TopBraid EDG Vulnerability Report

Generated 2026-08-07T15:49:32Z

9.3.0 (released 2026-08-07) — previous: 9.2.3

Not affected (5)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.2.3 (released 2026-08-07) — previous: 9.2.2

Not affected (30)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.16.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.16.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.16.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.15.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.16.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.16.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.15.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.15.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67315SNYK-JS-AXIOS-18065357axios1.15.2Permissive List of Allowed Inputs2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.15.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.15.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44489SNYK-JS-AXIOS-17111086axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (7)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.84Inefficient Algorithmic Complexity2026-08-03
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.84Memory Allocation with Excessive Size Value2026-08-03
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.84Uncontrolled Recursion2026-08-03
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.23.0Allocation of Resources Without Limits or Throttling2026-07-27
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-08
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-01
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-26

9.2.2 (released 2026-06-29) — previous: 9.2.1

Affected (7)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.84Inefficient Algorithmic Complexity2026-08-039.2.3Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.84Memory Allocation with Excessive Size Value2026-08-039.2.3Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.84Uncontrolled Recursion2026-08-039.2.3Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.23.0Allocation of Resources Without Limits or Throttling2026-07-279.2.3Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.2.3Upgrade to TopBraid EDG 9.2.3 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.2.3Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.2.3Upgrade to TopBraid EDG 9.3.0 or later, when available.

Not affected (83)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-8763SNYK-JAVA-ORGBOUNCYCASTLE-18512779org.bouncycastle:bcprov-jdk18on1.84Improper Certificate Validation2026-08-039.2.3vulnerable_code_not_in_execute_path
criticalCVE-2026-59650SNYK-JAVA-ORGBOUNCYCASTLE-18512810org.bouncycastle:bcprov-jdk18on1.84Improper Input Validation2026-08-039.2.3vulnerable_code_not_in_execute_path
criticalCVE-2026-58062SNYK-JAVA-ORGBOUNCYCASTLE-18519194org.bouncycastle:bcprov-jdk18on1.84Improper Certificate Validation2026-08-039.2.3vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web7.0.7Deserialization of Untrusted Data2026-06-089.2.3vulnerable_code_not_present
highCVE-2026-59645SNYK-JAVA-ORGBOUNCYCASTLE-18512330org.bouncycastle:bcutil-jdk18on1.84Uncontrolled Recursion2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-12185SNYK-JAVA-ORGBOUNCYCASTLE-18512520org.bouncycastle:bcprov-jdk18on1.84Memory Allocation with Excessive Size Value2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59651SNYK-JAVA-ORGBOUNCYCASTLE-18512572org.bouncycastle:bcprov-jdk18on1.84Inadequate Encryption Strength2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59641SNYK-JAVA-ORGBOUNCYCASTLE-18512864org.bouncycastle:bcjmail-jdk18on1.84Insufficient Verification of Data Authenticity2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59642SNYK-JAVA-ORGBOUNCYCASTLE-18512967org.bouncycastle:bcpkix-jdk18on1.84Improper Validation of Integrity Check Value2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59639SNYK-JAVA-ORGBOUNCYCASTLE-18513021org.bouncycastle:bcpkix-jdk18on1.84Improper Verification of Cryptographic Signature2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-12860SNYK-JAVA-ORGBOUNCYCASTLE-18518014org.bouncycastle:bcprov-jdk18on1.84Improper Verification of Cryptographic Signature2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-58061SNYK-JAVA-ORGBOUNCYCASTLE-18519127org.bouncycastle:bcprov-jdk18on1.84Improper Validation of Integrity Check Value2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-12803SNYK-JAVA-ORGBOUNCYCASTLE-18519148org.bouncycastle:bcprov-jdk18on1.84Improper Validation of Integrity Check Value2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-12816SNYK-JAVA-ORGBOUNCYCASTLE-18519163org.bouncycastle:bcprov-jdk18on1.84Improper Validation of Integrity Check Value2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-58060SNYK-JAVA-ORGBOUNCYCASTLE-18519180org.bouncycastle:bcprov-jdk18on1.84Memory Allocation with Excessive Size Value2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-12802SNYK-JAVA-ORGBOUNCYCASTLE-18519217org.bouncycastle:bcpkix-jdk18on1.84Improper Validation of Integrity Check Value2026-08-039.2.3vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.23.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.2.3vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.16.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.16.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.16.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.15.FinalInfinite loop2026-07-229.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.15.FinalInfinite loop2026-07-229.2.3vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-229.2.3vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-219.2.3vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-219.2.3vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-219.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59889SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608com.fasterxml.jackson.core:jackson-databind2.22.0Incorrect Authorization2026-07-149.2.3vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.2.3vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression7.0.7Inefficient Algorithmic Complexity2026-06-089.2.3vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression7.0.7Allocation of Resources Without Limits or Throttling2026-06-089.2.3vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.15.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
mediumCVE-2026-59647SNYK-JAVA-ORGBOUNCYCASTLE-18513013org.bouncycastle:bcpkix-jdk18on1.84Allocation of Resources Without Limits or Throttling2026-08-039.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-15055SNYK-JAVA-ORGBOUNCYCASTLE-18517495org.bouncycastle:bcpkix-jdk18on1.84Allocation of Resources Without Limits or Throttling2026-08-039.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518977org.bouncycastle:bcprov-jdk18on1.84Allocation of Resources Without Limits or Throttling2026-08-039.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518992org.bouncycastle:bcpkix-jdk18on1.84Allocation of Resources Without Limits or Throttling2026-08-039.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-58063SNYK-JAVA-ORGBOUNCYCASTLE-18519071org.bouncycastle:bcprov-jdk18on1.84Allocation of Resources Without Limits or Throttling2026-08-039.2.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.16.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.16.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.15.FinalCRLF Injection2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.15.FinalHTTP Request Smuggling2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.15.FinalHTTP Request Smuggling2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.15.FinalIncorrect Authorization2026-07-219.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.15.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.15.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67315SNYK-JS-AXIOS-18065357axios1.15.2Permissive List of Allowed Inputs2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.22.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.4.0Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.4.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.4.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.4.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.4.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.4.0Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.4.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-129.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression7.0.7Exposed Dangerous Method or Function2026-06-089.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core7.0.7Regular Expression Denial of Service (ReDoS)2026-06-089.2.3vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web7.0.7Server-side Request Forgery (SSRF)2026-06-089.2.3vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web7.0.7Cross-site Scripting (XSS)2026-06-089.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.15.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.15.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44489SNYK-JS-AXIOS-17111086axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.4.0Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.4.0Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.4.0Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (6)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.13.FinalImproper Verification of Cryptographic Signature2026-06-12
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider7.0.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-10
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider7.0.5Cross-site Scripting (XSS)2026-06-10
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce8.4.0Cross-site Scripting (XSS)2026-05-28
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce8.4.0Cross-site Scripting (XSS)2026-05-28
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce8.4.0Cross-site Scripting (XSS)2026-05-28

