Generated 2026-08-07T15:49:32Z
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.16.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.16.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.16.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.15.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.15.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.16.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.16.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.15.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.15.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67315 | SNYK-JS-AXIOS-18065357 | axios | 1.15.2 | Permissive List of Allowed Inputs | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.1 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.15.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.15.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44489 | SNYK-JS-AXIOS-17111086 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.84 | Inefficient Algorithmic Complexity | 2026-08-03 |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.84 | Memory Allocation with Excessive Size Value | 2026-08-03 |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.84 | Uncontrolled Recursion | 2026-08-03 |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.23.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.84 | Inefficient Algorithmic Complexity | 2026-08-03 | 9.2.3 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.84 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.2.3 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.84 | Uncontrolled Recursion | 2026-08-03 | 9.2.3 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.23.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.2.3 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.2.3 | Upgrade to TopBraid EDG 9.2.3 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.2.3 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.2.3 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-8763 | SNYK-JAVA-ORGBOUNCYCASTLE-18512779 | org.bouncycastle:bcprov-jdk18on | 1.84 | Improper Certificate Validation | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-59650 | SNYK-JAVA-ORGBOUNCYCASTLE-18512810 | org.bouncycastle:bcprov-jdk18on | 1.84 | Improper Input Validation | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-58062 | SNYK-JAVA-ORGBOUNCYCASTLE-18519194 | org.bouncycastle:bcprov-jdk18on | 1.84 | Improper Certificate Validation | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 7.0.7 | Deserialization of Untrusted Data | 2026-06-08 | 9.2.3 | vulnerable_code_not_present |
| high | CVE-2026-59645 | SNYK-JAVA-ORGBOUNCYCASTLE-18512330 | org.bouncycastle:bcutil-jdk18on | 1.84 | Uncontrolled Recursion | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12185 | SNYK-JAVA-ORGBOUNCYCASTLE-18512520 | org.bouncycastle:bcprov-jdk18on | 1.84 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59651 | SNYK-JAVA-ORGBOUNCYCASTLE-18512572 | org.bouncycastle:bcprov-jdk18on | 1.84 | Inadequate Encryption Strength | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59641 | SNYK-JAVA-ORGBOUNCYCASTLE-18512864 | org.bouncycastle:bcjmail-jdk18on | 1.84 | Insufficient Verification of Data Authenticity | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59642 | SNYK-JAVA-ORGBOUNCYCASTLE-18512967 | org.bouncycastle:bcpkix-jdk18on | 1.84 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59639 | SNYK-JAVA-ORGBOUNCYCASTLE-18513021 | org.bouncycastle:bcpkix-jdk18on | 1.84 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12860 | SNYK-JAVA-ORGBOUNCYCASTLE-18518014 | org.bouncycastle:bcprov-jdk18on | 1.84 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58061 | SNYK-JAVA-ORGBOUNCYCASTLE-18519127 | org.bouncycastle:bcprov-jdk18on | 1.84 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12803 | SNYK-JAVA-ORGBOUNCYCASTLE-18519148 | org.bouncycastle:bcprov-jdk18on | 1.84 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12816 | SNYK-JAVA-ORGBOUNCYCASTLE-18519163 | org.bouncycastle:bcprov-jdk18on | 1.84 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58060 | SNYK-JAVA-ORGBOUNCYCASTLE-18519180 | org.bouncycastle:bcprov-jdk18on | 1.84 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12802 | SNYK-JAVA-ORGBOUNCYCASTLE-18519217 | org.bouncycastle:bcpkix-jdk18on | 1.84 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.23.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.16.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.16.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.16.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.15.Final | Infinite loop | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.15.Final | Infinite loop | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59889 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608 | com.fasterxml.jackson.core:jackson-databind | 2.22.0 | Incorrect Authorization | 2026-07-14 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 7.0.7 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 7.0.7 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.15.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.15.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| medium | CVE-2026-59647 | SNYK-JAVA-ORGBOUNCYCASTLE-18513013 | org.bouncycastle:bcpkix-jdk18on | 1.84 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-15055 | SNYK-JAVA-ORGBOUNCYCASTLE-18517495 | org.bouncycastle:bcpkix-jdk18on | 1.84 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518977 | org.bouncycastle:bcprov-jdk18on | 1.84 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518992 | org.bouncycastle:bcpkix-jdk18on | 1.84 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-58063 | SNYK-JAVA-ORGBOUNCYCASTLE-18519071 | org.bouncycastle:bcprov-jdk18on | 1.84 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.16.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.16.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.15.Final | CRLF Injection | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.15.Final | HTTP Request Smuggling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.15.Final | HTTP Request Smuggling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.15.Final | Incorrect Authorization | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.15.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.15.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67315 | SNYK-JS-AXIOS-18065357 | axios | 1.15.2 | Permissive List of Allowed Inputs | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.22.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.4.0 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.4.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.4.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.4.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.4.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.4.0 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.4.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.1 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.5 | CRLF Injection | 2026-06-12 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 7.0.7 | Exposed Dangerous Method or Function | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 7.0.7 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.2.3 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 7.0.7 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.2.3 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 7.0.7 | Cross-site Scripting (XSS) | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.15.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.15.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44489 | SNYK-JS-AXIOS-17111086 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.4.0 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.4.0 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.4.0 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.13.Final | Improper Verification of Cryptographic Signature | 2026-06-12 |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Cross-site Scripting (XSS) | 2026-06-10 |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 8.4.0 | Cross-site Scripting (XSS) | 2026-05-28 |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 8.4.0 | Cross-site Scripting (XSS) | 2026-05-28 |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 8.4.0 | Cross-site Scripting (XSS) | 2026-05-28 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.23.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.2.3 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.2.3 | Upgrade to TopBraid EDG 9.2.3 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.2.3 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.2.3 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.13.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.2.2 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.2.2 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Cross-site Scripting (XSS) | 2026-06-10 | 9.2.2 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 8.4.0 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 8.4.0 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 8.4.0 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Deserialization of Untrusted Data | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.13.Final | Incorrect Comparison | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 7.0.7 | Deserialization of Untrusted Data | 2026-06-08 | 9.2.3 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.14.1 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.23.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.14.1 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.14.1 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.14.1 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.13.Final | Infinite loop | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.13.Final | Infinite loop | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59889 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-14 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-40993 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17304906 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Deserialization of Untrusted Data | 2026-06-09 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 7.0.7 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 7.0.7 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 4.0.3 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.15.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.14.1 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.15.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.14.1 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.14.1 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.13.Final | CRLF Injection | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.13.Final | HTTP Request Smuggling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.13.Final | HTTP Request Smuggling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-21 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.13.Final | Incorrect Authorization | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.15.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.15.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67315 | SNYK-JS-AXIOS-18065357 | axios | 1.15.2 | Permissive List of Allowed Inputs | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54517 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54518 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54516 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.4.0 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.4.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.4.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.4.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.4.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.4.0 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.4.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.1 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.13.Final | HTTP Request Smuggling | 2026-06-12 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.5 | CRLF Injection | 2026-06-12 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.13.