Known Vulnerabilities for Maven by Apache
Listed below are 3 of the newest known vulnerabilities associated with "Maven" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100725 json | http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-sid... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-100724 json | http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching on th... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-93598 json | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script... | Not Provided | 2026-09-18 | 2026-09-22 |
| CVE-2026-93594 json | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules o... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-93547 json | A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-91860 json | A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an o... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-88889 json | Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to exec... | Not Provided | 2026-09-10 | 2026-09-29 |
| CVE-2026-82428 json | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Ma... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-80351 json | Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-77121 json | A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversiz... | Not Provided | 2026-09-02 | 2026-09-02 |