9.2.1 (released 2026-05-22) — previous: 9.2.0

Affected (10)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.23.0Allocation of Resources Without Limits or Throttling2026-07-279.2.3Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.2.3Upgrade to TopBraid EDG 9.2.3 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.2.3Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.2.3Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.13.FinalImproper Verification of Cryptographic Signature2026-06-129.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider7.0.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider7.0.5Cross-site Scripting (XSS)2026-06-109.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.

Not affected (85)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.13.FinalIncorrect Comparison2026-06-089.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web7.0.7Deserialization of Untrusted Data2026-06-089.2.3vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.14.1Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.23.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.2.3vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.14.1Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.14.1Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.14.1Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.13.FinalInfinite loop2026-07-229.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.13.FinalInfinite loop2026-07-229.2.3vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-229.2.3vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-219.2.3vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-219.2.3vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-219.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59889SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-149.2.3vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.2.3vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40993SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17304906org.springframework.security:spring-security-saml2-service-provider7.0.5Deserialization of Untrusted Data2026-06-099.2.2vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression7.0.7Inefficient Algorithmic Complexity2026-06-089.2.3vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression7.0.7Allocation of Resources Without Limits or Throttling2026-06-089.2.3vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core4.0.3Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.14.1Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.15.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.14.1Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.14.1Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.13.FinalCRLF Injection2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.13.FinalHTTP Request Smuggling2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.13.FinalHTTP Request Smuggling2026-07-229.2.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-219.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.13.FinalIncorrect Authorization2026-07-219.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.15.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.15.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67315SNYK-JS-AXIOS-18065357axios1.15.2Permissive List of Allowed Inputs2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.4.0Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.4.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.4.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.4.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.4.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.4.0Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.4.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-129.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.13.FinalHTTP Request Smuggling2026-06-129.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-129.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.13.FinalMissing Release of Memory after Effective Lifetime2026-06-119.2.2vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web7.0.5Open Redirect2026-06-109.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider7.0.5Information Exposure2026-06-099.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-089.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.13.FinalMissing Release of Resource after Effective Lifetime2026-06-089.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression7.0.7Exposed Dangerous Method or Function2026-06-089.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core7.0.7Regular Expression Denial of Service (ReDoS)2026-06-089.2.3vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web7.0.7Server-side Request Forgery (SSRF)2026-06-089.2.3vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web7.0.7Cross-site Scripting (XSS)2026-06-089.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.15.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.15.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44489SNYK-JS-AXIOS-17111086axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.4.0Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.4.0Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.4.0Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.14.1Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.2.0 (released 2026-05-07) — previous: 9.1.8

Affected (10)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.2.3Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.2.3Upgrade to TopBraid EDG 9.2.3 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.2.3Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.2.3Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.13.FinalImproper Verification of Cryptographic Signature2026-06-129.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider7.0.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider7.0.5Cross-site Scripting (XSS)2026-06-109.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.

Not affected (87)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.13.FinalIncorrect Comparison2026-06-089.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web7.0.7Deserialization of Untrusted Data2026-06-089.2.3vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.14.1Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.2.3vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.14.1Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.14.1Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.14.1Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.13.FinalInfinite loop2026-07-229.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.13.FinalInfinite loop2026-07-229.2.3vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-229.2.3vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-219.2.3vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-219.2.3vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-219.2.3vulnerable_code_not_in_execute_path
highCVE-2026-59889SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-149.2.3vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.2.3vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40993SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17304906org.springframework.security:spring-security-saml2-service-provider7.0.5Deserialization of Untrusted Data2026-06-099.2.2vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression7.0.7Inefficient Algorithmic Complexity2026-06-089.2.3vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression7.0.7Allocation of Resources Without Limits or Throttling2026-06-089.2.3vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core4.0.3Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.14.1Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.15.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.14.1Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.14.1Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.13.FinalCRLF Injection2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.13.FinalHTTP Request Smuggling2026-07-229.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.13.FinalHTTP Request Smuggling2026-07-229.2.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-219.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.13.FinalIncorrect Authorization2026-07-219.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.15.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.15.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.15.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.15.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67315SNYK-JS-AXIOS-18065357axios1.15.2Permissive List of Allowed Inputs2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.4.0Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.4.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.4.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.4.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.4.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.4.0Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.4.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-129.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.13.FinalHTTP Request Smuggling2026-06-129.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-129.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.13.FinalMissing Release of Memory after Effective Lifetime2026-06-119.2.2vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web7.0.5Open Redirect2026-06-109.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider7.0.5Information Exposure2026-06-099.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-089.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.13.FinalMissing Release of Resource after Effective Lifetime2026-06-089.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression7.0.7Exposed Dangerous Method or Function2026-06-089.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core7.0.7Regular Expression Denial of Service (ReDoS)2026-06-089.2.3vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web7.0.7Server-side Request Forgery (SSRF)2026-06-089.2.3vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web7.0.7Cross-site Scripting (XSS)2026-06-089.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.15.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.15.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44489SNYK-JS-AXIOS-17111086axios1.15.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-8723SNYK-JS-QS-16721866qs6.15.1NULL Pointer Dereference2026-05-179.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.4.0Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.4.0Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.4.0Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.14.1Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (2)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-10
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-22

9.1.8 (released 2026-08-07) — previous: 9.1.7

Affected (5)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (68)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.12.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.12.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.12.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.12.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.3.3Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.12.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53668SNYK-JS-REACTROUTER-18313146react-router7.12.0Open Redirect2026-07-239.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.3.3Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.3.3Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (8)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-03
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-03
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-03
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-27
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-08
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-01
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-26
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-14

