CVE-2026-5680Undertow-core: undertow: denial of service via websocket permessage-deflate processing Exploitation status Not known exploited Fix Not confirmed Published 08/27/2026 Severity High CVE-2026-19611Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding Exploitation status Not known exploited Fix Not confirmed Published 08/20/2026 Severity High CVE-2026-15571Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client Exploitation status Not known exploited Fix Not confirmed Published 08/18/2026 Severity High CVE-2026-14180Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap Exploitation status Not known exploited Fix Not confirmed Published 08/11/2026 Severity Medium CVE-2026-15565Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serverendpoint class with any @onmessage method Exploitation status Not known exploited Fix Not confirmed Published 08/11/2026 Severity High CVE-2026-16442Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction Exploitation status Not known exploited Fix Not confirmed Published 08/05/2026 Severity High CVE-2026-16100Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text Exploitation status Not known exploited Fix Not confirmed Published 08/05/2026 Severity Medium CVE-2026-16071Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary Exploitation status Not known exploited Fix Not confirmed Published 08/05/2026 Severity Medium CVE-2026-16102Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers Exploitation status Not known exploited Fix Not confirmed Published 08/05/2026 Severity High CVE-2026-15573Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher Exploitation status Not known exploited Fix Not confirmed Published 08/05/2026 Severity High CVE-2026-16443Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation Exploitation status Not known exploited Fix Not confirmed Published 08/05/2026 Severity High CVE-2026-18569Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens Exploitation status Not known exploited Fix Not confirmed Published 08/04/2026 Severity Low CVE-2026-18573Keycloak-services: keycloak-services: client access-type policy condition bypass during client update Exploitation status Not known exploited Fix Not confirmed Published 08/02/2026 Severity Medium CVE-2026-18572Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes Exploitation status Not known exploited Fix Not confirmed Published 08/02/2026 Severity Medium CVE-2026-18571Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation Exploitation status Not known exploited Fix Not confirmed Published 08/02/2026 Severity Medium CVE-2026-18570Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed Exploitation status Not known exploited Fix Not confirmed Published 08/02/2026 Severity Medium CVE-2026-18209Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Low CVE-2026-18206Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Low CVE-2026-18214Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Medium CVE-2026-18203Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Medium CVE-2026-18211Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Medium CVE-2026-18208Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Medium CVE-2026-16105Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Medium CVE-2026-18215Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Medium CVE-2026-18217Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Low CVE-2026-18218Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero Exploitation status Not known exploited Fix Not confirmed Published 07/31/2026 Severity Medium CVE-2026-18201Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers to organizations without manage-organizations Exploitation status Not known exploited Fix Not confirmed Published 07/29/2026 Severity Medium CVE-2026-18207Keycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching Exploitation status Not known exploited Fix Not confirmed Published 07/29/2026 Severity Medium CVE-2026-17059Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter Exploitation status Not known exploited Fix Not confirmed Published 07/24/2026 Severity Medium CVE-2026-17048Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api Exploitation status Not known exploited Fix Not confirmed Published 07/24/2026 Severity Medium CVE-2026-16104Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins Exploitation status Not known exploited Fix Not confirmed Published 07/17/2026 Severity Medium CVE-2026-16103Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemption Exploitation status Not known exploited Fix Not confirmed Published 07/17/2026 Severity Medium CVE-2026-16106Keycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles Exploitation status Not known exploited Fix Not confirmed Published 07/17/2026 Severity Medium CVE-2026-16108Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2 Exploitation status Not known exploited Fix Not confirmed Published 07/17/2026 Severity Medium CVE-2026-16093Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers Exploitation status Not known exploited Fix Not confirmed Published 07/17/2026 Severity Medium CVE-2026-16089Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session Exploitation status Not known exploited Fix Not confirmed Published 07/17/2026 Severity Medium CVE-2026-16072Keycloak-services: keycloak-services: organization invitation link exposure allows unauthorized member creation Exploitation status Not known exploited Fix Not confirmed Published 07/17/2026 Severity Medium CVE-2026-15943Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change Exploitation status Not known exploited Fix Not confirmed Published 07/17/2026 Severity Medium CVE-2026-15945Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2 Exploitation status Not known exploited Fix Not confirmed Published 07/16/2026 Severity Medium CVE-2026-14781Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to userinfo email Exploitation status Not known exploited Fix Not confirmed Published 07/05/2026 Severity Medium CVE-2026-14614Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource Exploitation status Not known exploited Fix Not confirmed Published 07/03/2026 Severity Medium CVE-2026-14613Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission Exploitation status Not known exploited Fix Not confirmed Published 07/03/2026 Severity Medium CVE-2026-13676fast-uri vulnerable to host confusion via failed IDN canonicalization Exploitation status Not known exploited Fix YesPublished 06/29/2026 Severity High CVE-2026-11800Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion Exploitation status Not known exploited Fix Not confirmed Published 06/25/2026 Severity High CVE-2026-48779ws: Memory exhaustion DoS from tiny fragments and data chunks Exploitation status Public exploit Fix YesPublished 06/16/2026 Severity High CVE-2026-11577CVE-2026-11577 Exploitation status Not confirmed Fix Not confirmed Published 06/08/2026 Severity Unknown CVE-2024-52011launch-editor vulnerable to command injection via the crafted request on Windows Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity High CVE-2026-9277shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op` Exploitation status Not known exploited Fix YesPublished 05/22/2026 Severity Critical CVE-2026-41292Long list of incoming EDNS options degrades performance Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity Medium CVE-2026-45736ws: Uninitialized memory disclosure Exploitation status Public exploit Fix