TopBraid EDG Vulnerability Report

Generated 2026-05-29T15:03:35Z

9.2.1 (released 2026-05-22) — previous: 9.2.0

Not affected (2)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.2.0 (released 2026-05-07) — previous: 9.1.6

Not affected (5)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
mediumCVE-2026-8723SNYK-JS-QS-16721866qs6.15.1NULL Pointer Dereference2026-05-179.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (6)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-14
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-10
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-28
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-28
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-28
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-22

9.1.6 (released 2026-05-29) — previous: 9.1.5

Affected (3)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Unassessed (3)

No detailed assessment performed since remediation is available.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed in
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.0
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.0
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.0

Not affected (45)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (1)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-05

9.1.5 (released 2026-05-07) — previous: 9.1.4

Affected (4)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (45)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (4)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-10
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-10
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-10
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-10

9.1.4 (released 2026-04-09) — previous: 9.1.3

Affected (8)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (47)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.17Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.17Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (8)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-31
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-31
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-26
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-26
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-31
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-31
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-21
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.16Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-19

9.1.3 (released 2026-03-23) — previous: 9.1.2

Affected (16)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.16Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (47)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.16Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.16Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (3)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-20
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-09
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-03

9.1.2 (released 2026-02-20) — previous: 9.1.1

Affected (19)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-209.1.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.12Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (52)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.12Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.6Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.6Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.6Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.0Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.3.0Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.3.0Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.3.0Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.1.1 (released 2026-02-17) — previous: 9.1.0

Affected (19)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-209.1.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.12Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (52)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.12Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.6Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.6Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.6Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.0Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.3.0Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.3.0Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.3.0Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.1.0 (released 2026-02-03) — previous: 9.0.3

Affected (19)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-209.1.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.12Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (52)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.12Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.6Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.6Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.6Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.0Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.3.0Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.3.0Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.3.0Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (8)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-08
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-08
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-13
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-21
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-08
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-08
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-08
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-15

9.0.3 (released 2026-05-07) — previous: 9.0.2

Affected (21)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (50)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (7)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-20
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-10
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-10
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-10
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-10
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-18
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-19

9.0.2 (released 2025-12-18) — previous: 9.0.1

Affected (28)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-209.0.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-189.0.3Upgrade to TopBraid EDG 9.0.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.0.3Upgrade to TopBraid EDG 9.0.3 or later.

Not affected (52)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-179.0.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-179.0.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (1)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.2.6.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-07

9.0.1 (released 2025-11-18) — previous: 9.0.0

Affected (29)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-209.0.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.2.6.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-189.0.3Upgrade to TopBraid EDG 9.0.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.0.3Upgrade to TopBraid EDG 9.0.3 or later.

Not affected (53)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-179.0.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.2.6.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-179.0.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.0.0 (released 2025-11-04) — previous: 8.5.3

Affected (29)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-209.0.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.2.6.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-189.0.3Upgrade to TopBraid EDG 9.0.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.0.3Upgrade to TopBraid EDG 9.0.3 or later.

Not affected (53)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-179.0.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.2.6.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-179.0.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

8.5.3 (released 2026-05-07) — previous: 8.5.2

Affected (22)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.1.128.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.8.4HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.1.128.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.8.4Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.1.128.FinalCRLF Injection2025-12-159.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (54)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.8.4Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.8.4HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
criticalCVE-2025-7783SNYK-JS-FORMDATA-10841150form-data4.0.2Predictable Value Range from Previous Values2025-07-189.0.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438322io.netty:netty-codec4.1.128.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.1.128.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438930io.netty:netty-codec4.1.128.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.4Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.4XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.4Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.8.4Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.8.4Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.80Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.80Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2025-8671SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-15857052org.apache.httpcomponents.core5:httpcore5-h25.3.4Denial of Service (DoS)2025-08-139.0.0vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.1.128.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.8.4Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.8.4Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.8.4Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.8.4CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.5Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.80LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.8.4Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.5Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.5Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.5Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
mediumCVE-2025-58754SNYK-JS-AXIOS-12613773axios1.8.4Allocation of Resources Without Limits or Throttling2025-09-109.0.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2025-22227SNYK-JAVA-IOPROJECTREACTORNETTY-10770514io.projectreactor.netty:reactor-netty-http1.0.48Exposure of Sensitive System Information to an Unauthorized Control Sphere2025-07-159.0.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (8)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-20
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.24.3Improper Output Neutralization for Logs2026-04-10
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-10
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-10
highCVE-2024-22363SNYK-JS-XLSX-6252523xlsx0.20.3Regular Expression Denial of Service (ReDoS)2024-02-18
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2026-04-10
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2025-12-18
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-19

