') when it should use padLeft(64, '0') because SHA-256 produces 32 bytes which equates to 64 hex characters. This vulnerability is fixed in 2.2.
Source : NVD
## 8.7
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
net.gleske:jervis
Sources
NVD
Maven Severity HIGH Has Fix Added at: Jan 13, 2026
## Get a CVE risk assessment
Get a priori
Wiz
CVE-2025-54981 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-54981 [HIGH] CVE-2025-54981 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-54981 :
Java vulnerability analysis and mitigation
Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data
This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.
Users are recommended to upgrade to version 2.1.7, which fixes the issue.
Source : NVD
## 7.5
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.apache.streampark:streampark
Sourc
Wiz
CVE-2026-27830 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.9
CVE-2026-27830 [HIGH] CVE-2026-27830 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27830 :
Java vulnerability analysis and mitigation
javax.naming.Reference
ConnectionPoolDataSource
userOverridesAsString
Map>
ConnectionPoolDataSource
javax.naming.Reference
CLASSPATH
factoryClassLocation
userOverridesAsString
javax.naming.Reference
factoryClassLocation
userOverridesAsString
ConnectionPoolDataSource
factoryClassLocation
com.mchange.v2.naming.nameGuardClassName
Source : NVD
## 8.9
Score
Published February 26, 2026
Severity HIGH
CNA Score 8.9
Affected Technologies
Java
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 47.5
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
debezium-3.3
mchange-commons
Sources
NVD
Cha
Wiz
CVE-2025-14306 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2025-14306 [CRITICAL] CVE-2025-14306 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14306 :
Java vulnerability analysis and mitigation
A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/
Source : NVD
## 10
Score
Published December 9, 2025
Severity CRITICAL
CNA Score 10.0
Affected Technologies
Java
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 69
Exploitati
Wiz
CVE-2026-24308 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-24308 [HIGH] CVE-2026-24308 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24308 :
Java vulnerability analysis and mitigation
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue.
Source : NVD
## 7.5
Score
Published March 7, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
Java
Apache Solr
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.5
Exploitation Probability (EPSS) N/A
Affected
Wiz
CVE-2026-33701 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2026-33701 [CRITICAL] CVE-2026-33701 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33701 :
Java vulnerability analysis and mitigation
-javaagent
-Dcom.sun.management.jmxremote.port
-Dotel.instrumentation.rmi.enabled=false
Source : NVD
## 9.3
Score
Published March 27, 2026
Severity CRITICAL
CNA Score 9.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 60.9
Exploitation Probability (EPSS) 0.4
Affected packages and libraries
com.splunk:splunk-otel-javaagent
io.opentelemetry.javaagent:opentelemetry-javaagent
Sources
NVD
Maven Severity CRITICAL Has Fix Added at: Mar 26, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Relat
Wiz
CVE-2026-24400 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-24400 [HIGH] CVE-2026-24400 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24400 :
Java vulnerability analysis and mitigation
org.assertj.core.util.xml.XmlStringPrettyFormatter
toXmlDocument(String)
DocumentBuilderFactory
isXmlEqualTo(CharSequence)
CharSequence
isXmlEqualTo(CharSequence)
org.assertj.core.api.AbstractCharSequenceAssert
xmlPrettyFormat(String)
org.assertj.core.util.xml.XmlStringPrettyFormatter
file://
/etc/passwd
isXmlEqualTo(CharSequence)
isXmlEqualTo(CharSequence)
isXmlEqualTo(CharSequence)
XmlStringPrettyFormatter
XmlStringPrettyFormatter
isXmlEqualTo(CharSequence)
Source : NVD
## 8.2
Score
Published January 26, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
Java
Apache Log4j
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability
Wiz
CVE-2025-66474 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2025-66474 [HIGH] CVE-2025-66474 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66474 :
Java vulnerability analysis and mitigation
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 have insufficient protection against {{/html}} injection, which attackers can exploit through RCE. Any user who can edit their own profile or any other document can execute arbitrary script macros, including Groovy and Python macros, which enable remote code execution as well as unrestricted read and write access to all wiki contents. This issue is fixed in versions 16.10.10, 17.4.3 and 17.6.0-rc-1.
