Known Vulnerabilities for Groovy by Apache
Listed below are 4 of the newest known vulnerabilities associated with "Groovy" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-76224 json | ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin q... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-70431 json | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script ... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-69100 json | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in Glu... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-63071 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for ... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-57284 json | Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through t... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-57283 json | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows at... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-57281 json | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying ... | Not Provided | 2026-06-24 | 2026-07-15 |
| CVE-2026-57280 json | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the eleme... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-53421 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements ca... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-53405 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can ... | Not Provided | 2026-07-20 | 2026-07-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Groovy | 4.0.0 | |||
| Application | Apache | Groovy | 3.0.6 | |||
| Application | Apache | Groovy | 3.0.5 | |||
| Application | Apache | Groovy | 3.0.4 | |||
| Application | Apache | Groovy | 3.0.3 | |||
| Application | Apache | Groovy | 3.0.2 | |||
| Application | Apache | Groovy | 3.0.1 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 2.5.9 | |||
| Application | Apache | Groovy | 2.5.8 |