8.5.2 (released 2025-12-09) — previous: 8.5.1

Affected (30)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-208.5.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.1.128.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.24.3Improper Output Neutralization for Logs2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.8.4HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.1.128.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.8.4Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2024-22363SNYK-JS-XLSX-6252523xlsx0.20.3Regular Expression Denial of Service (ReDoS)2024-02-188.5.3Upgrade to TopBraid EDG 8.5.3 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2025-12-188.5.3Upgrade to TopBraid EDG 8.5.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.1.128.FinalCRLF Injection2025-12-159.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-198.5.3Upgrade to TopBraid EDG 8.5.3 or later.

Not affected (56)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.8.4Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.8.4HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
criticalCVE-2025-7783SNYK-JS-FORMDATA-10841150form-data4.0.2Predictable Value Range from Previous Values2025-07-189.0.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438322io.netty:netty-codec4.1.128.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.1.128.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438930io.netty:netty-codec4.1.128.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.4Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.4XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.4Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.8.4Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.8.4Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-178.5.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.80Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.80Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2025-8671SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-15857052org.apache.httpcomponents.core5:httpcore5-h25.3.4Denial of Service (DoS)2025-08-139.0.0vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.1.128.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.8.4Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.8.4Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.8.4Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.8.4CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-178.5.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.5Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.80LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.8.4Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.5Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.5Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.5Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
mediumCVE-2025-58754SNYK-JS-AXIOS-12613773axios1.8.4Allocation of Resources Without Limits or Throttling2025-09-109.0.0vulnerable_code_not_in_execute_path
mediumCVE-2023-30533SNYK-JS-XLSX-5457926xlsx0.20.3Prototype Pollution2023-04-248.5.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2025-22227SNYK-JAVA-IOPROJECTREACTORNETTY-10770514io.projectreactor.netty:reactor-netty-http1.0.48Exposure of Sensitive System Information to an Unauthorized Control Sphere2025-07-159.0.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary

Fixed (9)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2025-41249SNYK-JAVA-ORGSPRINGFRAMEWORK-12817817org.springframework:spring-core6.2.8Incorrect Authorization2025-09-16
highCVE-2025-58056SNYK-JAVA-IONETTY-12485149io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2025-09-03
highCVE-2025-58057SNYK-JAVA-IONETTY-12485150io.netty:netty-codec-http4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-03
highCVE-2025-58057SNYK-JAVA-IONETTY-12485151io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-03
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-12238980org.apache.tika:tika-parser-pdf-module3.2.0XML External Entity (XXE) Injection2025-08-20
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-14188255org.apache.tika:tika-core3.2.0XML External Entity (XXE) Injection2025-08-20
highCVE-2025-41242SNYK-JAVA-ORGSPRINGFRAMEWORK-12008931org.springframework:spring-beans6.2.8Relative Path Traversal2025-08-14
highCVE-2025-55163SNYK-JAVA-IONETTY-11799531io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2025-08-13
mediumCVE-2025-7962SNYK-JAVA-ORGECLIPSEANGUS-12239873org.eclipse.angus:angus-mail2.0.3Improper Neutralization2025-07-21

8.5.1 (released 2025-08-26) — previous: 8.5.0

Affected (38)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.1Use of Cache Containing Sensitive Information2026-03-208.5.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.1.112.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.24.3Improper Output Neutralization for Logs2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.8.4HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.8.4Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-41249SNYK-JAVA-ORGSPRINGFRAMEWORK-12817817org.springframework:spring-core6.2.8Incorrect Authorization2025-09-168.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58056SNYK-JAVA-IONETTY-12485149io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58057SNYK-JAVA-IONETTY-12485150io.netty:netty-codec-http4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58057SNYK-JAVA-IONETTY-12485151io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-12238980org.apache.tika:tika-parser-pdf-module3.2.0XML External Entity (XXE) Injection2025-08-208.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-14188255org.apache.tika:tika-core3.2.0XML External Entity (XXE) Injection2025-08-208.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-41242SNYK-JAVA-ORGSPRINGFRAMEWORK-12008931org.springframework:spring-beans6.2.8Relative Path Traversal2025-08-148.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IONETTY-11799531io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2025-08-138.5.2Upgrade to TopBraid EDG 8.5.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2025-12-188.5.3Upgrade to TopBraid EDG 8.5.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.1.118.FinalCRLF Injection2025-12-159.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-7962SNYK-JAVA-ORGECLIPSEANGUS-12239873org.eclipse.angus:angus-mail2.0.3Improper Neutralization2025-07-218.5.2Upgrade to TopBraid EDG 8.5.2 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.8Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-198.5.3Upgrade to TopBraid EDG 8.5.3 or later.