Source : NVD
## 8.7
Score
Published December 10, 2025
Severity HIGH
CNA Score 8.7
Affe
Wiz
CVE-2025-66024 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2025-66024 [HIGH] CVE-2025-66024 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66024 :
Java vulnerability analysis and mitigation
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arises because the post title is injected directly into the HTML tag without proper escaping. An attacker with permissions to create or edit blog posts can inject malicious JavaScript into the title field. This script will execute in the browser of any user (including administrators) who views the blog post. This leads to potential session hijacking or privilege escalation. The vulnerability has been patched in the blog application version 9.15.7 by adding missing escaping. No known workarounds are available.
Sour
Wiz
CVE-2025-11419 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-11419 [HIGH] CVE-2025-11419 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-11419 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by repeatedly initiating TLS 1.2 client-initiated renegotiation requests to exhaust server CPU resources, making the service unavailable.
Source : NVD
## 7.5
Score
Published December 23, 2025
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
org.keycloak:keycloak-quarkus-dist
Sources
NVD
Maven Severity HIGH Has Fix Added at: Oct 28, 2025
## Get a CVE risk assessment
Wiz
CVE-2025-68925 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2025-68925 [MEDIUM] CVE-2025-68925 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68925 :
Java vulnerability analysis and mitigation
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header specifies "alg":"RS256". This vulnerability is fixed in 2.2.
Source : NVD
## 6.9
Score
Published January 13, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
net.gleske:jervis
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Jan 13, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's
Wiz
CVE-2025-66524 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-66524 [HIGH] CVE-2025-66524 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66524 :
Java vulnerability analysis and mitigation
Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserialization without filtering. Unfiltered Java object deserialization does not provide protection against crafted state information stored in the cache server configured for GetAsanaObject. Exploitation requires an Apache NiFi system running with the GetAsanaObject Processor, and direct access to the configured cache server. Upgrading to Apache NiFi 2.7.0 is the recommended mitigation, which replaces Java Object serialization with JSON serialization. Remo
Wiz
CVE-2025-14674 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-14674 [MEDIUM] CVE-2025-14674 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14674 :
Java vulnerability analysis and mitigation
A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java. The manipulation results in injection. The attack can be launched remotely. Upgrading to version 1.7.0-beta1 addresses this issue. The patch is identified as 978f316c38b3d68bb74d2489b5e5f721f6675e86. The affected component should be upgraded.
Source : NVD
## 5.3
Score
Published December 14, 2025
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Expl
Wiz
CVE-2025-66033 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-66033 [MEDIUM] CVE-2025-66033 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66033 :
Java vulnerability analysis and mitigation
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1.
Source : NVD
## 5.3
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Ha
Wiz
CVE-2026-1190 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.1
CVE-2026-1190 [LOW] CVE-2026-1190 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1190 :
Java vulnerability analysis and mitigation
NotOnOrAfter
SubjectConfirmationData
Source : NVD
## 3.1
Score
Published January 26, 2026
Severity LOW
CNA Score 3.1
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak-26.5
keycloak-fips-26.5
Sources
NVD
Chainguard Has Fix Added at: Feb 11, 2026
Maven Severity LOW No Fix Added at: Jan 28, 2026
MinimOS Severity LOW Has Fix Added at: Feb 11, 2026
Wolfi Has Fix Added at: Feb 11, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not
Wiz
CVE-2026-26010 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.6
CVE-2026-26010 [HIGH] CVE-2026-26010 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26010 :
Java vulnerability analysis and mitigation
OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies). This vulnerability is fixed in 1.11.8.
Source : NVD
## 7.6
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.6
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due
Wiz
CVE-2026-1605 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-1605 [HIGH] CVE-2026-1605 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1605 :
Java vulnerability analysis and mitigation
In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed.
This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response.
In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.
Source : NVD
## 7.5
Score
Published March 5, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Expl
Wiz
CVE-2026-24802 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-24802 [MEDIUM] CVE-2026-24802 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24802 :
Java vulnerability analysis and mitigation
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in briandilley jsonrpc4j (src/main/java/com/googlecode/jsonrpc4j modules). This vulnerability is associated with program files NoCloseOutputStream.Java.