9.1.7 (released 2026-06-29) — previous: 9.1.6

Affected (13)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-039.1.8Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.1.8Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-039.1.8Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.1.8Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (121)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-8763SNYK-JAVA-ORGBOUNCYCASTLE-18512779org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.1.8vulnerable_code_not_in_execute_path
criticalCVE-2026-59650SNYK-JAVA-ORGBOUNCYCASTLE-18512810org.bouncycastle:bcprov-jdk18on1.81Improper Input Validation2026-08-039.1.8vulnerable_code_not_in_execute_path
criticalCVE-2026-58062SNYK-JAVA-ORGBOUNCYCASTLE-18519194org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.1.8vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.18Deserialization of Untrusted Data2026-06-089.1.8vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.1.8vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-59645SNYK-JAVA-ORGBOUNCYCASTLE-18512330org.bouncycastle:bcutil-jdk18on1.81.1Uncontrolled Recursion2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-12185SNYK-JAVA-ORGBOUNCYCASTLE-18512520org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59651SNYK-JAVA-ORGBOUNCYCASTLE-18512572org.bouncycastle:bcprov-jdk18on1.81Inadequate Encryption Strength2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59641SNYK-JAVA-ORGBOUNCYCASTLE-18512864org.bouncycastle:bcjmail-jdk18on1.81Insufficient Verification of Data Authenticity2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59642SNYK-JAVA-ORGBOUNCYCASTLE-18512967org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59639SNYK-JAVA-ORGBOUNCYCASTLE-18513021org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-12860SNYK-JAVA-ORGBOUNCYCASTLE-18518014org.bouncycastle:bcprov-jdk18on1.81Improper Verification of Cryptographic Signature2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-58061SNYK-JAVA-ORGBOUNCYCASTLE-18519127org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-12803SNYK-JAVA-ORGBOUNCYCASTLE-18519148org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-12816SNYK-JAVA-ORGBOUNCYCASTLE-18519163org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-58060SNYK-JAVA-ORGBOUNCYCASTLE-18519180org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-12802SNYK-JAVA-ORGBOUNCYCASTLE-18519217org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.1.8vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.12.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.12.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.12.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.15.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.15.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59889SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608com.fasterxml.jackson.core:jackson-databind2.22.0Incorrect Authorization2026-07-149.1.8vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.18Allocation of Resources Without Limits or Throttling2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59647SNYK-JAVA-ORGBOUNCYCASTLE-18513013org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-15055SNYK-JAVA-ORGBOUNCYCASTLE-18517495org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518977org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518992org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-58063SNYK-JAVA-ORGBOUNCYCASTLE-18519071org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.12.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.3.3Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.12.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53668SNYK-JS-REACTROUTER-18313146react-router7.12.0Open Redirect2026-07-239.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.15.FinalCRLF Injection2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.15.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.15.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.15.FinalIncorrect Authorization2026-07-219.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.22.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-129.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.1.8vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.3.3Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.3.3Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (3)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.12.FinalImproper Verification of Cryptographic Signature2026-06-12
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-10
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-10

9.1.6 (released 2026-05-29) — previous: 9.1.5

Affected (13)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.1.8Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.12.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (132)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.12.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.18Deserialization of Untrusted Data2026-06-089.1.8vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.1.8vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.12.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.12.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.12.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.12.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.12.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59889SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-149.1.8vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.18Allocation of Resources Without Limits or Throttling2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.12.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.3.3Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.12.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53668SNYK-JS-REACTROUTER-18313146react-router7.12.0Open Redirect2026-07-239.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.12.FinalCRLF Injection2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.12.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.12.FinalIncorrect Authorization2026-07-219.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-129.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.12.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.1.8vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.3.3Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.3.3Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (4)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-03
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-03
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-03
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-05

9.1.5 (released 2026-05-07) — previous: 9.1.4

Affected (17)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-039.1.6Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.1.6Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-039.1.6Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.1.8Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.12.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (153)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-8763SNYK-JAVA-ORGBOUNCYCASTLE-18512779org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.1.6vulnerable_code_not_in_execute_path
criticalCVE-2026-59650SNYK-JAVA-ORGBOUNCYCASTLE-18512810org.bouncycastle:bcprov-jdk18on1.81Improper Input Validation2026-08-039.1.6vulnerable_code_not_in_execute_path
criticalCVE-2026-58062SNYK-JAVA-ORGBOUNCYCASTLE-18519194org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.1.6vulnerable_code_not_in_execute_path
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.12.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.18Deserialization of Untrusted Data2026-06-089.1.8vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.1.8vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-59645SNYK-JAVA-ORGBOUNCYCASTLE-18512330org.bouncycastle:bcutil-jdk18on1.81.1Uncontrolled Recursion2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-12185SNYK-JAVA-ORGBOUNCYCASTLE-18512520org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-59651SNYK-JAVA-ORGBOUNCYCASTLE-18512572org.bouncycastle:bcprov-jdk18on1.81Inadequate Encryption Strength2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-59641SNYK-JAVA-ORGBOUNCYCASTLE-18512864org.bouncycastle:bcjmail-jdk18on1.81Insufficient Verification of Data Authenticity2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-59642SNYK-JAVA-ORGBOUNCYCASTLE-18512967org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-59639SNYK-JAVA-ORGBOUNCYCASTLE-18513021org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-12860SNYK-JAVA-ORGBOUNCYCASTLE-18518014org.bouncycastle:bcprov-jdk18on1.81Improper Verification of Cryptographic Signature2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-58061SNYK-JAVA-ORGBOUNCYCASTLE-18519127org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-12803SNYK-JAVA-ORGBOUNCYCASTLE-18519148org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-12816SNYK-JAVA-ORGBOUNCYCASTLE-18519163org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-58060SNYK-JAVA-ORGBOUNCYCASTLE-18519180org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-12802SNYK-JAVA-ORGBOUNCYCASTLE-18519217org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.1.6vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.12.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.12.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.12.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.12.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.12.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-68494SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159com.fasterxml.jackson.core:jackson-core2.21.2Allocation of Resources Without Limits or Throttling2026-07-219.1.6vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59889SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-149.1.8vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.18Allocation of Resources Without Limits or Throttling2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59647SNYK-JAVA-ORGBOUNCYCASTLE-18513013org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.1.6vulnerable_code_not_in_execute_path
mediumCVE-2026-15055SNYK-JAVA-ORGBOUNCYCASTLE-18517495org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.1.6vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518977org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.1.6vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518992org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.1.6vulnerable_code_not_in_execute_path
mediumCVE-2026-58063SNYK-JAVA-ORGBOUNCYCASTLE-18519071org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.1.6vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.12.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.3.3Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.12.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53668SNYK-JS-REACTROUTER-18313146react-router7.12.0Open Redirect2026-07-239.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.12.FinalCRLF Injection2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.12.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.12.FinalIncorrect Authorization2026-07-219.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-129.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.12.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.1.8vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.3.3Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.3.3Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (4)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-10
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-10
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-10
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-10

