An open index of dependabot pull requests across open source projects.

Security Advisories

Browse security advisories and track which Dependabot PRs address them.

37,666

Total Advisories

3,550

With Dependabot PRs

4,878

Critical Severity

13,364

High Severity

jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)
GHSA-7hhh-6rmp-j9qf CVE-2026-89425 HIGH 1 day ago
## Status **FULLY REPRODUCED.** A malformed token fed through `createParser(DataInput)` produced a 20,000,109-character exception message from a 2...
maven
1
Dependabot PRs
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()
GHSA-p6pp-m3f8-5c89 CVE-2026-89407 HIGH 1 day ago
## Status **FULLY REPRODUCED** with a clean, textbook empirical signature: measured runtime grew almost exactly 4x for every doubling of input siz...
maven
No PRs yet
jackson-databind quadratic forward-reference completion
GHSA-cxp5-3px4-pw24 CVE-2026-91777 HIGH 2 days ago
### Summary When an `@JsonIdentityInfo` collection or map first creates N unresolved object-ID references and later resolves the same IDs in rever...
maven
1
Dependabot PRs
jackson-databind retains every unknown raw type ID
GHSA-wv8q-qhhj-9h54 CVE-2026-91776 HIGH 2 days ago
### Summary With `@JsonTypeInfo(use = Id.NAME, defaultImpl = ...)`, every distinct unknown raw type ID selects the same fallback deserializer but ...
maven
No PRs yet
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
GHSA-gx83-3vf8-gh7j CVE-2026-83557 MODERATE 4 days ago
### Summary `DefaultBaseTypeLimitingValidator` — the `PolymorphicTypeValidator` used automatically whenever `@JsonTypeInfo` is applied without an e...
maven
No PRs yet
jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
GHSA-q4xh-88c3-wmh7 CVE-2026-68497 HIGH 4 days ago
### Summary `jackson-databind` 3.2.1 deserializes a JSON **string** bound to a `javax.xml.datatype.Duration` or `javax.xml.datatype.XMLGregorianCal...
maven
No PRs yet
jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution
GHSA-wjgm-6hv5-3cvf CVE-2026-19032 MODERATE 4 days ago
### Summary A `java.nio.file.Path` field bound from untrusted JSON reaches `JDKFromStringDeserializer.NioPathHelper.deserialize`. The attacker str...
maven
No PRs yet
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization
GHSA-vvgp-rfg2-7rr6 CVE-2026-77310 MODERATE 4 days ago
### Summary CVE-2026-54514 (GHSA-hgj6-7826-r7m5) fixed an eager-DNS-resolution / SSRF issue in jackson-databind's deserialization of `java.net.Inet...
maven
No PRs yet
http4s-scala-xml has an XML External Entity (XXE) processing issue
GHSA-cjx3-73hr-rpw7 CVE-2026-61741 CRITICAL 8 days ago
http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. These decoders used a `javax.xml.parsers.SAXP...
maven
No PRs yet
Jawn: Quadratic parsing effort in AsyncParser
GHSA-w4cm-gvhj-cgw6 CVE-2026-61814 HIGH 9 days ago
`AsyncParser` can be forced to perform O(n^2) work on the length of the input. When a single JSON token arrives across many small chunks, each `ab...
maven
No PRs yet
Jawn: Uncontrolled nesting depth in JSON parser
GHSA-cc4v-rvgp-2pf3 CVE-2026-59990 HIGH 9 days ago
The Jawn parser before 1.6.1 is vulnerable to a denial of service attack via untrusted input. ### Impact A remote attacker who can submit JSON to...
maven
No PRs yet
JLine: ReDoS in Nano Editor Regex Search Mode
GHSA-ph9c-7hw9-vhhw CVE-2026-77421 MODERATE 9 days ago
### Summary When regex search mode is enabled in the JLine3 `nano` editor, the user-supplied search term is compiled directly as a Java regular ex...
maven
No PRs yet
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping
GHSA-r2xf-8xr9-62gw CVE-2026-77422 HIGH 9 days ago
### Summary The JLine3 built-in `grep` command wraps the user-supplied regular expression with `.*` before compiling it with Java's backtracking r...
maven
No PRs yet
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable
GHSA-5q95-hrpc-m3w3 CVE-2026-77420 MODERATE 9 days ago
### Summary The JLine3 `HISTORY_IGNORE` variable is converted into a Java regular expression with only partial escaping. As a result, regex metach...
maven
No PRs yet
Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug
GHSA-5f42-97gr-vfhq CVE-2026-85724 CRITICAL 9 days ago
moquette is reachable by untrusted MQTT clients (anonymous by default), so every byte from any client, including pre-authentication, is untrusted. ...
maven
No PRs yet
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
GHSA-m9c2-85gv-8xr5 CVE-2026-69190 MODERATE 10 days ago
### Impact A vulnerability was found in Graylog's API endpoint for updating saved searches and dashboards. A user with edit permissions on a dashb...
maven