This issue affects jsonrpc4j: through 1.6.0.
Source : NVD
## 5.3
Score
Published January 27, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
com.github.briandilley.jsonrpc4j:jsonrpc4j
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Jan 28, 2026
## Get a CVE risk
Wiz
CVE-2026-27100 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-27100 [MEDIUM] CVE-2026-27100 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27100 :
Java vulnerability analysis and mitigation
Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name.
Source : NVD
## 4.3
Score
Published February 18, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 33.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:jenkins:jenkins
cpe:2.3:a:je
Wiz
CVE-2024-4027 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2024-4027 [HIGH] CVE-2024-4027 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-4027 :
Java vulnerability analysis and mitigation
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.
Source : NVD
## 7.5
Score
Published January 30, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 49
Exploitation Probability (EPSS) 0.3
Affected packages and libraries
io.undertow:undertow-core
undertow
Sources
NVD
Debian 14 Severity HIGH No Fix Added
Wiz
CVE-2026-34214 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2026-34214 [HIGH] CVE-2026-34214 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34214 :
Java vulnerability analysis and mitigation
Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users that have write privilege on SQL level. This issue has been patched in version 480.
Source : NVD
## 6.5
Score
Published March 31, 2026
Severity MEDIUM
CNA Score 7.7
Affected Technologies
Java
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
io.trino:trino-iceberg
trino
Sources
NVD
Chainguard Has Fix Added at:
Wiz
CVE-2025-64087 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2025-64087 [CRITICAL] CVE-2025-64087 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64087 :
Java vulnerability analysis and mitigation
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.
Source : NVD
## 9.8
Score
Published January 20, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
fr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarker
Sources
NVD
Maven Severity CRITICAL Has Fix Added at: Jan 22, 2026
## Get a CVE risk assessment
Get a prio
Wiz
GHSA-43w5-mmxv-cpvh Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-43w5-mmxv-cpvh Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-43w5-mmxv-cpvh :
Java vulnerability analysis and mitigation
JsonBeanPropertyBinder::expandArrayToThreshold
io.micronaut:micronaut-json-core
authors[1].name
authors[0].name
## Example
With such an application
package dosform;
import io.micronaut.http.HttpResponse;
import io.micronaut.http.MediaType;
import io.micronaut.http.annotation.Body;
import io.micronaut.http.annotation.Consumes;
import io.micronaut.http.annotation.Controller;
import io.micronaut.http.annotation.Get;
import io.micronaut.http.annotation.Post;
import io.micronaut.http.annotation.Produces;
import java.net.URI;
@Controller
class HomeController {
@Produces(MediaType.TEXT_HTML)
@Get
String index() {
return """
Fist Author
Second Author
Third Author
Submit
""";
}
@Consumes(MediaType.APPLICATI
Wiz
CVE-2025-67642 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2025-67642 [MEDIUM] CVE-2025-67642 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67642 :
Java vulnerability analysis and mitigation
Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.
Source : NVD
## 4.3
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 35
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
jenkins
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17,
Wiz
CVE-2025-14307 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2025-14307 [CRITICAL] CVE-2025-14307 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14307 :
Java vulnerability analysis and mitigation
An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attackers to exploit race conditions and potentially execute arbitrary code or overwrite critical files. This vulnerability can be exploited by manipulating the temporary file creation process, leading to potential unauthorized actions.
Source : NVD
## 9.3
Score
Published December 9, 2025
Severity CRITICAL
CNA Score 9.3
Affected Technologies
Java
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.9
Exploitation Probabili
Wiz
CVE-2026-3009 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-3009 [HIGH] CVE-2026-3009 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3009 :
Java vulnerability analysis and mitigation
A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.
Source : NVD
## 8.1
Score
Published March 5, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9
Exploitation Probabi
Wiz
CVE-2026-1050 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-1050 [MEDIUM] CVE-2026-1050 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1050 :
Java vulnerability analysis and mitigation
A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Source : NVD
## 6.9
Score
Published January 17, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.6
Exploit
Wiz
CVE-2026-24015 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-24015 [CRITICAL] CVE-2026-24015 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24015 :
Java vulnerability analysis and mitigation
A vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7.
Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.
Source : NVD
## 9.8
Score
Published March 9, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.apache.iotdb:iotdb-core
Sources
NVD
Maven Severity CRITICAL Has Fix Added at: Mar 11, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on wh
Wiz
CVE-2025-67030 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-67030 [HIGH] CVE-2025-67030 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67030 :
Java vulnerability analysis and mitigation
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
Source : NVD
## 8.8
Score
Published March 25, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Java
Maven
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 47.9
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
javapackages-tools:201801::maven-artifact-transfer-javadoc
javapackages-tools:201801::plexus-containers-container-default
Sources
NVD
Chainguard Has Fix Added at: Mar 29, 2026
Deb
Wiz
CVE-2026-4636 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-4636 [HIGH] CVE-2026-4636 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4636 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.
Source : NVD
## 8.1
Score
Published April 2, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Ex
Wiz
CVE-2026-28367 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-28367 [HIGH] CVE-2026-28367 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28367 :
Java vulnerability analysis and mitigation
\r\r\r
Source : NVD
## 8.7
Score
Published March 27, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Java
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
io.undertow:undertow-parent
undertow
Sources
NVD
Debian 14 Severity HIGH No Fix Added at: Mar 29, 2026
Maven Severity HIGH No Fix Added at: Apr 02, 2026
Red Hat 8 Severity HIGH No Fix Added at: Mar 29, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vulnera
Wiz
CVE-2026-33004 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-33004 [MEDIUM] CVE-2026-33004 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33004 :
Java vulnerability analysis and mitigation
Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Source : NVD
## 4.3
Score
Published March 18, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.jenkins-ci.plugins:loadninja
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Mar 20, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable
Wiz
CVE-2026-22723 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-22723 [MEDIUM] CVE-2026-22723 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22723 :
Java vulnerability analysis and mitigation
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
Source : NVD
## 6.5
Score
Published March 5, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
org.cloudfoundry.identity:cloudfoundry-identity-server
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Mar 09, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so
Wiz
CVE-2026-29000 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2026-29000 [CRITICAL] CVE-2026-29000 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-29000 :
Java vulnerability analysis and mitigation
pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.
Source : NVD
## 9.3
Score
Published March 4, 2026
Severity CRITICAL
CNA Score 9.3
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.9
Exploitation Probability (EPSS) 0.1
Affected
Wiz
CVE-2026-24819 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2026-24819 [MEDIUM] CVE-2026-24819 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24819 :
Java vulnerability analysis and mitigation
Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/foxinmy/weixin4j/util modules). This vulnerability is associated with program files CharArrayBuffer.Java, ClassUtil.Java.
This issue affects weixin4j.
Source : NVD
## 6.3
Score
Published January 27, 2026
Severity MEDIUM
CNA Score 6.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
com.foxinmy:weixin4j-base
Sources
NVD
Maven Severity MEDIUM No Fix Added at: Jan 28, 2026
## Get a CVE risk assessment
Ge
Wiz
GHSA-443w-3rq3-5m5h Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-443w-3rq3-5m5h Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-443w-3rq3-5m5h :
Java vulnerability analysis and mitigation
## Summary
This notification is related to the CloudFront signing utilities in the AWS SDK for Java v2, which are used to generate Amazon CloudFront signed URLs and signed cookies. A defense-in-depth enhancement has been implemented to improve handling of special characters, such as double quotes and backslashes, in input values.
## Impact
The CloudFront signing utilities build policy documents that define access restrictions for signed URLs and cookies. If an application passes unsanitized input containing special characters to these utilities, the resulting policy document may not reflect the application's intended access restrictions. While the SDK was functioning safely within the requirements of the shared res
Wiz
CVE-2026-3872 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2026-3872 [HIGH] CVE-2026-3872 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3872 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.