9.1.4 (released 2026-04-09) — previous: 9.1.3

Affected (18)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.1.8Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.12.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (134)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.12.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.17Deserialization of Untrusted Data2026-06-089.1.8vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.1.8vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.12.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.12.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.12.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.12.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.12.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59889SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-149.1.8vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.17Inefficient Algorithmic Complexity2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.17Allocation of Resources Without Limits or Throttling2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.17Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.12.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.3.3Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.12.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53668SNYK-JS-REACTROUTER-18313146react-router7.12.0Open Redirect2026-07-239.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.12.FinalCRLF Injection2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.12.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.12.FinalIncorrect Authorization2026-07-219.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.3Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-129.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.12.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.17Exposed Dangerous Method or Function2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.17Regular Expression Denial of Service (ReDoS)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.17Server-side Request Forgery (SSRF)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.17Cross-site Scripting (XSS)2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.17Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.1.8vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.3.3Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.3.3Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (8)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-31
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-31
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-26
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-26
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-31
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-31
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-21
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.16Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-19

9.1.3 (released 2026-03-23) — previous: 9.1.2

Affected (26)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.1.8Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.9.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.16Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (134)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.9.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.16Deserialization of Untrusted Data2026-06-089.1.8vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.1.8vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.12.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.12.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.12.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.9.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.9.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59889SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-149.1.8vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.16Inefficient Algorithmic Complexity2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.16Allocation of Resources Without Limits or Throttling2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.16Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.12.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.3.3Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.12.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53668SNYK-JS-REACTROUTER-18313146react-router7.12.0Open Redirect2026-07-239.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.9.FinalCRLF Injection2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.9.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-07-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.9.FinalIncorrect Authorization2026-07-219.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.13.6Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.13.6Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.13.6Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.3Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-129.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.9.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.16Exposed Dangerous Method or Function2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.16Regular Expression Denial of Service (ReDoS)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.16Server-side Request Forgery (SSRF)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.16Cross-site Scripting (XSS)2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.16Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.1.8vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.3.3Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.3.3Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (3)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-20
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-09
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-03

9.1.2 (released 2026-02-20) — previous: 9.1.1

Affected (29)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-209.1.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.1.8Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.9.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.6Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.6Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.12Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (134)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.9.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.12Deserialization of Untrusted Data2026-06-089.1.8vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.1.8vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.12.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.12.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.12.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.9.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.9.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.12Inefficient Algorithmic Complexity2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.12Allocation of Resources Without Limits or Throttling2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.15Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.12Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.1.8vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.12.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.3.0Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.12.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53668SNYK-JS-REACTROUTER-18313146react-router7.12.0Open Redirect2026-07-239.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.9.FinalCRLF Injection2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.9.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.9.FinalIncorrect Authorization2026-07-219.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.13.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.13.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.13.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.13.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.13.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.3Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.3.0Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.3.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.3.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.0Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.3.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-129.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.9.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.6Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.6Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.12Exposed Dangerous Method or Function2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.12Regular Expression Denial of Service (ReDoS)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.12Server-side Request Forgery (SSRF)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.12Cross-site Scripting (XSS)2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.6Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.6Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.6Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.0Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.1.8vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-65913SNYK-JS-DOMPURIFY-15874903dompurify3.3.0Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65912SNYK-JS-DOMPURIFY-15874905dompurify3.3.0Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65914SNYK-JS-DOMPURIFY-15810938dompurify3.3.0Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.3.0Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.3.0Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.3.0Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.1.1 (released 2026-02-17) — previous: 9.1.0

Affected (29)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-209.1.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.1.8Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.9.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.6Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.6Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.12Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (134)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.9.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.12Deserialization of Untrusted Data2026-06-089.1.8vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.1.8vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.12.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.12.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.12.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.9.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.9.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.12Inefficient Algorithmic Complexity2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.12Allocation of Resources Without Limits or Throttling2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.15Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.12Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.1.8vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.12.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.3.0Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.12.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53668SNYK-JS-REACTROUTER-18313146react-router7.12.0Open Redirect2026-07-239.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.9.FinalCRLF Injection2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.9.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.9.FinalIncorrect Authorization2026-07-219.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.13.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.13.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.13.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.13.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.13.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.3Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.3.0Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.3.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.3.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.0Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.3.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-129.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.9.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.6Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.6Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.12Exposed Dangerous Method or Function2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.12Regular Expression Denial of Service (ReDoS)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.12Server-side Request Forgery (SSRF)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.12Cross-site Scripting (XSS)2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.6Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.6Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.6Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.0Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.1.8vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-65913SNYK-JS-DOMPURIFY-15874903dompurify3.3.0Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65912SNYK-JS-DOMPURIFY-15874905dompurify3.3.0Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65914SNYK-JS-DOMPURIFY-15810938dompurify3.3.0Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.3.0Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.3.0Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.3.0Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (3)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-03
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-03
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-03