YesPublished 05/15/2026 Severity High CVE-2026-42584Netty: HttpClientCodec response desynchronization Exploitation status Public exploit Fix YesPublished 05/13/2026 Severity High CVE-2026-42579Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder) Exploitation status Public exploit Fix YesPublished 05/13/2026 Severity High CVE-2026-42578Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation Exploitation status Public exploit Fix YesPublished 05/13/2026 Severity Low CVE-2026-42581Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization Exploitation status Public exploit Fix YesPublished 05/13/2026 Severity High CVE-2026-43869Apache Thrift: TSSLTransportFactory.java hostname verification Exploitation status Not known exploited Fix YesPublished 05/05/2026 Severity High CVE-2026-6321fast-uri vulnerable to path traversal via percent-encoded dot segments Exploitation status Not known exploited Fix YesPublished 05/04/2026 Severity High CVE-2026-40682Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor Exploitation status Not known exploited Fix YesPublished 05/04/2026 Severity Critical CVE-2026-42027Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader Exploitation status Not known exploited Fix YesPublished 05/04/2026 Severity Critical CVE-2026-42044Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` Exploitation status Public exploit Fix YesPublished 04/24/2026 Severity High CVE-2026-40542Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification Exploitation status Not known exploited Fix YesPublished 04/22/2026 Severity High CVE-2026-40895follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets Exploitation status Not known exploited Fix YesPublished 04/21/2026 Severity Medium CVE-2026-3505Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion. Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity High CVE-2026-5588PKIX draft CompositeVerifier accepts empty signature sequence as valid. Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity Medium CVE-2026-5598Non-constant time comparisons risk private key leakage in FrodoKEM. Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity High CVE-2026-0636LDAP Injection Vulnerability in LDAPStoreHelper.java Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity Medium CVE-2025-14813GOSTCTR implementation unable to process more than 255 blocks correctly Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity Critical CVE-2026-2332HTTP Request Smuggling via Chunked Extension Quoted-String Parsing Exploitation status Public exploit Fix YesPublished 04/14/2026 Severity High CVE-2026-40175Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain Exploitation status Public exploit Fix YesPublished 04/10/2026 Severity High CVE-2025-62718Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF Exploitation status Public exploit Fix YesPublished 04/09/2026 Severity Medium CVE-2026-5795CVE-2026-5795 Exploitation status Not known exploited Fix YesPublished 04/08/2026 Severity High CVE-2026-34197Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans Exploitation status KEV Fix YesPublished 04/07/2026 Severity High CVE-2026-33941Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options Exploitation status Public exploit Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-33940Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial Exploitation status Public exploit Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-33939Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation Exploitation status Public exploit Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-33938Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block Exploitation status Public exploit Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-33937Handlebars.js has JavaScript Injection via AST Type Confusion Exploitation status Public exploit Fix Not confirmed Published 03/27/2026 Severity Critical CVE-2026-33896Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) Exploitation status Public exploit Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-33895Forge has signature forgery in Ed25519 due to missing S > L check Exploitation status Public exploit Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-33894Forge has signature forgery in RSA-PKCS due to ASN.1 extra field Exploitation status Public exploit Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-33891Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input Exploitation status Public exploit Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-28369Undertow: undertow: request smuggling via malformed http request headers Exploitation status Not known exploited Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-28367Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator Exploitation status Not known exploited Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-28368Undertow: undertow: request smuggling via inconsistent header parsing Exploitation status Not known exploited Fix Not confirmed Published 03/27/2026 Severity High CVE-2026-4926path-to-regexp vulnerable to Denial of Service via sequential optional groups Exploitation status Not known exploited Fix YesPublished 03/26/2026 Severity High CVE-2025-67030CVE-2025-67030 Exploitation status Not known exploited Fix Not confirmed Published 03/25/2026 Severity High CVE-2026-3260CVE-2026-3260 Exploitation status Not confirmed Fix Not confirmed Published 03/24/2026 Severity Unknown CVE-2026-33228flatted: Prototype Pollution via parse() Exploitation status Public exploit Fix YesPublished 03/20/2026 Severity High CVE-2026-32141flatted: Unbounded recursion DoS in parse() revive phase Exploitation status Public exploit Fix YesPublished 03/12/2026 Severity High CVE-2026-29074SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs) Exploitation status Not known exploited Fix YesPublished 03/06/2026 Severity High CVE-2026-1605CVE-2026-1605 Exploitation status Not known exploited Fix YesPublished 03/05/2026 Severity High CVE-2025-69873CVE-2025-69873 Exploitation status Public exploit Fix YesPublished 02/11/2026 Severity High CVE-2026-25639Axios affected by Denial of Service via __proto__ Key in mergeConfig Exploitation status Not known exploited Fix YesPublished 02/09/2026 Severity High CVE-2024-4027Undertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacks Exploitation status Not known exploited Fix Not confirmed Published 01/30/2026 Severity High CVE-2026-0603Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection Exploitation status Not known exploited Fix YesPublished 01/23/2026 Severity High CVE-2026-22029React Router vulnerable to XSS via Open Redirects Exploitation status Not known exploited Fix Not confirmed Published 01/10/2026 Severity High CVE-2025-12543Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf Exploitation status Public exploit Fix Not confirmed Published 01/07/2026 Severity Critical CVE-2024-3884Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded Exploitation status Not known exploited Fix Not confirmed Published 12/03/2025 Severity High CVE-2025-9784Undertow: undertow madeyoureset http/2 ddos vulnerability Exploitation status Not known exploited Fix YesPublished 09/02/2025 Severity High CVE-2024-6875Infinispan: infinispan: rest compare api has buffer leak Exploitation status Not known exploited Fix YesPublished 03/28/2025 Severity Medium CVE-2025-23368Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli Exploitation status Not known exploited Fix Not confirmed Published 03/04/2025 Severity High