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.2.2 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 7.0.5 | Open Redirect | 2026-06-10 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Information Exposure | 2026-06-09 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.13.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 7.0.7 | Exposed Dangerous Method or Function | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 7.0.7 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.2.3 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 7.0.7 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.2.3 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 7.0.7 | Cross-site Scripting (XSS) | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.15.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.15.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44489 | SNYK-JS-AXIOS-17111086 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.4.0 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.4.0 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.4.0 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.14.1 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.2.3 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.2.3 | Upgrade to TopBraid EDG 9.2.3 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.2.3 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.2.3 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.13.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.2.2 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.2.2 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Cross-site Scripting (XSS) | 2026-06-10 | 9.2.2 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 8.4.0 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 8.4.0 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 8.4.0 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Deserialization of Untrusted Data | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.13.Final | Incorrect Comparison | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 7.0.7 | Deserialization of Untrusted Data | 2026-06-08 | 9.2.3 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.14.1 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.14.1 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.14.1 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.14.1 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.13.Final | Infinite loop | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.13.Final | Infinite loop | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59889 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-14 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-40993 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17304906 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Deserialization of Untrusted Data | 2026-06-09 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 7.0.7 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 7.0.7 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 4.0.3 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.15.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.14.1 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.15.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.14.1 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.14.1 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.13.Final | CRLF Injection | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.13.Final | HTTP Request Smuggling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.13.Final | HTTP Request Smuggling | 2026-07-22 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-21 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.13.Final | Incorrect Authorization | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.15.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.15.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.15.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67315 | SNYK-JS-AXIOS-18065357 | axios | 1.15.2 | Permissive List of Allowed Inputs | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54517 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54518 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54516 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.4.0 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.4.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.4.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.4.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.4.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.4.0 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.4.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.1 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.13.Final | HTTP Request Smuggling | 2026-06-12 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.5 | CRLF Injection | 2026-06-12 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.13.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.2.2 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 7.0.5 | Open Redirect | 2026-06-10 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 7.0.5 | Information Exposure | 2026-06-09 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.13.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.13.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 7.0.7 | Exposed Dangerous Method or Function | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 7.0.7 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.2.3 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 7.0.7 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.2.3 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 7.0.7 | Cross-site Scripting (XSS) | 2026-06-08 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.15.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.15.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.15.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44489 | SNYK-JS-AXIOS-17111086 | axios | 1.15.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-8723 | SNYK-JS-QS-16721866 | qs | 6.15.1 | NULL Pointer Dereference | 2026-05-17 | 9.2.1 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.2.1 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.4.0 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.4.0 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.4.0 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.14.1 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-10 |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.12.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.13.6 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.12.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.16 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.12.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.13.6 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.13.6 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.12.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53668 | SNYK-JS-REACTROUTER-18313146 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.3.3 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.3.3 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.1 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.13.6 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33245 | SNYK-JS-REACTROUTER-17137545 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.13.6 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.13.6 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.3.3 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.13.6 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.3.3 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.3.3 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.3.3 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.11 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 | 9.1.8 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.1.8 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 | 9.1.8 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.1.8 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.11 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-8763 | SNYK-JAVA-ORGBOUNCYCASTLE-18512779 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-59650 | SNYK-JAVA-ORGBOUNCYCASTLE-18512810 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Input Validation | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-58062 | SNYK-JAVA-ORGBOUNCYCASTLE-18519194 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.18 | Deserialization of Untrusted Data | 2026-06-08 | 9.1.8 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.12.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.13.6 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59645 | SNYK-JAVA-ORGBOUNCYCASTLE-18512330 | org.bouncycastle:bcutil-jdk18on | 1.81.1 | Uncontrolled Recursion | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12185 | SNYK-JAVA-ORGBOUNCYCASTLE-18512520 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59651 | SNYK-JAVA-ORGBOUNCYCASTLE-18512572 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inadequate Encryption Strength | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59641 | SNYK-JAVA-ORGBOUNCYCASTLE-18512864 | org.bouncycastle:bcjmail-jdk18on | 1.81 | Insufficient Verification of Data Authenticity | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59642 | SNYK-JAVA-ORGBOUNCYCASTLE-18512967 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59639 | SNYK-JAVA-ORGBOUNCYCASTLE-18513021 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12860 | SNYK-JAVA-ORGBOUNCYCASTLE-18518014 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58061 | SNYK-JAVA-ORGBOUNCYCASTLE-18519127 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12803 | SNYK-JAVA-ORGBOUNCYCASTLE-18519148 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12816 | SNYK-JAVA-ORGBOUNCYCASTLE-18519163 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58060 | SNYK-JAVA-ORGBOUNCYCASTLE-18519180 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12802 | SNYK-JAVA-ORGBOUNCYCASTLE-18519217 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.12.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.15.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.15.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59889 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608 | com.fasterxml.jackson.core:jackson-databind | 2.22.0 | Incorrect Authorization | 2026-07-14 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.18 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.18 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.16 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.12.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.7 | Unsafe Reflection | 2026-05-04 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.7 | XML External Entity (XXE) Injection | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.7 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.13.6 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.13.6 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59647 | SNYK-JAVA-ORGBOUNCYCASTLE-18513013 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-15055 | SNYK-JAVA-ORGBOUNCYCASTLE-18517495 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518977 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518992 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-58063 | SNYK-JAVA-ORGBOUNCYCASTLE-18519071 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.12.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53668 | SNYK-JS-REACTROUTER-18313146 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.15.Final | CRLF Injection | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.15.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.15.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.15.Final | Incorrect Authorization | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.22.