Known Vulnerabilities for Groovy by Apache
Listed below are 4 of the newest known vulnerabilities associated with "Groovy" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63071 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for ... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-57284 json | Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through t... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-57283 json | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows at... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-57281 json | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying ... | Not Provided | 2026-06-24 | 2026-07-15 |
| CVE-2026-57280 json | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the eleme... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-53421 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements ca... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-53405 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can ... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-48921 json | Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared librar... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-46351 json | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with ins... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-42782 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for ... | Not Provided | 2026-05-25 | 2026-05-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Groovy | 4.0.0 | |||
| Application | Apache | Groovy | 3.0.6 | |||
| Application | Apache | Groovy | 3.0.5 | |||
| Application | Apache | Groovy | 3.0.4 | |||
| Application | Apache | Groovy | 3.0.3 | |||
| Application | Apache | Groovy | 3.0.2 | |||
| Application | Apache | Groovy | 3.0.1 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 3.0.0 | |||
| Application | Apache | Groovy | 2.5.9 | |||
| Application | Apache | Groovy | 2.5.8 |