Source : NVD
## 7.3
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak
keycloak-fips
Sources
NVD
Chainguard Has Fix Added at: Apr 05, 2026
Maven
Wiz
CVE-2025-68704 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2025-68704 [HIGH] CVE-2025-68704 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68704 :
Java vulnerability analysis and mitigation
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.
Source : NVD
## 8.2
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15
Exploitation Probability (EPSS) N/A
Affected packages and libraries
net.gleske:jervis
Sources
NVD
Maven Severity HIGH Has Fix Added at: Jan 13, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so y
Wiz
CVE-2026-3911 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.7
CVE-2026-3911 [LOW] CVE-2026-3911 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3911 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
Source : NVD
## 2.7
Score
Published March 11, 2026
Severity LOW
CNA Score 2.7
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak
keycloak-fips
Sources
NVD
Chaing
Wiz
CVE-2025-67635 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-67635 [HIGH] CVE-2025-67635 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67635 :
Java vulnerability analysis and mitigation
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
Source : NVD
## 7.5
Score
Published December 10, 2025
Severity HIGH
CNA Score 7.5
Affected Technologies
Java
Jenkins
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 30.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
jenkins-2.528
jenkins-2.504
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, edge Severity HIGH No Fix Added at: Dec 18, 2025
Alpine
Wiz
CVE-2025-54920 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-54920 [HIGH] CVE-2025-54920 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-54920 :
Java vulnerability analysis and mitigation
This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.
Summary
Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to overly permissive Jackson deserialization of event log data. This allows an attacker with access to the Spark event logs directory to inject malicious JSON payloads that trigger deserialization of arbitrary classes, enabling command execution on the host running the Spark History Server.
Details
The vulnerability arises because the Spark History Server uses Jackson polymorphic deserialization with @JsonTypeInfo.Id.CLASS on SparkListenerEvent objects, allo
Wiz
CVE-2026-29062 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-29062 [HIGH] CVE-2026-29062 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-29062 :
Java vulnerability analysis and mitigation
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a java.io.DataInput source, bypasses the maxNestingDepth constraint (default: 500) defined in StreamReadConstraints. A similar issue was found in ReaderBasedJsonParser. This allows a user to supply a JSON document with excessive nesting, which can cause a StackOverflowError when the structure is processed, leading to a Denial of Service (DoS). This issue has been patched in version 3.1.0.
Source : NVD
## 8.7
Score
Published March 6, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Wiz
CVE-2026-23795 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.9
CVE-2026-23795 [MEDIUM] CVE-2026-23795 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23795 :
Java vulnerability analysis and mitigation
Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console.
An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby causing sensitive data leakage occurs.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
Source : NVD
## 4.9
Score
Published February 3, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 26.6
Expl
Wiz
CVE-2026-2092 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2026-2092 [HIGH] CVE-2026-2092 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2092 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response. This allows the attacker to inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.
Source : NVD
## 7.7
Score
Published March 18, 2026
Severity HIGH
CNA Score 7.7
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.3
Exploitatio
Wiz
CVE-2026-33013 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-33013 [HIGH] CVE-2026-33013 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33013 :
Java vulnerability analysis and mitigation
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.
Source : NVD
## 8.2
Score
Published March 20, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
Java
NixOS
Has Public Exploit Yes
Has CISA KEV Exploit No
Wiz
CVE-2025-12150 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.1
CVE-2025-12150 [LOW] CVE-2025-12150 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12150 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.
Source : NVD
## 3.1
Score
Published February 27, 2026
Severity LOW
CNA Score 3.1
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected p
Wiz
GHSA-2m67-wjpj-xhg9 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-2m67-wjpj-xhg9 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-2m67-wjpj-xhg9 :
Java vulnerability analysis and mitigation
## Summary
StreamReadConstraints.maxDocumentLength
StreamConstraintsException
## Details
maxDocumentLength
## 1. Blocking parsers skip validation of the final in-memory buffer
Blocking parsers validate only previously processed buffers, not the final in-memory buffer:
ReaderBasedJsonParser.java:255
UTF8StreamJsonParser.java:208
_currInputProcessed += bufSize;
_streamReadConstraints.validateDocumentLength(_currInputProcessed);
This means the check occurs only when a completed buffer is rolled over. If an oversized document is fully contained in the final buffer, parsing can complete without any document-length exception.