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.3.3 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.3.3 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.1 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.5 | CRLF Injection | 2026-06-12 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.18 | Exposed Dangerous Method or Function | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.18 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.18 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.18 | Cross-site Scripting (XSS) | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.13.6 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33245 | SNYK-JS-REACTROUTER-17137545 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.13.6 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.13.6 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-40542 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546 | org.apache.httpcomponents.client5:httpclient5 | 5.6 | Missing Critical Step in Authentication | 2026-04-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.3.3 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.13.6 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.3.3 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.3.3 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.3.3 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.12.Final | Improper Verification of Cryptographic Signature | 2026-06-12 |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Cross-site Scripting (XSS) | 2026-06-10 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.1.8 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.12.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.11 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Cross-site Scripting (XSS) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Deserialization of Untrusted Data | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.12.Final | Incorrect Comparison | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.18 | Deserialization of Untrusted Data | 2026-06-08 | 9.1.8 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.12.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.13.6 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.12.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.12.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.12.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59889 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-14 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.9 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.9 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.18 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.18 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.16 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.12.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.12.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.12.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.12.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.7 | Unsafe Reflection | 2026-05-04 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.7 | XML External Entity (XXE) Injection | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.7 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.13.6 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.13.6 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.12.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53668 | SNYK-JS-REACTROUTER-18313146 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.12.Final | CRLF Injection | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.12.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.12.Final | Incorrect Authorization | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54517 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54518 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54516 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.3.3 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.3.3 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.1 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.5 | CRLF Injection | 2026-06-12 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.12.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.9 | Open Redirect | 2026-06-10 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Information Exposure | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.12.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.18 | Exposed Dangerous Method or Function | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.18 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.18 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.18 | Cross-site Scripting (XSS) | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.13.6 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33245 | SNYK-JS-REACTROUTER-17137545 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-05 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.13.6 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.13.6 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-40542 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546 | org.apache.httpcomponents.client5:httpclient5 | 5.6 | Missing Critical Step in Authentication | 2026-04-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.9 | Information Exposure | 2026-04-22 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.9 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.9 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.3.3 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.13.6 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.3.3 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.3.3 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.3.3 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 | 9.1.6 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.1.6 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 | 9.1.6 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.1.8 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.12.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.11 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Cross-site Scripting (XSS) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.1.6 | Upgrade to TopBraid EDG 9.1.6 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-8763 | SNYK-JAVA-ORGBOUNCYCASTLE-18512779 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-59650 | SNYK-JAVA-ORGBOUNCYCASTLE-18512810 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Input Validation | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-58062 | SNYK-JAVA-ORGBOUNCYCASTLE-18519194 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Deserialization of Untrusted Data | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.12.Final | Incorrect Comparison | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.18 | Deserialization of Untrusted Data | 2026-06-08 | 9.1.8 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.12.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.13.6 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59645 | SNYK-JAVA-ORGBOUNCYCASTLE-18512330 | org.bouncycastle:bcutil-jdk18on | 1.81.1 | Uncontrolled Recursion | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12185 | SNYK-JAVA-ORGBOUNCYCASTLE-18512520 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59651 | SNYK-JAVA-ORGBOUNCYCASTLE-18512572 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inadequate Encryption Strength | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59641 | SNYK-JAVA-ORGBOUNCYCASTLE-18512864 | org.bouncycastle:bcjmail-jdk18on | 1.81 | Insufficient Verification of Data Authenticity | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59642 | SNYK-JAVA-ORGBOUNCYCASTLE-18512967 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59639 | SNYK-JAVA-ORGBOUNCYCASTLE-18513021 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12860 | SNYK-JAVA-ORGBOUNCYCASTLE-18518014 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58061 | SNYK-JAVA-ORGBOUNCYCASTLE-18519127 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12803 | SNYK-JAVA-ORGBOUNCYCASTLE-18519148 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12816 | SNYK-JAVA-ORGBOUNCYCASTLE-18519163 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58060 | SNYK-JAVA-ORGBOUNCYCASTLE-18519180 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12802 | SNYK-JAVA-ORGBOUNCYCASTLE-18519217 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.12.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.12.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.12.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-68494 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159 | com.fasterxml.jackson.core:jackson-core | 2.21.2 | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.6 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59889 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-14 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.9 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.9 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.18 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.18 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.16 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.12.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.12.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.12.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.12.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.7 | Unsafe Reflection | 2026-05-04 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.7 | XML External Entity (XXE) Injection | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.7 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.13.6 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.13.6 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59647 | SNYK-JAVA-ORGBOUNCYCASTLE-18513013 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-15055 | SNYK-JAVA-ORGBOUNCYCASTLE-18517495 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518977 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518992 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-58063 | SNYK-JAVA-ORGBOUNCYCASTLE-18519071 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.6 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.12.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53668 | SNYK-JS-REACTROUTER-18313146 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.12.Final | CRLF Injection | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.12.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.12.Final | Incorrect Authorization | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54517 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54518 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54516 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.3.3 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.3.3 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.5 | CRLF Injection | 2026-06-12 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.12.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.9 | Open Redirect | 2026-06-10 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Information Exposure | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.12.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.18 | Exposed Dangerous Method or Function | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.18 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.18 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.18 | Cross-site Scripting (XSS) | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.13.6 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33245 | SNYK-JS-REACTROUTER-17137545 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-05 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.13.6 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.13.6 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-40542 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546 | org.apache.httpcomponents.client5:httpclient5 | 5.6 | Missing Critical Step in Authentication | 2026-04-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.9 | Information Exposure | 2026-04-22 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.9 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.9 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.3.3 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.13.6 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.3.3 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.3.3 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.3.3 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Output Neutralization for Logs | 2026-04-10 |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.1.8 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.12.