Not affected (58)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.8.4Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.8.4HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.80.2Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
criticalCVE-2025-7783SNYK-JS-FORMDATA-10841150form-data4.0.2Predictable Value Range from Previous Values2025-07-189.0.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438322io.netty:netty-codec4.1.118.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438930io.netty:netty-codec4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.4Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.4XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.4Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.8.4Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.8.4Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.8Incomplete Cleanup2026-04-178.5.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.80Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.80Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2025-41248SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-12817818org.springframework.security:spring-security-core6.5.1Incorrect Authorization2025-09-168.5.2vulnerable_code_not_in_execute_path
highCVE-2025-8671SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-15857052org.apache.httpcomponents.core5:httpcore5-h25.3.4Denial of Service (DoS)2025-08-139.0.0vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.1.118.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.8.4Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.8.4Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.8.4Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.8.4CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.1Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.1Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.1Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.8Allocation of Resources Without Limits or Throttling2026-04-178.5.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.5Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.80LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.8.4Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.5Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.5Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.5Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
mediumCVE-2025-58754SNYK-JS-AXIOS-12613773axios1.8.4Allocation of Resources Without Limits or Throttling2025-09-109.0.0vulnerable_code_not_in_execute_path
mediumCVE-2025-53864SNYK-JAVA-COMNIMBUSDS-10691768com.nimbusds:nimbus-jose-jwt9.37.3Uncontrolled Recursion2025-07-118.5.2vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2025-22227SNYK-JAVA-IOPROJECTREACTORNETTY-10770514io.projectreactor.netty:reactor-netty-http1.0.48Exposure of Sensitive System Information to an Unauthorized Control Sphere2025-07-159.0.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-038.5.2vulnerable_code_not_in_execute_path

Fixed (1)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2024-22363SNYK-JS-XLSX-6252523xlsx0.20.3Regular Expression Denial of Service (ReDoS)2024-02-18

8.5.0 (released 2025-08-05) — previous: 8.4.3

Affected (39)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.1Use of Cache Containing Sensitive Information2026-03-208.5.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.1.112.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.24.3Improper Output Neutralization for Logs2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.8.4HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.8.4Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-41249SNYK-JAVA-ORGSPRINGFRAMEWORK-12817817org.springframework:spring-core6.2.8Incorrect Authorization2025-09-168.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58056SNYK-JAVA-IONETTY-12485149io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58057SNYK-JAVA-IONETTY-12485150io.netty:netty-codec-http4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58057SNYK-JAVA-IONETTY-12485151io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-12238980org.apache.tika:tika-parser-pdf-module3.2.0XML External Entity (XXE) Injection2025-08-208.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-14188255org.apache.tika:tika-core3.2.0XML External Entity (XXE) Injection2025-08-208.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-41242SNYK-JAVA-ORGSPRINGFRAMEWORK-12008931org.springframework:spring-beans6.2.8Relative Path Traversal2025-08-148.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IONETTY-11799531io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2025-08-138.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2024-22363SNYK-JS-XLSX-6252523xlsx0.20.3Regular Expression Denial of Service (ReDoS)2024-02-188.5.1Upgrade to TopBraid EDG 8.5.1 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2025-12-188.5.3Upgrade to TopBraid EDG 8.5.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.1.118.FinalCRLF Injection2025-12-159.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-7962SNYK-JAVA-ORGECLIPSEANGUS-12239873org.eclipse.angus:angus-mail2.0.3Improper Neutralization2025-07-218.5.2Upgrade to TopBraid EDG 8.5.2 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.8Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-198.5.3Upgrade to TopBraid EDG 8.5.3 or later.