## 2. Async parsers skip validation of the final chunk on end-of-input
Async parser
Wiz
CVE-2026-1180 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2026-1180 [MEDIUM] CVE-2026-1180 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1180 :
Java vulnerability analysis and mitigation
A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue allows a client to specify an arbitrary jwks_uri, which Keycloak then retrieves without validating the destination. This enables attackers to coerce the Keycloak server into making HTTP requests to internal or restricted network resources. As a result, attackers can probe internal services and cloud metadata endpoints, creating an information disclosure and reconnaissance risk.
Source : NVD
## 5.8
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.8
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due
Wiz
GHSA-93fv-4pm9-xp28 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
[HIGH] GHSA-93fv-4pm9-xp28 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-93fv-4pm9-xp28 :
Java vulnerability analysis and mitigation
## Impact
Message#getComponents
sendMessageComponents
Thumbnail
FileDisplay
MediaGallery
## Patches
This bug has been fixed in 6.1.3, and we recommend updating.
## Workarounds
Avoid sending components from untrusted messages or update to version 6.1.3.
Source : NVD
## 6.9
Score
Published December 9, 2025
Severity MEDIUM
CNA Score N/A
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
net.dv8tion:jda
net.dv8tion:JDA
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Dec 09, 2025
## Get a CVE risk asses
Wiz
CVE-2026-24806 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-24806 [MEDIUM] CVE-2026-24806 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24806 :
Java vulnerability analysis and mitigation
Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/png modules). This vulnerability is associated with program files PNGImageEncoder.Java.
This issue affects quick-media: before v1.0.
Source : NVD
## 5.3
Score
Published January 27, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
com.github.liuyueyi.media:batik-codec-fix
Sources
NVD
Maven Severity MEDIUM N
Wiz
CVE-2025-67721 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2025-67721 [MEDIUM] CVE-2025-67721 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67721 :
Java vulnerability analysis and mitigation
Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions 3.3 and below, incorrect handling of malformed data in Java-based decompressor implementations for Snappy and LZ4 allow remote attackers to read previous buffer contents via crafted compressed input. With certain crafted compressed inputs, elements from the output buffer can end up in the uncompressed output, potentially leaking sensitive data. This is relevant for applications that reuse the same output buffer to uncompress multiple inputs. This can be the case of a web server that allocates a fix-sized buffer for performance purposes. There is similar vulnerability in GHSA-cmp6-m4wj-q63q. This issue is fi
Wiz
CVE-2026-27099 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.0
CVE-2026-27099 [HIGH] CVE-2026-27099 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27099 :
Java vulnerability analysis and mitigation
Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.
Source : NVD
## 8
Score
Published February 18, 2026
Severity HIGH
CNA Score 8.0
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
org.jenkins-ci.main:jenkins-core
jenkins
Sources
Alpine 3.23,
Wiz
CVE-2026-34361 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2026-34361 [CRITICAL] CVE-2026-34361 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34361 :
Java vulnerability analysis and mitigation
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a startsWith() URL prefix matching flaw in the credential provider (ManagedWebAccessUtils.getServer()), an attacker can steal authentication tokens (Bearer, Basic, API keys) configured for legitimate FHIR servers by registering a domain that prefix-matches a configured server URL. This issue has been patched in version 6.9.4.
Source : NVD
## 9.3
Score
Published March 31, 2026
Severity CRITICAL
CNA Score 9.3
Affected Technologies
Java
Ha
Wiz
CVE-2026-22738 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-22738 [CRITICAL] CVE-2026-22738 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22738 :
Java vulnerability analysis and mitigation
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key are affected.
This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
Source : NVD
## 9.8
Score
Published March 27, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 26
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
org
Wiz
CVE-2025-37731 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2025-37731 [MEDIUM] CVE-2025-37731 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-37731 :
Java vulnerability analysis and mitigation
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.