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.11 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Output Neutralization for Logs | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Cross-site Scripting (XSS) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.1.6 | Upgrade to TopBraid EDG 9.1.6 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Deserialization of Untrusted Data | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.12.Final | Incorrect Comparison | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.17 | Deserialization of Untrusted Data | 2026-06-08 | 9.1.8 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.12.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.13.6 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.12.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.12.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.12.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59889 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-14 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.9 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.9 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.17 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.17 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.16 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.12.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.12.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.12.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.12.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.7 | Unsafe Reflection | 2026-05-04 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.7 | XML External Entity (XXE) Injection | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.7 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.13.6 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.13.6 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-22740 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615 | org.springframework:spring-web | 6.2.17 | Incomplete Cleanup | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.12.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53668 | SNYK-JS-REACTROUTER-18313146 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.12.Final | CRLF Injection | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.12.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.12.Final | Incorrect Authorization | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.3 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54517 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54518 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54516 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.3.3 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.3.3 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.5 | CRLF Injection | 2026-06-12 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.12.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.9 | Open Redirect | 2026-06-10 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Information Exposure | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.12.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.12.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.17 | Exposed Dangerous Method or Function | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.17 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.17 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.17 | Cross-site Scripting (XSS) | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.13.6 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33245 | SNYK-JS-REACTROUTER-17137545 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.12.Final | HTTP Request Smuggling | 2026-05-05 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.13.6 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.13.6 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-40542 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546 | org.apache.httpcomponents.client5:httpclient5 | 5.6 | Missing Critical Step in Authentication | 2026-04-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.9 | Information Exposure | 2026-04-22 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.9 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.9 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22745 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618 | org.springframework:spring-core | 6.2.17 | Allocation of Resources Without Limits or Throttling | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.3.3 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.13.6 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.3.3 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.3.3 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.3.3 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.23 | Arbitrary Code Injection | 2026-03-31 |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-03-26 |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.23 | Prototype Pollution | 2026-03-31 |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 |
| low | CVE-2026-22735 | SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 | org.springframework:spring-web | 6.2.16 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2026-03-19 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.1.8 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.9.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.11 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Output Neutralization for Logs | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.23 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-03-26 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Cross-site Scripting (XSS) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.23 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.1.6 | Upgrade to TopBraid EDG 9.1.6 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| low | CVE-2026-22735 | SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 | org.springframework:spring-web | 6.2.16 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2026-03-19 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Deserialization of Untrusted Data | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.9.Final | Incorrect Comparison | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.16 | Deserialization of Untrusted Data | 2026-06-08 | 9.1.8 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.12.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.13.6 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.13.6 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.12.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.9.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.9.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59889 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-14 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.9 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.9 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.16 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.16 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.16 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.12.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.9.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.9.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.9.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.7 | Unsafe Reflection | 2026-05-04 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.7 | XML External Entity (XXE) Injection | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.7 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.13.6 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.13.6 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-22740 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615 | org.springframework:spring-web | 6.2.16 | Incomplete Cleanup | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.12.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53668 | SNYK-JS-REACTROUTER-18313146 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.9.Final | CRLF Injection | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.9.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18170132 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-07-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.9.Final | Incorrect Authorization | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.13.6 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.13.6 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.3 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54517 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54518 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Incorrect Authorization | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54516 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.21.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.3.3 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.3.3 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.3.3 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.5 | CRLF Injection | 2026-06-12 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.9.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.9 | Open Redirect | 2026-06-10 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Information Exposure | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.9.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.16 | Exposed Dangerous Method or Function | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.16 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.16 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.16 | Cross-site Scripting (XSS) | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.13.6 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33245 | SNYK-JS-REACTROUTER-17137545 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.13.6 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-05 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.13.6 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.13.6 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.13.6 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.13.6 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.13.6 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.13.6 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-40542 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546 | org.apache.httpcomponents.client5:httpclient5 | 5.6 | Missing Critical Step in Authentication | 2026-04-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.9 | Information Exposure | 2026-04-22 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.9 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.9 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22745 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618 | org.springframework:spring-core | 6.2.16 | Allocation of Resources Without Limits or Throttling | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.3.3 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.13.6 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.3.3 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.3.3 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.3.3 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.3.3 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| critical | CVE-2026-22732 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796 | org.springframework.security:spring-security-web | 6.5.6 | Use of Cache Containing Sensitive Information | 2026-03-20 |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.13.2 | Prototype Pollution | 2026-02-09 |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-03-03 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-22732 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796 | org.springframework.security:spring-security-web | 6.5.6 | Use of Cache Containing Sensitive Information | 2026-03-20 | 9.1.3 | Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.1.8 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.9.