No PRs yet
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
GHSA-7952-gx68-cjqr CVE-2026-65829 MODERATE 10 days ago
### Impact When reading a suitably crafted PRX or STX file, MPXJ can be made to write files to arbitrary locations in the file system. ### Patches...
maven nuget pypi +1 more
No PRs yet
MPXJ: XXE Vulnerability in MerlinReader
GHSA-5vvx-3h34-f3gj CVE-2026-61570 HIGH 10 days ago
### Impact MPXJ used the default configuration when creating a DocumentBuilder instance, which leaves doctype declarations enabled, when parsing th...
maven nuget pypi +1 more
No PRs yet
io.moquette:moquette-broker has a Missing Authorization issue
GHSA-9jjc-fw8x-fmwx CVE-2026-85058 HIGH 14 days ago
## Summary Moquette MQTT Broker fails to enforce ACL write permission checks when publishing Will (Last Will and Testament) messages on behalf of ...
maven
No PRs yet
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
GHSA-26vp-8gxg-v4pg CVE-2025-53837 CRITICAL 14 days ago
### Impact Any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macro...
maven
No PRs yet
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
GHSA-m6c8-jcw2-5r25 CVE-2026-77615 HIGH 14 days ago
## Summary The Opencast Paella player renders caption cue text into `innerHTML` without escaping. The captions canvas clears `_captionsContainer.i...
maven npm
No PRs yet
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
GHSA-gq9c-wmrm-5hvr CVE-2026-81876 HIGH 15 days ago
### Summary A malformed Smart Health Card (SHC) JWT with `zip: "DEF"` and an empty or truncated DEFLATE payload causes `SHCParser.inflate()` to loo...
maven
No PRs yet
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
GHSA-3w98-rrpr-fprr CVE-2026-81875 HIGH 15 days ago
### Summary `SHCParser` inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submi...
maven
No PRs yet
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
GHSA-f8m2-889x-vw4x CVE-2026-85717 MODERATE 15 days ago
### Impact A client configured with a client-wide realm (a Realm set on the config builder rather than on an individual request) and following redi...
maven
No PRs yet
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
GHSA-xr57-gcx8-52hf CVE-2026-85720 MODERATE 15 days ago
### Impact When a request uses an HTTP proxy to reach an HTTPS origin, the client opens the tunnel with a plaintext CONNECT sent to the proxy befor...
maven
No PRs yet
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
GHSA-7grg-jcf7-rpmx CVE-2026-85721 HIGH 15 days ago
### Impact With automatic response decompression enabled (the default), the HTTP/1.1 path decompresses response bodies with no limit on the total o...
maven
No PRs yet
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
GHSA-fj9w-c36g-h5x8 CVE-2026-85716 LOW 15 days ago
### Impact For SCRAM, and for Digest with mutual authentication, the client computes the server's verification value (the SCRAM ServerSignature, or...
maven
No PRs yet
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
GHSA-hpj9-grjp-7vc7 CVE-2026-73245 MODERATE 15 days ago
## Summary Kestra's Micronaut **management endpoints are served on port 8081 with no authentication**, even when the main API (port 8080) has basic...
maven
No PRs yet
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
GHSA-r56g-q4p6-m3p6 CVE-2026-73247 HIGH 15 days ago
### Summary The Pebble template engine's `http()` function in Kestra OSS accepts user-controlled URLs without any validation, allowing Server-Side ...
maven
No PRs yet
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
GHSA-89m4-43j5-vhhx CVE-2026-86071 LOW 15 days ago
## Summary `LocalFolderExtractor` validates only the final canonical file path before extraction. However, `makeFile()` creates intermediate direc...
maven
No PRs yet
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
GHSA-wxmm-q36w-r9xj CVE-2026-61700 LOW 15 days ago
## Summary MariaDB Connector/J does not enforce `allowLocalInfile=false` when processing server-initiated LOCAL INFILE requests (protocol packet ...
maven
No PRs yet
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
GHSA-9rm7-3qhh-h2mc CVE-2026-63126 HIGH 15 days ago
Wire's protobuf decoders did not consistently validate attacker-controlled length-delimited sizes against the current reader bounds before computin...
maven
No PRs yet
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
GHSA-jh4v-gfqj-7rhx CVE-2026-75516 HIGH 15 days ago
## Vulnerability In `AMQConnection.java` (line 435-436), after `Connection.Tune` negotiation, the frame-max limit is set via: ```java _frameHandl...
maven
No PRs yet