Source : NVD
## 7.4
Score
Published December 15, 2025
Severity HIGH
CNA Score 6.8
Affected Technologies
Java
Elasticsearch
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15
Exploitation Probability (EPSS) N/A
Affected packages and libraries
sonarqube
elasticsearch-8.19
Sources
NVD
Chainguard Has Fix Added at: Dec 26, 2025
Maven Severity MEDIUM Has Fix Added at: Dec 17
Wiz
CVE-2026-21452 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-21452 [HIGH] CVE-2026-21452 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21452 :
Java vulnerability analysis and mitigation
MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforcing any upper bound. A malicious .msgpack file of only a few bytes can therefore trigger unbounded heap allocation, resulting in JVM heap exhaustion, process termination, or service unavailability. This vulnerability is triggered durin
Wiz
CVE-2026-22244 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.5
CVE-2026-22244 [HIGH] CVE-2026-22244 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22244 :
Java vulnerability analysis and mitigation
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.
Source : NVD
## 8.5
Score
Published January 8, 2026
Severity HIGH
CNA Score 8.5
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 65.2
Exploitation Probability (EPSS) 0.5
Affected packages and libraries
org.open-metadata:platform
Sources
NVD
Maven Severity HIGH Has Fix Added at: Jan 08, 2026
## Get a C
Wiz
CVE-2026-4633 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-4633 [HIGH] CVE-2026-4633 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4633 :
Java vulnerability analysis and mitigation
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.
Source : NVD
## 3.7
Score
Published March 23, 2026
Severity LOW
CNA Score 3.7
Affected Technologies
Java
Keycloak
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak
keycloak-fips
Sources
NVD
Chainguard Has Fix Added at: Apr 05, 2026
Maven Severity LOW
Wiz
CVE-2026-25526 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-25526 [CRITICAL] CVE-2026-25526 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25526 :
Java vulnerability analysis and mitigation
JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.
Source : NVD
## 9.8
Score
Published February 4, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
Java
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ka
Wiz
CVE-2025-68931 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2025-68931 [HIGH] CVE-2025-68931 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68931 :
Java vulnerability analysis and mitigation
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2.
Source : NVD
## 8.7
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
net.gleske:jervis
Sources
NVD
Maven Severity HIGH Has Fix Added at: Jan 13, 2026
## Get a CVE risk assessment
Get a prioritized view of C
Wiz
CVE-2025-66168 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-66168 [MEDIUM] CVE-2025-66168 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66168 :
Java vulnerability analysis and mitigation
Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted.
This issue affects Apache ActiveMQ: before 5.19.2, 6
Wiz
CVE-2026-33003 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-33003 [MEDIUM] CVE-2026-33003 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33003 :
Java vulnerability analysis and mitigation
Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Source : NVD
## 4.3
Score
Published March 18, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.jenkins-ci.plugins:loadninja
Sources
NVD
Maven Severity MEDIUM Has Fix Added at: Mar 20, 2026
## Get a CVE risk assessment
Get a prioritized v
Wiz
CVE-2026-25747 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-25747 [HIGH] CVE-2026-25747 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25747 :
Java vulnerability analysis and mitigation
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component.
The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. An attacker who can write to the LevelDB database files used by a Camel application can inject a crafted serialized Java object that, when deserialized during normal aggregation repository operations, results in arbitrary code execution in the context of the application.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.5, from 4.15.0 before 4.18.0.
Users are recommended to upgrade to version 4.18.0
Wiz
CVE-2026-27727 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.9
CVE-2026-27727 [HIGH] CVE-2026-27727 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27727 :
Java vulnerability analysis and mitigation
factoryClassLocation
jaxax.naming.Reference
false
com.sun.jndi.ldap.object.trustURLCodebase
Source : NVD
## 8.9
Score
Published February 25, 2026
Severity HIGH
CNA Score 8.9
Affected Technologies
Java
Wolfi
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
c3p0-javadoc
mchange-commons-javadoc
Sources
NVD
Chainguard Has Fix Added at: Mar 02, 2026
Maven Severity HIGH Has Fix Added at: Mar 02, 2026
Wolfi Has Fix Added at: Mar 08, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's explo
Wiz
CVE-2026-33180 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-33180 [HIGH] CVE-2026-33180 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33180 :
Java vulnerability analysis and mitigation
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the Location: response header value. Sending the same set of headers to subsequent hosts is a problem as this header often contains privacy sensitive information or data that could allow others to impersonate the client's request. This issue has been patched in release 6.9.0. No known workarounds are available.