9.1.0 (released 2026-02-03) — previous: 9.0.5

Affected (32)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-209.1.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-039.1.1Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.1.1Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-039.1.1Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.1.8Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.9.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.6Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.1.8Upgrade to TopBraid EDG 9.1.8 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.6Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.12Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (155)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-8763SNYK-JAVA-ORGBOUNCYCASTLE-18512779org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.1.1vulnerable_code_not_in_execute_path
criticalCVE-2026-59650SNYK-JAVA-ORGBOUNCYCASTLE-18512810org.bouncycastle:bcprov-jdk18on1.81Improper Input Validation2026-08-039.1.1vulnerable_code_not_in_execute_path
criticalCVE-2026-58062SNYK-JAVA-ORGBOUNCYCASTLE-18519194org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.1.1vulnerable_code_not_in_execute_path
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.9.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.12Deserialization of Untrusted Data2026-06-089.1.8vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.1.8vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-59645SNYK-JAVA-ORGBOUNCYCASTLE-18512330org.bouncycastle:bcutil-jdk18on1.81.1Uncontrolled Recursion2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-12185SNYK-JAVA-ORGBOUNCYCASTLE-18512520org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-59651SNYK-JAVA-ORGBOUNCYCASTLE-18512572org.bouncycastle:bcprov-jdk18on1.81Inadequate Encryption Strength2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-59641SNYK-JAVA-ORGBOUNCYCASTLE-18512864org.bouncycastle:bcjmail-jdk18on1.81Insufficient Verification of Data Authenticity2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-59642SNYK-JAVA-ORGBOUNCYCASTLE-18512967org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-59639SNYK-JAVA-ORGBOUNCYCASTLE-18513021org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-12860SNYK-JAVA-ORGBOUNCYCASTLE-18518014org.bouncycastle:bcprov-jdk18on1.81Improper Verification of Cryptographic Signature2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-58061SNYK-JAVA-ORGBOUNCYCASTLE-18519127org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-12803SNYK-JAVA-ORGBOUNCYCASTLE-18519148org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-12816SNYK-JAVA-ORGBOUNCYCASTLE-18519163org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-58060SNYK-JAVA-ORGBOUNCYCASTLE-18519180org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-12802SNYK-JAVA-ORGBOUNCYCASTLE-18519217org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.1.1vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.12.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53667SNYK-JS-REACTROUTER-18313128react-router7.12.0Cross-site Scripting (XSS)2026-07-239.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.12.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.9.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.9.FinalInfinite loop2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
highCVE-2026-68494SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-07-219.1.1vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-219.1.8vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.4Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.12Inefficient Algorithmic Complexity2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.12Allocation of Resources Without Limits or Throttling2026-06-089.1.8vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.15Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.1.8vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.12Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.1.8vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.1.8vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
highCVE-2026-18401SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59647SNYK-JAVA-ORGBOUNCYCASTLE-18513013org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.1.1vulnerable_code_not_in_execute_path
mediumCVE-2026-15055SNYK-JAVA-ORGBOUNCYCASTLE-18517495org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.1.1vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518977org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.1.1vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518992org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.1.1vulnerable_code_not_in_execute_path
mediumCVE-2026-58063SNYK-JAVA-ORGBOUNCYCASTLE-18519071org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.1.1vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-REACTROUTER-18313151react-router7.12.0Cross-site Request Forgery (CSRF)2026-07-249.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.3.0Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.12.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53668SNYK-JS-REACTROUTER-18313146react-router7.12.0Open Redirect2026-07-239.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.9.FinalCRLF Injection2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.9.FinalHTTP Request Smuggling2026-07-229.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.9.FinalIncorrect Authorization2026-07-219.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.13.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.13.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.13.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67318SNYK-JS-AXIOS-18060804axios1.13.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.13.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.13.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.3Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.3.0Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.3.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.3.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.0Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.0Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.3.0Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-129.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.9.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.6Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.6Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.12Exposed Dangerous Method or Function2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.12Regular Expression Denial of Service (ReDoS)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.12Server-side Request Forgery (SSRF)2026-06-089.1.8vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.12Cross-site Scripting (XSS)2026-06-089.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.6Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.6Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.6Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.0Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.1.8vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-65913SNYK-JS-DOMPURIFY-15874903dompurify3.3.0Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65912SNYK-JS-DOMPURIFY-15874905dompurify3.3.0Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65914SNYK-JS-DOMPURIFY-15810938dompurify3.3.0Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.1.8vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.3.0Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.3.0Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.3.0Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (6)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-08
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-08
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-13
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-08
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-08
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-08

9.0.5 (released 2026-08-07) — previous: 9.0.4

Affected (19)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.7Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (68)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.6.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.6.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.2.7Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.6.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.2.7Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.2.7Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.7Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.2.7Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.7Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.7Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.2.7Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.7Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.7Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-65913SNYK-JS-DOMPURIFY-15874903dompurify3.2.7Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65912SNYK-JS-DOMPURIFY-15874905dompurify3.2.7Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65914SNYK-JS-DOMPURIFY-15810938dompurify3.2.7Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.2.7Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.2.7Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.2.7Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.7Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (9)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-03
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-03
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-03
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-08
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-26
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-14
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-21
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-21
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-05

9.0.4 (released 2026-06-29) — previous: 9.0.3

Affected (28)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.0.5Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (118)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-8763SNYK-JAVA-ORGBOUNCYCASTLE-18512779org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-59650SNYK-JAVA-ORGBOUNCYCASTLE-18512810org.bouncycastle:bcprov-jdk18on1.81Improper Input Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-58062SNYK-JAVA-ORGBOUNCYCASTLE-18519194org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.18Deserialization of Untrusted Data2026-06-089.0.5vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.0.5vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-59645SNYK-JAVA-ORGBOUNCYCASTLE-18512330org.bouncycastle:bcutil-jdk18on1.81.1Uncontrolled Recursion2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12185SNYK-JAVA-ORGBOUNCYCASTLE-18512520org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59651SNYK-JAVA-ORGBOUNCYCASTLE-18512572org.bouncycastle:bcprov-jdk18on1.81Inadequate Encryption Strength2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59641SNYK-JAVA-ORGBOUNCYCASTLE-18512864org.bouncycastle:bcjmail-jdk18on1.81Insufficient Verification of Data Authenticity2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59642SNYK-JAVA-ORGBOUNCYCASTLE-18512967org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59639SNYK-JAVA-ORGBOUNCYCASTLE-18513021org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12860SNYK-JAVA-ORGBOUNCYCASTLE-18518014org.bouncycastle:bcprov-jdk18on1.81Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58061SNYK-JAVA-ORGBOUNCYCASTLE-18519127org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12803SNYK-JAVA-ORGBOUNCYCASTLE-18519148org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12816SNYK-JAVA-ORGBOUNCYCASTLE-18519163org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58060SNYK-JAVA-ORGBOUNCYCASTLE-18519180org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12802SNYK-JAVA-ORGBOUNCYCASTLE-18519217org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.6.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.6.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.15.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.15.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59889SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608com.fasterxml.jackson.core:jackson-databind2.22.0Incorrect Authorization2026-07-149.0.5vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.18Allocation of Resources Without Limits or Throttling2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.0.5vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.0.5vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.0.5vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59647SNYK-JAVA-ORGBOUNCYCASTLE-18513013org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-15055SNYK-JAVA-ORGBOUNCYCASTLE-18517495org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518977org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518992org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-58063SNYK-JAVA-ORGBOUNCYCASTLE-18519071org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.2.6Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.6.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.15.FinalCRLF Injection2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.15.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.15.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.15.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.15.FinalIncorrect Authorization2026-07-219.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.22.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-129.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-65913SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65912SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65914SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.0.5vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.2.6Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.2.6Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (6)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-12
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-10
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-26
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-26
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-10
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-15