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.6 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.9 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Output Neutralization for Logs | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.2 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.23 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-03-26 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.13.2 | Prototype Pollution | 2026-02-09 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.6 | Cross-site Scripting (XSS) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.23 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-03-03 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.1.6 | Upgrade to TopBraid EDG 9.1.6 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| low | CVE-2026-22735 | SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 | org.springframework:spring-web | 6.2.12 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2026-03-19 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Deserialization of Untrusted Data | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.9.Final | Incorrect Comparison | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.12 | Deserialization of Untrusted Data | 2026-06-08 | 9.1.8 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.12.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.13.2 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.13.2 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.13.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.12.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.9.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.9.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.6 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.6 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.12 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.12 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.15 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.13.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.12.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.13.2 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.13.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.13.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.9.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.9.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.9.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.7 | Unsafe Reflection | 2026-05-04 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.7 | XML External Entity (XXE) Injection | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.7 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.13.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.13.2 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-22740 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615 | org.springframework:spring-web | 6.2.12 | Incomplete Cleanup | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-04-04 | 9.1.3 | vulnerable_code_not_in_execute_path |
| high | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-02-28 | 9.1.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.12.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53668 | SNYK-JS-REACTROUTER-18313146 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.9.Final | CRLF Injection | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.9.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.9.Final | Incorrect Authorization | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.13.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.13.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.3 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.3.0 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.3.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.3.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.3.0 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.4 | CRLF Injection | 2026-06-12 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.9.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.6 | Open Redirect | 2026-06-10 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.6 | Information Exposure | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.9.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.12 | Exposed Dangerous Method or Function | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.12 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.12 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.12 | Cross-site Scripting (XSS) | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.13.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.13.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33245 | SNYK-JS-REACTROUTER-17137545 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.13.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-05 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.13.2 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.13.2 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.13.2 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.13.2 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.13.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-40542 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546 | org.apache.httpcomponents.client5:httpclient5 | 5.6 | Missing Critical Step in Authentication | 2026-04-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.6 | Information Exposure | 2026-04-22 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.6 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.6 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22745 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618 | org.springframework:spring-core | 6.2.12 | Allocation of Resources Without Limits or Throttling | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.3.0 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.13.2 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-65913 | SNYK-JS-DOMPURIFY-15874903 | dompurify | 3.3.0 | Prototype Pollution | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65912 | SNYK-JS-DOMPURIFY-15874905 | dompurify | 3.3.0 | Permissive List of Allowed Inputs | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65914 | SNYK-JS-DOMPURIFY-15810938 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-03-27 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.3.0 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.3.0 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.3.0 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-22732 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796 | org.springframework.security:spring-security-web | 6.5.6 | Use of Cache Containing Sensitive Information | 2026-03-20 | 9.1.3 | Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.1.8 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.9.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.6 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.9 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Output Neutralization for Logs | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.2 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.23 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-03-26 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.13.2 | Prototype Pollution | 2026-02-09 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.6 | Cross-site Scripting (XSS) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.23 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-03-03 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.1.6 | Upgrade to TopBraid EDG 9.1.6 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| low | CVE-2026-22735 | SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 | org.springframework:spring-web | 6.2.12 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2026-03-19 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Deserialization of Untrusted Data | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.9.Final | Incorrect Comparison | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.12 | Deserialization of Untrusted Data | 2026-06-08 | 9.1.8 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.12.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.13.2 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.13.2 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.13.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.12.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.9.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.9.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.6 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.6 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.12 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.12 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.15 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.13.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.12.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.13.2 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.13.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.13.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.9.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.9.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.9.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.7 | Unsafe Reflection | 2026-05-04 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.7 | XML External Entity (XXE) Injection | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.7 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.13.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.13.2 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-22740 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615 | org.springframework:spring-web | 6.2.12 | Incomplete Cleanup | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-04-04 | 9.1.3 | vulnerable_code_not_in_execute_path |
| high | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-02-28 | 9.1.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.12.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53668 | SNYK-JS-REACTROUTER-18313146 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.9.Final | CRLF Injection | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.9.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.9.Final | Incorrect Authorization | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.13.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.13.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.3 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.3.0 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.3.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.3.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.3.0 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.4 | CRLF Injection | 2026-06-12 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.9.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.6 | Open Redirect | 2026-06-10 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.6 | Information Exposure | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.9.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.12 | Exposed Dangerous Method or Function | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.12 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.12 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.12 | Cross-site Scripting (XSS) | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.13.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.13.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33245 | SNYK-JS-REACTROUTER-17137545 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.13.