Source : NVD
## 7.5
Score
Published March 20, 2026
Severit
Wiz
CVE-2026-22730 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-22730 [HIGH] CVE-2026-22730 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22730 :
Java vulnerability analysis and mitigation
A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands.
The vulnerability exists due to missing input sanitization.
Source : NVD
## 8.8
Score
Published March 18, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Java
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.springframework.ai:spring-ai-mariadb-store
Sources
NVD
Maven Severity HIGH Has Fix Added at: Mar 19, 2026
## Get a CVE risk assessment
Get a priorit
Wiz
CVE-2026-34359 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-34359 [HIGH] CVE-2026-34359 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34359 :
Java vulnerability analysis and mitigation
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authentication credential dispatch. Because configured server URLs (e.g., http://tx.fhir.org ) lack a trailing slash or host boundary check, an attacker-controlled domain like http://tx.fhir.org.attacker.com matches the prefix and receives Bearer tokens, Basic auth credentials, or API keys when the HTTP client follows a redirect to that domain. This issue has been patched in version 6.9.4.
Source : NVD
## 9.1
Score
Published March 31, 2026
Severity CRITICAL
CNA Score 7.4
Affec
Wiz
CVE-2026-1225 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 1.8
CVE-2026-1225 [LOW] CVE-2026-1225 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1225 :
Java vulnerability analysis and mitigation
ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.
The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.
Source : NVD
## 1.8
Score
Published January 22, 2026
Severity LOW
CNA Score 1.8
Affected Technologies
Java
Apache Log4j
Has Public Exploit No
Has CISA KEV Exploi
Wiz
CVE-2025-59355 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-59355 [MEDIUM] CVE-2025-59355 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59355 :
Java vulnerability analysis and mitigation
A vulnerability.
When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contains sensitive information such as Hive Metastore keys, plaintext passwords will be left in the log files when decoding fails, resulting in information leakage.
Affected Scope
Component: Sensitive fields in hive-site.xml (e.g., javax.jdo.option.ConnectionPassword) or other fields encoded in Base64.
Version: Apache Linkis 1.0.0 – 1.7.0
Trigger Conditions
The value of the configuration item is an invalid Base64 string.
Log files are readable by users other than hive-site.xml administrators.
S
Wiz
CVE-2026-24733 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.7
CVE-2026-24733 [LOW] CVE-2026-24733 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24733 :
Java vulnerability analysis and mitigation
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security
constraint was configured to allow HEAD requests to a URI but deny GET
requests, the user could bypass that constraint on GET requests by
sending a (specification invalid) HEAD request using HTTP/0.9.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.
Older, EOL versions are also affected.
Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
Source : NVD
## 3.7
Score
Published February 17, 2026
Severity LOW
CNA Score 6.5
Affected Technologi
Wiz
CVE-2025-67505 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2025-67505 [HIGH] CVE-2025-67505 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67505 :
Java vulnerability analysis and mitigation
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
Source : NVD
## 8.4
Score
Published December 10, 2025
Severity HIGH
CNA Score 8.4
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
com.okta.sdk:okta-sdk-root
Sources
NVD
Maven
https://access.redhat.com/errata/RHSA-2026:6475https://access.redhat.com/errata/RHSA-2026:6476https://access.redhat.com/errata/RHSA-2026:6477https://access.redhat.com/errata/RHSA-2026:6478https://access.redhat.com/security/cve/CVE-2026-4636https://bugzilla.redhat.com/show_bug.cgi?id=2450251https://access.redhat.com/errata/RHSA-2026:6475https://access.redhat.com/errata/RHSA-2026:6476https://access.redhat.com/errata/RHSA-2026:6477https://access.redhat.com/errata/RHSA-2026:6478https://access.redhat.com/security/cve/CVE-2026-4636https://bugzilla.redhat.com/show_bug.cgi?id=2450251https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4636.json
2026-04-02
Published