9.0.3 (released 2026-05-07) — previous: 9.0.2

Affected (34)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.0.5Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-129.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.0.4Upgrade to TopBraid EDG 9.0.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (147)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-8763SNYK-JAVA-ORGBOUNCYCASTLE-18512779org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-59650SNYK-JAVA-ORGBOUNCYCASTLE-18512810org.bouncycastle:bcprov-jdk18on1.81Improper Input Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-58062SNYK-JAVA-ORGBOUNCYCASTLE-18519194org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.6.FinalIncorrect Comparison2026-06-089.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.18Deserialization of Untrusted Data2026-06-089.0.5vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.0.5vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-59645SNYK-JAVA-ORGBOUNCYCASTLE-18512330org.bouncycastle:bcutil-jdk18on1.81.1Uncontrolled Recursion2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12185SNYK-JAVA-ORGBOUNCYCASTLE-18512520org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59651SNYK-JAVA-ORGBOUNCYCASTLE-18512572org.bouncycastle:bcprov-jdk18on1.81Inadequate Encryption Strength2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59641SNYK-JAVA-ORGBOUNCYCASTLE-18512864org.bouncycastle:bcjmail-jdk18on1.81Insufficient Verification of Data Authenticity2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59642SNYK-JAVA-ORGBOUNCYCASTLE-18512967org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59639SNYK-JAVA-ORGBOUNCYCASTLE-18513021org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12860SNYK-JAVA-ORGBOUNCYCASTLE-18518014org.bouncycastle:bcprov-jdk18on1.81Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58061SNYK-JAVA-ORGBOUNCYCASTLE-18519127org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12803SNYK-JAVA-ORGBOUNCYCASTLE-18519148org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12816SNYK-JAVA-ORGBOUNCYCASTLE-18519163org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58060SNYK-JAVA-ORGBOUNCYCASTLE-18519180org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12802SNYK-JAVA-ORGBOUNCYCASTLE-18519217org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.6.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.6.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.6.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.6.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-68494SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-07-219.0.4vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.18Allocation of Resources Without Limits or Throttling2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.0.5vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.0.5vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.0.5vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.0.4vulnerable_code_not_in_execute_path
highCVE-2026-18401SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.0.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59647SNYK-JAVA-ORGBOUNCYCASTLE-18513013org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-15055SNYK-JAVA-ORGBOUNCYCASTLE-18517495org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518977org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518992org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-58063SNYK-JAVA-ORGBOUNCYCASTLE-18519071org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.2.6Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.6.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.6.FinalCRLF Injection2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.6.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.6.FinalIncorrect Authorization2026-07-219.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.4Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-129.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.6.FinalMissing Release of Memory after Effective Lifetime2026-06-119.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-65913SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65912SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65914SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.0.5vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.2.6Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.2.6Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (7)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-20
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-10
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-10
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-10
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-10
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-18
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-19

9.0.2 (released 2025-12-18) — previous: 9.0.1

Affected (41)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-209.0.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.0.5Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-129.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.5Cross-site Scripting (XSS)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-189.0.3Upgrade to TopBraid EDG 9.0.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.0.4Upgrade to TopBraid EDG 9.0.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.0.3Upgrade to TopBraid EDG 9.0.3 or later.

Not affected (149)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-8763SNYK-JAVA-ORGBOUNCYCASTLE-18512779org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-59650SNYK-JAVA-ORGBOUNCYCASTLE-18512810org.bouncycastle:bcprov-jdk18on1.81Improper Input Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-58062SNYK-JAVA-ORGBOUNCYCASTLE-18519194org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.6.FinalIncorrect Comparison2026-06-089.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.11Deserialization of Untrusted Data2026-06-089.0.5vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.0.5vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-59645SNYK-JAVA-ORGBOUNCYCASTLE-18512330org.bouncycastle:bcutil-jdk18on1.81.1Uncontrolled Recursion2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12185SNYK-JAVA-ORGBOUNCYCASTLE-18512520org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59651SNYK-JAVA-ORGBOUNCYCASTLE-18512572org.bouncycastle:bcprov-jdk18on1.81Inadequate Encryption Strength2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59641SNYK-JAVA-ORGBOUNCYCASTLE-18512864org.bouncycastle:bcjmail-jdk18on1.81Insufficient Verification of Data Authenticity2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59642SNYK-JAVA-ORGBOUNCYCASTLE-18512967org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59639SNYK-JAVA-ORGBOUNCYCASTLE-18513021org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12860SNYK-JAVA-ORGBOUNCYCASTLE-18518014org.bouncycastle:bcprov-jdk18on1.81Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58061SNYK-JAVA-ORGBOUNCYCASTLE-18519127org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12803SNYK-JAVA-ORGBOUNCYCASTLE-18519148org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12816SNYK-JAVA-ORGBOUNCYCASTLE-18519163org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58060SNYK-JAVA-ORGBOUNCYCASTLE-18519180org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12802SNYK-JAVA-ORGBOUNCYCASTLE-18519217org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.6.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.6.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.6.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.6.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-68494SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-07-219.0.4vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.11Inefficient Algorithmic Complexity2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.11Allocation of Resources Without Limits or Throttling2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.14Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.0.5vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-179.0.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.0.5vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.0.5vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.0.4vulnerable_code_not_in_execute_path
highCVE-2026-18401SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.0.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59647SNYK-JAVA-ORGBOUNCYCASTLE-18513013org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-15055SNYK-JAVA-ORGBOUNCYCASTLE-18517495org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518977org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518992org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-58063SNYK-JAVA-ORGBOUNCYCASTLE-18519071org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.2.6Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.6.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.6.FinalCRLF Injection2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.6.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.6.FinalIncorrect Authorization2026-07-219.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.2Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-129.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.6.FinalMissing Release of Memory after Effective Lifetime2026-06-119.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.5Open Redirect2026-06-109.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.5Information Exposure2026-06-099.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.11Exposed Dangerous Method or Function2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.11Regular Expression Denial of Service (ReDoS)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.11Server-side Request Forgery (SSRF)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.11Cross-site Scripting (XSS)2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-179.0.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-65913SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65912SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65914SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.0.5vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.2.6Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.2.6Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (4)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-08
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-08
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.2.6.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-07
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.2.6.FinalGeneration of Predictable Numbers or Identifiers2026-06-08

9.0.1 (released 2025-11-18) — previous: 9.0.0

Affected (45)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-209.0.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.0.5Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-129.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.2.6.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.5Cross-site Scripting (XSS)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.2.6.FinalGeneration of Predictable Numbers or Identifiers2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-189.0.3Upgrade to TopBraid EDG 9.0.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.0.4Upgrade to TopBraid EDG 9.0.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.0.3Upgrade to TopBraid EDG 9.0.3 or later.