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-05 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.13.2 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.13.2 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.13.2 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.13.2 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.13.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-40542 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546 | org.apache.httpcomponents.client5:httpclient5 | 5.6 | Missing Critical Step in Authentication | 2026-04-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.6 | Information Exposure | 2026-04-22 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.6 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.6 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22745 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618 | org.springframework:spring-core | 6.2.12 | Allocation of Resources Without Limits or Throttling | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.3.0 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.13.2 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-65913 | SNYK-JS-DOMPURIFY-15874903 | dompurify | 3.3.0 | Prototype Pollution | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65912 | SNYK-JS-DOMPURIFY-15874905 | dompurify | 3.3.0 | Permissive List of Allowed Inputs | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65914 | SNYK-JS-DOMPURIFY-15810938 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-03-27 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.3.0 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.3.0 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.3.0 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-22732 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796 | org.springframework.security:spring-security-web | 6.5.6 | Use of Cache Containing Sensitive Information | 2026-03-20 | 9.1.3 | Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available. |
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 | 9.1.1 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.1.1 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 | 9.1.1 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.1.8 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.9.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.6 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.9 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8 or later. |
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Output Neutralization for Logs | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.13.2 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.23 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-03-26 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.13.2 | Prototype Pollution | 2026-02-09 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.6 | Cross-site Scripting (XSS) | 2026-06-10 | 9.1.7 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.3 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 | 9.1.5 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.23 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-03-03 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.1.6 | Upgrade to TopBraid EDG 9.1.6 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| low | CVE-2026-22735 | SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 | org.springframework:spring-web | 6.2.12 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2026-03-19 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-8763 | SNYK-JAVA-ORGBOUNCYCASTLE-18512779 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-59650 | SNYK-JAVA-ORGBOUNCYCASTLE-18512810 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Input Validation | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-58062 | SNYK-JAVA-ORGBOUNCYCASTLE-18519194 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Deserialization of Untrusted Data | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.9.Final | Incorrect Comparison | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.12 | Deserialization of Untrusted Data | 2026-06-08 | 9.1.8 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.12.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.13.2 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.13.2 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.13.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59645 | SNYK-JAVA-ORGBOUNCYCASTLE-18512330 | org.bouncycastle:bcutil-jdk18on | 1.81.1 | Uncontrolled Recursion | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12185 | SNYK-JAVA-ORGBOUNCYCASTLE-18512520 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59651 | SNYK-JAVA-ORGBOUNCYCASTLE-18512572 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inadequate Encryption Strength | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59641 | SNYK-JAVA-ORGBOUNCYCASTLE-18512864 | org.bouncycastle:bcjmail-jdk18on | 1.81 | Insufficient Verification of Data Authenticity | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59642 | SNYK-JAVA-ORGBOUNCYCASTLE-18512967 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59639 | SNYK-JAVA-ORGBOUNCYCASTLE-18513021 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12860 | SNYK-JAVA-ORGBOUNCYCASTLE-18518014 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58061 | SNYK-JAVA-ORGBOUNCYCASTLE-18519127 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12803 | SNYK-JAVA-ORGBOUNCYCASTLE-18519148 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12816 | SNYK-JAVA-ORGBOUNCYCASTLE-18519163 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58060 | SNYK-JAVA-ORGBOUNCYCASTLE-18519180 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12802 | SNYK-JAVA-ORGBOUNCYCASTLE-18519217 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.12.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53667 | SNYK-JS-REACTROUTER-18313128 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.9.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.9.Final | Infinite loop | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-68494 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.1 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.4 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.6 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.6 | User Impersonation | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.4 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.12 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.12 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.15 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.13.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.12.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.12.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.13.2 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.13.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.13.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.9.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.9.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.9.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.1.7 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.7 | Unsafe Reflection | 2026-05-04 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.7 | XML External Entity (XXE) Injection | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.7 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.13.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.13.2 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-22740 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615 | org.springframework:spring-web | 6.2.12 | Incomplete Cleanup | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-04-04 | 9.1.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-18401 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-02-28 | 9.1.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59647 | SNYK-JAVA-ORGBOUNCYCASTLE-18513013 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-15055 | SNYK-JAVA-ORGBOUNCYCASTLE-18517495 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518977 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518992 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-58063 | SNYK-JAVA-ORGBOUNCYCASTLE-18519071 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.1.1 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-REACTROUTER-18313151 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.12.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53668 | SNYK-JS-REACTROUTER-18313146 | react-router | 7.12.0 | Open Redirect | 2026-07-23 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.9.Final | CRLF Injection | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.9.Final | HTTP Request Smuggling | 2026-07-22 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.9.Final | Incorrect Authorization | 2026-07-21 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.13.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.13.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67318 | SNYK-JS-AXIOS-18060804 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.13.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.3 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.3.0 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.3.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.3.0 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.3.0 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-06-12 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.4 | CRLF Injection | 2026-06-12 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.9.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.6 | Open Redirect | 2026-06-10 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.6 | Information Exposure | 2026-06-09 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.9.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.9.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.12 | Exposed Dangerous Method or Function | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.12 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.12 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.1.8 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.12 | Cross-site Scripting (XSS) | 2026-06-08 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.13.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.13.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33245 | SNYK-JS-REACTROUTER-17137545 | react-router | 7.12.0 | Cross-site Scripting (XSS) | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.13.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-07 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.9.Final | HTTP Request Smuggling | 2026-05-05 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.13.2 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.13.2 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.13.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.13.2 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.13.2 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.13.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-40542 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546 | org.apache.httpcomponents.client5:httpclient5 | 5.6 | Missing Critical Step in Authentication | 2026-04-23 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.6 | Information Exposure | 2026-04-22 | 9.1.7 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.6 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.6 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.1.7 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22745 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618 | org.springframework:spring-core | 6.2.12 | Allocation of Resources Without Limits or Throttling | 2026-04-17 | 9.1.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.3.0 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.13.2 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-65913 | SNYK-JS-DOMPURIFY-15874903 | dompurify | 3.3.0 | Prototype Pollution | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65912 | SNYK-JS-DOMPURIFY-15874905 | dompurify | 3.3.0 | Permissive List of Allowed Inputs | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65914 | SNYK-JS-DOMPURIFY-15810938 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-03-27 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.3.0 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.3.0 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.3.0 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-53663 | SNYK-JS-REACTROUTER-17342510 | react-router | 7.12.0 | Cross-site Request Forgery (CSRF) | 2026-06-15 | 9.2.2 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.3.0 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2025-68470 | SNYK-JS-REACTROUTER-14908286 | react-router | 7.6.0 | Open Redirect | 2026-01-08 |
