Known Vulnerabilities for Groovy by Apache
Listed below are 4 of the newest known vulnerabilities associated with "Groovy" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84663 json | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier ... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-78166 json | A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmartFilte... | Not Provided | 2026-08-24 | 2026-08-26 |
| CVE-2026-76224 json | ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin q... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-75411 json | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy scri... | Not Provided | 2026-08-26 | 2026-09-01 |
| CVE-2026-70431 json | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script ... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-69100 json | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in Glu... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-63071 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for ... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-57284 json | Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through t... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-57283 json | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows at... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-57281 json | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying ... | Not Provided | 2026-06-24 | 2026-08-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Groovy | 4.0.0 | |||
| Application | Apache | Groovy | 3.0.6 | |||
| Application | Apache | Groovy | 3.0.5 | |||
| Application | Apache | Groovy | 3.0.4 | |||
| Application | Apache | Groovy | 3.0.3 | |||
| Application | Apache | Groovy | 3.0.2 | |||
| Application | Apache | Groovy | 3.0.1 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 2.5.9 | |||
| Application | Apache | Groovy | 2.5.8 |