Not affected (152)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-8763SNYK-JAVA-ORGBOUNCYCASTLE-18512779org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-59650SNYK-JAVA-ORGBOUNCYCASTLE-18512810org.bouncycastle:bcprov-jdk18on1.81Improper Input Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-58062SNYK-JAVA-ORGBOUNCYCASTLE-18519194org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.6.FinalIncorrect Comparison2026-06-089.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.11Deserialization of Untrusted Data2026-06-089.0.5vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.0.5vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-59645SNYK-JAVA-ORGBOUNCYCASTLE-18512330org.bouncycastle:bcutil-jdk18on1.81.1Uncontrolled Recursion2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12185SNYK-JAVA-ORGBOUNCYCASTLE-18512520org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59651SNYK-JAVA-ORGBOUNCYCASTLE-18512572org.bouncycastle:bcprov-jdk18on1.81Inadequate Encryption Strength2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59641SNYK-JAVA-ORGBOUNCYCASTLE-18512864org.bouncycastle:bcjmail-jdk18on1.81Insufficient Verification of Data Authenticity2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59642SNYK-JAVA-ORGBOUNCYCASTLE-18512967org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59639SNYK-JAVA-ORGBOUNCYCASTLE-18513021org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12860SNYK-JAVA-ORGBOUNCYCASTLE-18518014org.bouncycastle:bcprov-jdk18on1.81Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58061SNYK-JAVA-ORGBOUNCYCASTLE-18519127org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12803SNYK-JAVA-ORGBOUNCYCASTLE-18519148org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12816SNYK-JAVA-ORGBOUNCYCASTLE-18519163org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58060SNYK-JAVA-ORGBOUNCYCASTLE-18519180org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12802SNYK-JAVA-ORGBOUNCYCASTLE-18519217org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.6.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.6.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.6.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.6.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-68494SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-07-219.0.4vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.11Inefficient Algorithmic Complexity2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.11Allocation of Resources Without Limits or Throttling2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.14Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.0.5vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-179.0.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.0.5vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.0.5vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.0.4vulnerable_code_not_in_execute_path
highCVE-2026-18401SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.0.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59647SNYK-JAVA-ORGBOUNCYCASTLE-18513013org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-15055SNYK-JAVA-ORGBOUNCYCASTLE-18517495org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518977org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518992org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-58063SNYK-JAVA-ORGBOUNCYCASTLE-18519071org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
medium(none)SNYK-JAVA-IONETTY-18313049io.netty:netty-codec-dns4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-07-249.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.2.6Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.6.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.6.FinalCRLF Injection2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.6.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.6.FinalIncorrect Authorization2026-07-219.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.2Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-129.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.6.FinalMissing Release of Memory after Effective Lifetime2026-06-119.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.5Open Redirect2026-06-109.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.5Information Exposure2026-06-099.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41715SNYK-JAVA-IOPROJECTREACTORNETTY-17260961io.projectreactor.netty:reactor-netty-http1.2.9Cleartext Transmission of Sensitive Information2026-06-089.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.11Exposed Dangerous Method or Function2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.11Regular Expression Denial of Service (ReDoS)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.11Server-side Request Forgery (SSRF)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.11Cross-site Scripting (XSS)2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.2.6.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-179.0.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-65913SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65912SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65914SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.0.5vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.2.6Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.2.6Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.0.0 (released 2025-11-04) — previous: 8.5.4

Affected (45)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-209.0.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-58059SNYK-JAVA-ORGBOUNCYCASTLE-18518039org.bouncycastle:bcprov-jdk18on1.81Inefficient Algorithmic Complexity2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-14682SNYK-JAVA-ORGBOUNCYCASTLE-18518087org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-13506SNYK-JAVA-ORGBOUNCYCASTLE-18519010org.bouncycastle:bcprov-jdk18on1.81Uncontrolled Recursion2026-08-039.0.5Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-45112SNYK-JAVA-ORGAPACHETHRIFT-18389002org.apache.thrift:libthrift0.22.0Allocation of Resources Without Limits or Throttling2026-07-279.1.8Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available.
highCVE-2026-59887SNYK-JS-LINKIFYIT-17901217linkify-it5.0.0Inefficient Algorithmic Complexity2026-07-089.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-54399SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available.
highCVE-2026-48801SNYK-JS-LINKIFYIT-17817062linkify-it5.0.0Regular Expression Denial of Service (ReDoS)2026-06-269.0.5Upgrade to TopBraid EDG 9.3.0 or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-129.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.2.6.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.0.5Upgrade to TopBraid EDG 9.0.5 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.5Cross-site Scripting (XSS)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.2.6.FinalGeneration of Predictable Numbers or Identifiers2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-189.0.3Upgrade to TopBraid EDG 9.0.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.0.4Upgrade to TopBraid EDG 9.0.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.0.5Upgrade to TopBraid EDG 9.0.5 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.0.3Upgrade to TopBraid EDG 9.0.3 or later.