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
GHSA-gq9p-f254-h286 CVE-2026-88975 HIGH 17 days ago
### Summary An unauthenticated peer can make Ember's HTTP/2 read loop hold 16 MiB of a single frame in memory on a connection where Ember advertise...
maven
No PRs yet
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
GHSA-crq5-92j2-j7wv CVE-2026-69201 MODERATE 17 days ago
The static content handlers `ResourceService` and `WebjarService` URL decode each path segment and then reject only segments that are exactly `""`,...
maven
No PRs yet
Http4s Ember HTTP/2: unbounded continuation frame accumulation
GHSA-cp4q-fqw9-4hf6 CVE-2026-69218 HIGH 17 days ago
When Ember receives an HTTP/2 `HEADERS` or `PUSH_PROMISE` frame without the `END_HEADERS` flag, it buffers the header block fragment and waits for ...
maven
No PRs yet
Http4s: Ember chunk parser lenience (TE.TE request smuggling)
GHSA-jrpm-956j-96jg CVE-2026-69216 MODERATE 17 days ago
## Summary Ember's chunk decoder parses the size token leniently: it strips leading and trailing whitespace and accepts a leading `+` or `-` sign....
maven
No PRs yet
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
GHSA-grh8-3p95-f9rr CVE-2026-69215 MODERATE 17 days ago
The `CookieJar` client middleware decides whether to attach a cookie to an outgoing request using an unanchored substring test on the host and path...
maven
No PRs yet
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
GHSA-wv64-j4fq-5f9x CVE-2026-69214 MODERATE 17 days ago
When processing a `Set-Cookie` from a response, the `CookieJar` client middleware trusts the server-supplied `Domain` attribute verbatim, with no c...
maven
No PRs yet
Http4s Ember HTTP/2 has an unbounded outbound frame queue
GHSA-8f3q-3jmv-7prw CVE-2026-69213 HIGH 17 days ago
Ember's HTTP/2 connection serializes all outgoing frames through a single unbounded queue drained by one writer fiber (`writeLoop`). When the writ...
maven
No PRs yet
Http4s: DigestAuth nonce map grows unbounded
GHSA-fm4g-76c9-7w69 CVE-2026-69208 HIGH 17 days ago
The `DigestAuth` server middleware's stale-nonce cleanup uses an inverted comparison: it removes *fresh* nonces and stops at the first *stale* one....
maven
No PRs yet
Http4s: DigestAuth allows replay of captured requests
GHSA-9xww-74xv-gjfp CVE-2026-69206 MODERATE 17 days ago
The `DigestAuth` replay defence stores `lastNc + 1` rather than the nonce-count (`nc`) value it just accepted. When a legitimate client sends non-c...
maven
No PRs yet
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
GHSA-9998-894r-fwvr CVE-2026-69205 HIGH 17 days ago
## Summary Ember's HTTP/1.1 header parser matches the `Transfer-Encoding` header value with a case-sensitive substring test (`hValue.contains("chu...
maven
No PRs yet
Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
GHSA-8h4c-x2wg-6xp8 CVE-2026-69204 CRITICAL 17 days ago
## Summary Ember's HTTP/1.1 request parser does not reject a message that carries both a `Transfer-Encoding` and a `Content-Length` header. RFC 91...
maven
No PRs yet
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
GHSA-9vwc-pc8p-253q CVE-2026-69203 HIGH 17 days ago
An ember server with HTTP/2 enabled (`.withHttp2`) does not enforce `SETTINGS_MAX_CONCURRENT_STREAMS` on streams opened by the peer. A single unau...
maven
No PRs yet
Http4s Ember HTTP/2: unbounded inbound body buffering
GHSA-6m4x-pp6q-5jmm CVE-2026-69202 HIGH 17 days ago
Ember's HTTP/2 stack replenishes the inbound flow-control window based on bytes received off the wire, not bytes consumed by the application. Rece...
maven
No PRs yet
Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)
GHSA-vjfw-cpmh-xwv3 CVE-2026-11745 HIGH 21 days ago
# Vulnerability Central Dogma's Git mirror SSH client installs an Apache MINA SSHD `ServerKeyVerifier` lambda that returns `true` unconditionally ...
maven
No PRs yet
Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover
GHSA-2j95-gqxf-v3vg CVE-2026-11746 CRITICAL 21 days ago
## Vulnerability `ZooKeeperReplicationConfig.secret()` silently substitutes the hard-coded constant `"ch4n63m3"` (leetspeak for "change me") whene...
maven
No PRs yet
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion
GHSA-98q5-5qh2-7w75 CVE-2026-11748 MODERATE 21 days ago
# Vulnerability `SearchFirstActiveDirectoryRealm.findUserDn()` substitutes the user-supplied username from the login form into an LDAP search filt...
maven
No PRs yet
Apache FreeMarker template loading mechanism vulnerable to path traversal
GHSA-27j2-h3m2-8237 CVE-2026-84939 CRITICAL 22 days ago
Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier ...
maven
No PRs yet