| high | CVE-2026-22029 | SNYK-JS-REACTROUTER-14908531 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 |
| high | CVE-2025-55163 | SNYK-JAVA-IOGRPC-13786834 | io.grpc:grpc-netty-shaded | 1.68.0 | Allocation of Resources Without Limits or Throttling | 2025-08-13 |
| medium | CVE-2025-59057 | SNYK-JS-REACTROUTER-14908289 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 |
| medium | CVE-2026-21884 | SNYK-JS-REACTROUTER-14908293 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 |
| medium | CVE-2026-22030 | SNYK-JS-REACTROUTER-14908429 | react-router | 7.6.0 | Cross-site Request Forgery (CSRF) | 2026-01-08 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.23 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.23 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.12.2 | Prototype Pollution | 2026-02-09 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| high | CVE-2025-68470 | SNYK-JS-REACTROUTER-14908286 | react-router | 7.6.0 | Open Redirect | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2026-22029 | SNYK-JS-REACTROUTER-14908531 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2025-55163 | SNYK-JAVA-IOGRPC-13786834 | io.grpc:grpc-netty-shaded | 1.68.0 | Allocation of Resources Without Limits or Throttling | 2025-08-13 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.23 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.23 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.2.7 | Cross-site Scripting (XSS) | 2026-03-03 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2025-59057 | SNYK-JS-REACTROUTER-14908289 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-21884 | SNYK-JS-REACTROUTER-14908293 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-22030 | SNYK-JS-REACTROUTER-14908429 | react-router | 7.6.0 | Cross-site Request Forgery (CSRF) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.6.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.12.2 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.6.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.6.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.16 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.6.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.12.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.12.2 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.2.7 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.6.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.2.7 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.2.7 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.2.7 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.2.7 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.2.7 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.2.7 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.2.7 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.1 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.12.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.12.2 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.12.2 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.2.7 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.2.7 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.12.2 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-65913 | SNYK-JS-DOMPURIFY-15874903 | dompurify | 3.2.7 | Prototype Pollution | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65912 | SNYK-JS-DOMPURIFY-15874905 | dompurify | 3.2.7 | Permissive List of Allowed Inputs | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65914 | SNYK-JS-DOMPURIFY-15810938 | dompurify | 3.2.7 | Cross-site Scripting (XSS) | 2026-03-27 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.2.7 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.2.7 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.2.7 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.2.7 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.9 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 |
| medium | CVE-2025-13465 | SNYK-JS-LODASH-15053838 | lodash | 4.17.21 | Prototype Pollution | 2026-01-21 |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.0.5 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.9 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.12.2 | Prototype Pollution | 2026-02-09 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| high | CVE-2025-68470 | SNYK-JS-REACTROUTER-14908286 | react-router | 7.6.0 | Open Redirect | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2026-22029 | SNYK-JS-REACTROUTER-14908531 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2025-55163 | SNYK-JAVA-IOGRPC-13786834 | io.grpc:grpc-netty-shaded | 1.68.0 | Allocation of Resources Without Limits or Throttling | 2025-08-13 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASH-15053838 | lodash | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-59057 | SNYK-JS-REACTROUTER-14908289 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-21884 | SNYK-JS-REACTROUTER-14908293 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-22030 | SNYK-JS-REACTROUTER-14908429 | react-router | 7.6.0 | Cross-site Request Forgery (CSRF) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-8763 | SNYK-JAVA-ORGBOUNCYCASTLE-18512779 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-59650 | SNYK-JAVA-ORGBOUNCYCASTLE-18512810 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Input Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-58062 | SNYK-JAVA-ORGBOUNCYCASTLE-18519194 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.18 | Deserialization of Untrusted Data | 2026-06-08 | 9.0.5 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.6.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.12.2 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59645 | SNYK-JAVA-ORGBOUNCYCASTLE-18512330 | org.bouncycastle:bcutil-jdk18on | 1.81.1 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12185 | SNYK-JAVA-ORGBOUNCYCASTLE-18512520 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59651 | SNYK-JAVA-ORGBOUNCYCASTLE-18512572 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inadequate Encryption Strength | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59641 | SNYK-JAVA-ORGBOUNCYCASTLE-18512864 | org.bouncycastle:bcjmail-jdk18on | 1.81 | Insufficient Verification of Data Authenticity | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59642 | SNYK-JAVA-ORGBOUNCYCASTLE-18512967 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59639 | SNYK-JAVA-ORGBOUNCYCASTLE-18513021 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12860 | SNYK-JAVA-ORGBOUNCYCASTLE-18518014 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58061 | SNYK-JAVA-ORGBOUNCYCASTLE-18519127 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12803 | SNYK-JAVA-ORGBOUNCYCASTLE-18519148 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12816 | SNYK-JAVA-ORGBOUNCYCASTLE-18519163 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58060 | SNYK-JAVA-ORGBOUNCYCASTLE-18519180 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12802 | SNYK-JAVA-ORGBOUNCYCASTLE-18519217 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.6.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.6.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.15.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.15.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59889 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972608 | com.fasterxml.jackson.core:jackson-databind | 2.22.0 | Incorrect Authorization | 2026-07-14 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.18 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.18 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.16 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.6.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.5 | Unsafe Reflection | 2026-05-04 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.5 | XML External Entity (XXE) Injection | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.5 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.12.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.12.2 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59647 | SNYK-JAVA-ORGBOUNCYCASTLE-18513013 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-15055 | SNYK-JAVA-ORGBOUNCYCASTLE-18517495 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518977 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518992 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-58063 | SNYK-JAVA-ORGBOUNCYCASTLE-18519071 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.6.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.15.Final | CRLF Injection | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.15.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.15.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.15.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.15.Final | Incorrect Authorization | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.22.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.2.6 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.2.6 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.4 | CRLF Injection | 2026-06-12 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.18 | Exposed Dangerous Method or Function | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.18 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.18 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.18 | Cross-site Scripting (XSS) | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.12.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.12.2 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.12.2 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.2.6 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.12.2 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-65913 | SNYK-JS-DOMPURIFY-15874903 | dompurify | 3.2.6 | Prototype Pollution | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65912 | SNYK-JS-DOMPURIFY-15874905 | dompurify | 3.2.6 | Permissive List of Allowed Inputs | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65914 | SNYK-JS-DOMPURIFY-15810938 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-27 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-15599 | SNYK-JS-DOMPURIFY-15371386 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.2.6 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.2.6 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.2.6 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.6.Final | Improper Verification of Cryptographic Signature | 2026-06-12 |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-03-26 |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Cross-site Scripting (XSS) | 2026-06-10 |