Not affected (152)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-8763SNYK-JAVA-ORGBOUNCYCASTLE-18512779org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-59650SNYK-JAVA-ORGBOUNCYCASTLE-18512810org.bouncycastle:bcprov-jdk18on1.81Improper Input Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-58062SNYK-JAVA-ORGBOUNCYCASTLE-18519194org.bouncycastle:bcprov-jdk18on1.81Improper Certificate Validation2026-08-039.0.5vulnerable_code_not_in_execute_path
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.6.FinalIncorrect Comparison2026-06-089.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-41855SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609org.springframework:spring-web6.2.11Deserialization of Untrusted Data2026-06-089.0.5vulnerable_code_not_present
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.0.5vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-59645SNYK-JAVA-ORGBOUNCYCASTLE-18512330org.bouncycastle:bcutil-jdk18on1.81.1Uncontrolled Recursion2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12185SNYK-JAVA-ORGBOUNCYCASTLE-18512520org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59651SNYK-JAVA-ORGBOUNCYCASTLE-18512572org.bouncycastle:bcprov-jdk18on1.81Inadequate Encryption Strength2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59641SNYK-JAVA-ORGBOUNCYCASTLE-18512864org.bouncycastle:bcjmail-jdk18on1.81Insufficient Verification of Data Authenticity2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59642SNYK-JAVA-ORGBOUNCYCASTLE-18512967org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59639SNYK-JAVA-ORGBOUNCYCASTLE-18513021org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12860SNYK-JAVA-ORGBOUNCYCASTLE-18518014org.bouncycastle:bcprov-jdk18on1.81Improper Verification of Cryptographic Signature2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58061SNYK-JAVA-ORGBOUNCYCASTLE-18519127org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12803SNYK-JAVA-ORGBOUNCYCASTLE-18519148org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12816SNYK-JAVA-ORGBOUNCYCASTLE-18519163org.bouncycastle:bcprov-jdk18on1.81Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-58060SNYK-JAVA-ORGBOUNCYCASTLE-18519180org.bouncycastle:bcprov-jdk18on1.81Memory Allocation with Excessive Size Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-12802SNYK-JAVA-ORGBOUNCYCASTLE-18519217org.bouncycastle:bcpkix-jdk18on1.81.1Improper Validation of Integrity Check Value2026-08-039.0.5vulnerable_code_not_in_execute_path
highCVE-2026-48586SNYK-JAVA-ORGAPACHETHRIFT-18389256org.apache.thrift:libthrift0.22.0Improper Handling of Highly Compressed Data (Data Amplification)2026-07-279.1.8vulnerable_code_not_in_execute_path
highCVE-2026-55685SNYK-JS-REACTROUTER-18313148react-router7.6.0Inefficient Algorithmic Complexity2026-07-249.3.0vulnerable_code_not_in_execute_path
highCVE-2026-53669SNYK-JS-REACTROUTER-18313144react-router7.6.0Open Redirect2026-07-239.3.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-59901SNYK-JAVA-IONETTY-18230935io.netty:netty-codec4.2.6.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-59901SNYK-JAVA-IONETTY-18230936io.netty:netty-codec-compression4.2.6.FinalInfinite loop2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-55831SNYK-JAVA-IONETTY-18233079io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
highCVE-2026-68494SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-07-219.0.4vulnerable_code_not_in_execute_path
highCVE-2026-55833SNYK-JAVA-IONETTY-18170202io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56819SNYK-JAVA-IONETTY-18170204io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-56745SNYK-JAVA-IONETTY-18170213io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-219.0.5vulnerable_code_not_in_execute_path
highCVE-2026-54428SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217org.apache.httpcomponents.core5:httpcore5-h25.3.6Allocation of Resources Without Limits or Throttling2026-07-019.1.8vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.11Inefficient Algorithmic Complexity2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606org.springframework:spring-expression6.2.11Allocation of Resources Without Limits or Throttling2026-06-089.0.5vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.14Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.0.5vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.0.5vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-179.0.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.0.5vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.0.5vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.0.4vulnerable_code_not_in_execute_path
highCVE-2026-18401SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.0.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59647SNYK-JAVA-ORGBOUNCYCASTLE-18513013org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-15055SNYK-JAVA-ORGBOUNCYCASTLE-18517495org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518977org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-13586SNYK-JAVA-ORGBOUNCYCASTLE-18518992org.bouncycastle:bcpkix-jdk18on1.81.1Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-58063SNYK-JAVA-ORGBOUNCYCASTLE-18519071org.bouncycastle:bcprov-jdk18on1.81Allocation of Resources Without Limits or Throttling2026-08-039.0.5vulnerable_code_not_in_execute_path
medium(none)SNYK-JAVA-IONETTY-18313049io.netty:netty-codec-dns4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-07-249.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-65911SNYK-JS-DOMPURIFY-18307175dompurify3.2.6Cross-site Scripting (XSS)2026-07-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-53666SNYK-JS-REACTROUTER-18313130react-router7.6.0Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2026-07-239.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59921SNYK-JAVA-IONETTY-18231070io.netty:netty-codec-http4.2.6.FinalCRLF Injection2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59899SNYK-JAVA-IONETTY-18233081io.netty:netty-codec-http4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59898SNYK-JAVA-IONETTY-18233107io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-59900SNYK-JAVA-IONETTY-18233111io.netty:netty-codec-http24.2.6.FinalHTTP Request Smuggling2026-07-229.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-56746SNYK-JAVA-IONETTY-18170206io.netty:netty-codec-http4.2.6.FinalIncorrect Authorization2026-07-219.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-67312SNYK-JS-AXIOS-18060165axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67313SNYK-JS-AXIOS-18060167axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67314SNYK-JS-AXIOS-18060659axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67321SNYK-JS-AXIOS-18060730axios1.12.2Uncontrolled Recursion2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67319SNYK-JS-AXIOS-18065349axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-67320SNYK-JS-AXIOS-18065351axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67317SNYK-JS-AXIOS-18065353axios1.12.2Allocation of Resources Without Limits or Throttling2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-67316SNYK-JS-AXIOS-18065355axios1.12.2Prototype Pollution2026-07-209.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-59888SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-07-149.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-49844SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276org.apache.logging.log4j:log4j-api2.25.2Improper Encoding or Escaping of Output2026-07-109.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-65898SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-189.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65901SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65902SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65900SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-159.2.3vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-159.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-129.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.6.FinalMissing Release of Memory after Effective Lifetime2026-06-119.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.5Open Redirect2026-06-109.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.5Information Exposure2026-06-099.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41715SNYK-JAVA-IOPROJECTREACTORNETTY-17260961io.projectreactor.netty:reactor-netty-http1.2.9Cleartext Transmission of Sensitive Information2026-06-089.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.11Exposed Dangerous Method or Function2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.11Regular Expression Denial of Service (ReDoS)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.11Server-side Request Forgery (SSRF)2026-06-089.0.5vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.11Cross-site Scripting (XSS)2026-06-089.0.5vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-049.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-049.3.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-299.3.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.2.6.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.1.8vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-179.0.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-65913SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65912SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-65914SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.0.5vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.0.5vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
lowCVE-2026-65904SNYK-JS-DOMPURIFY-18307177dompurify3.2.6Improper Check for Unusual or Exceptional Conditions2026-07-239.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-66010SNYK-JS-DOMPURIFY-18170233dompurify3.2.6Incomplete List of Disallowed Inputs2026-07-219.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-65899SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-159.2.3vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path