Not affected (59)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.8.4Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.8.4HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.80.2Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
criticalCVE-2025-7783SNYK-JS-FORMDATA-10841150form-data4.0.2Predictable Value Range from Previous Values2025-07-189.0.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438322io.netty:netty-codec4.1.118.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.0vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438930io.netty:netty-codec4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.0vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.4Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.4XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.4Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.8.4Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.8.4Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.8Incomplete Cleanup2026-04-178.5.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.80Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.80Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2025-41248SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-12817818org.springframework.security:spring-security-core6.5.1Incorrect Authorization2025-09-168.5.2vulnerable_code_not_in_execute_path
highCVE-2025-8671SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-15857052org.apache.httpcomponents.core5:httpcore5-h25.3.4Denial of Service (DoS)2025-08-139.0.0vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-079.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.1.118.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-059.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.8.4Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.8.4Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.8.4Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.8.4CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.1Information Exposure2026-04-229.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.1Insufficient Verification of Data Authenticity2026-04-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.1Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.8Allocation of Resources Without Limits or Throttling2026-04-178.5.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.5Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.80LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.8.4Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.5Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.5Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.5Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
mediumCVE-2025-58754SNYK-JS-AXIOS-12613773axios1.8.4Allocation of Resources Without Limits or Throttling2025-09-109.0.0vulnerable_code_not_in_execute_path
mediumCVE-2025-53864SNYK-JAVA-COMNIMBUSDS-10691768com.nimbusds:nimbus-jose-jwt9.37.3Uncontrolled Recursion2025-07-118.5.2vulnerable_code_not_in_execute_path
mediumCVE-2023-30533SNYK-JS-XLSX-5457926xlsx0.20.3Prototype Pollution2023-04-248.5.1vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2025-22227SNYK-JAVA-IOPROJECTREACTORNETTY-10770514io.projectreactor.netty:reactor-netty-http1.0.48Exposure of Sensitive System Information to an Unauthorized Control Sphere2025-07-159.0.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-038.5.2vulnerable_code_not_in_execute_path

Fixed (13)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
high(none)SNYK-JAVA-COMGITHUBJUNRAR-16097905com.github.junrar:junrar7.5.5Directory Traversal2026-04-16
highCVE-2026-28208SNYK-JAVA-COMGITHUBJUNRAR-15360268com.github.junrar:junrar7.5.5Directory Traversal2026-02-27
highCVE-2025-68470SNYK-JS-REMIXRUNROUTER-14908287@remix-run/router1.14.1Open Redirect2026-01-08
highCVE-2026-22029SNYK-JS-REMIXRUNROUTER-14908530@remix-run/router1.14.1Cross-site Scripting (XSS)2026-01-08
highCVE-2025-48976SNYK-JAVA-ORGAPACHECOMMONS-10363251org.apache.commons:commons-fileupload2-core2.0.0-M2Allocation of Resources Without Limits or Throttling2025-06-16
highCVE-2025-48734SNYK-JAVA-COMMONSBEANUTILS-10259368commons-beanutils:commons-beanutils1.9.4Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2025-05-28
mediumCVE-2026-41245SNYK-JAVA-COMGITHUBJUNRAR-16115493com.github.junrar:junrar7.5.5Directory Traversal2026-04-20
mediumCVE-2025-8916SNYK-JAVA-ORGBOUNCYCASTLE-11789695org.bouncycastle:bcprov-jdk18on1.78.1Allocation of Resources Without Limits or Throttling2025-08-13
mediumCVE-2025-41234SNYK-JAVA-ORGSPRINGFRAMEWORK-10345766org.springframework:spring-web6.1.18HTTP Response Splitting2025-06-12
mediumCVE-2025-4949SNYK-JAVA-ORGECLIPSEJGIT-10231763org.eclipse.jgit:org.eclipse.jgit7.2.0.202503040940-rXML External Entity (XXE) Injection2025-05-21
mediumCVE-2025-22234SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-9789380org.springframework.security:spring-security-crypto6.3.8Timing Attack2025-04-22
lowCVE-2025-22233SNYK-JAVA-ORGSPRINGFRAMEWORK-10176071org.springframework:spring-context6.1.18Improper Handling of Case Sensitivity2025-05-15
lowCVE-2025-26791SNYK-JS-DOMPURIFY-8722251dompurify2.5.7Cross-site Scripting (XSS)2025-02-14