Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
OmniFaces: Forged combined-resource IDs and related output/push boundaries
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
CVE-2026-62379
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
CVE-2026-62280
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
CVE-2026-62263
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
CVE-2026-59949
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
CVE-2026-55223
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
CVE-2024-7708
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
CVE-2026-8384
Eclipse Jetty: Path parameter traversal
CVE-2026-6790
Eclipse Jetty: HTTP Authority/Host mismatch
CVE-2026-10051
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
CVE-2026-10050
Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution
CVE-2026-59921
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Showing 1 - 20 of 1,000+ results