| medium | CVE-2025-67735 | SNYK-JAVA-IONETTY-14423947 | io.netty:netty-codec-http | 4.2.6.Final | CRLF Injection | 2025-12-15 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.0.5 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.6.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.9 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-03-26 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.12.2 | Prototype Pollution | 2026-02-09 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| high | CVE-2025-68470 | SNYK-JS-REACTROUTER-14908286 | react-router | 7.6.0 | Open Redirect | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2026-22029 | SNYK-JS-REACTROUTER-14908531 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2025-55163 | SNYK-JAVA-IOGRPC-13786834 | io.grpc:grpc-netty-shaded | 1.68.0 | Allocation of Resources Without Limits or Throttling | 2025-08-13 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Cross-site Scripting (XSS) | 2026-06-10 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASH-15053838 | lodash | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-59057 | SNYK-JS-REACTROUTER-14908289 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-21884 | SNYK-JS-REACTROUTER-14908293 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-22030 | SNYK-JS-REACTROUTER-14908429 | react-router | 7.6.0 | Cross-site Request Forgery (CSRF) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2025-67735 | SNYK-JAVA-IONETTY-14423947 | io.netty:netty-codec-http | 4.2.6.Final | CRLF Injection | 2025-12-15 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-8763 | SNYK-JAVA-ORGBOUNCYCASTLE-18512779 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-59650 | SNYK-JAVA-ORGBOUNCYCASTLE-18512810 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Input Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-58062 | SNYK-JAVA-ORGBOUNCYCASTLE-18519194 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Deserialization of Untrusted Data | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.6.Final | Incorrect Comparison | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.18 | Deserialization of Untrusted Data | 2026-06-08 | 9.0.5 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.6.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.12.2 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59645 | SNYK-JAVA-ORGBOUNCYCASTLE-18512330 | org.bouncycastle:bcutil-jdk18on | 1.81.1 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12185 | SNYK-JAVA-ORGBOUNCYCASTLE-18512520 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59651 | SNYK-JAVA-ORGBOUNCYCASTLE-18512572 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inadequate Encryption Strength | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59641 | SNYK-JAVA-ORGBOUNCYCASTLE-18512864 | org.bouncycastle:bcjmail-jdk18on | 1.81 | Insufficient Verification of Data Authenticity | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59642 | SNYK-JAVA-ORGBOUNCYCASTLE-18512967 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59639 | SNYK-JAVA-ORGBOUNCYCASTLE-18513021 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12860 | SNYK-JAVA-ORGBOUNCYCASTLE-18518014 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58061 | SNYK-JAVA-ORGBOUNCYCASTLE-18519127 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12803 | SNYK-JAVA-ORGBOUNCYCASTLE-18519148 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12816 | SNYK-JAVA-ORGBOUNCYCASTLE-18519163 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58060 | SNYK-JAVA-ORGBOUNCYCASTLE-18519180 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12802 | SNYK-JAVA-ORGBOUNCYCASTLE-18519217 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.6.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.6.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.6.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.6.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-68494 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.9 | User Impersonation | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.9 | User Impersonation | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.18 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.18 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.16 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.6.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.6.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.6.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.5 | Unsafe Reflection | 2026-05-04 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.5 | XML External Entity (XXE) Injection | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.5 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.12.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.12.2 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-04-04 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-18401 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-02-28 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59647 | SNYK-JAVA-ORGBOUNCYCASTLE-18513013 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-15055 | SNYK-JAVA-ORGBOUNCYCASTLE-18517495 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518977 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518992 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-58063 | SNYK-JAVA-ORGBOUNCYCASTLE-18519071 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.6.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.6.Final | CRLF Injection | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.6.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.6.Final | Incorrect Authorization | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.4 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.2.6 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.2.6 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-06-12 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.4 | CRLF Injection | 2026-06-12 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.6.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.0.4 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.9 | Open Redirect | 2026-06-10 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.9 | Information Exposure | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.18 | Exposed Dangerous Method or Function | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.18 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.18 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.18 | Cross-site Scripting (XSS) | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.12.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-05 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.12.2 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.12.2 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.9 | Information Exposure | 2026-04-22 | 9.0.4 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.9 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.9 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.2.6 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.12.2 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-65913 | SNYK-JS-DOMPURIFY-15874903 | dompurify | 3.2.6 | Prototype Pollution | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65912 | SNYK-JS-DOMPURIFY-15874905 | dompurify | 3.2.6 | Permissive List of Allowed Inputs | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65914 | SNYK-JS-DOMPURIFY-15810938 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-27 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-15599 | SNYK-JS-DOMPURIFY-15371386 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.2.6 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.2.6 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.2.6 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| critical | CVE-2026-22732 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796 | org.springframework.security:spring-security-web | 6.5.5 | Use of Cache Containing Sensitive Information | 2026-03-20 |
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Output Neutralization for Logs | 2026-04-10 |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Encoding or Escaping of Output | 2026-04-10 |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Encoding or Escaping of Output | 2026-04-10 |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 |
| medium | CVE-2025-68161 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Validation of Certificate with Host Mismatch | 2025-12-18 |
| low | CVE-2026-22735 | SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 | org.springframework:spring-web | 6.2.11 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2026-03-19 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-22732 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796 | org.springframework.security:spring-security-web | 6.5.5 | Use of Cache Containing Sensitive Information | 2026-03-20 | 9.0.3 | Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available. |
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.0.5 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.6.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.5 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.9 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Output Neutralization for Logs | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-03-26 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.12.2 | Prototype Pollution | 2026-02-09 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| high | CVE-2025-68470 | SNYK-JS-REACTROUTER-14908286 | react-router | 7.6.0 | Open Redirect | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2026-22029 | SNYK-JS-REACTROUTER-14908531 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2025-55163 | SNYK-JAVA-IOGRPC-13786834 | io.grpc:grpc-netty-shaded | 1.68.0 | Allocation of Resources Without Limits or Throttling | 2025-08-13 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.5 | Cross-site Scripting (XSS) | 2026-06-10 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASH-15053838 | lodash | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-59057 | SNYK-JS-REACTROUTER-14908289 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-21884 | SNYK-JS-REACTROUTER-14908293 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-22030 | SNYK-JS-REACTROUTER-14908429 | react-router | 7.6.0 | Cross-site Request Forgery (CSRF) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2025-68161 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Validation of Certificate with Host Mismatch | 2025-12-18 | 9.0.3 | Upgrade to TopBraid EDG 9.0.3 or later. |
| medium | CVE-2025-67735 | SNYK-JAVA-IONETTY-14423947 | io.netty:netty-codec-http | 4.2.6.Final | CRLF Injection | 2025-12-15 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| low | CVE-2026-22735 | SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 | org.springframework:spring-web | 6.2.11 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2026-03-19 | 9.0.3 | Upgrade to TopBraid EDG 9.0.3 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-8763 | SNYK-JAVA-ORGBOUNCYCASTLE-18512779 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-59650 | SNYK-JAVA-ORGBOUNCYCASTLE-18512810 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Input Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-58062 | SNYK-JAVA-ORGBOUNCYCASTLE-18519194 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Deserialization of Untrusted Data | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.6.Final | Incorrect Comparison | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.11 | Deserialization of Untrusted Data | 2026-06-08 | 9.0.5 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.6.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.12.2 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59645 | SNYK-JAVA-ORGBOUNCYCASTLE-18512330 | org.bouncycastle:bcutil-jdk18on | 1.81.1 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12185 | SNYK-JAVA-ORGBOUNCYCASTLE-18512520 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59651 | SNYK-JAVA-ORGBOUNCYCASTLE-18512572 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inadequate Encryption Strength | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59641 | SNYK-JAVA-ORGBOUNCYCASTLE-18512864 | org.bouncycastle:bcjmail-jdk18on | 1.81 | Insufficient Verification of Data Authenticity | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59642 | SNYK-JAVA-ORGBOUNCYCASTLE-18512967 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59639 | SNYK-JAVA-ORGBOUNCYCASTLE-18513021 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12860 | SNYK-JAVA-ORGBOUNCYCASTLE-18518014 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58061 | SNYK-JAVA-ORGBOUNCYCASTLE-18519127 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12803 | SNYK-JAVA-ORGBOUNCYCASTLE-18519148 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12816 | SNYK-JAVA-ORGBOUNCYCASTLE-18519163 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58060 | SNYK-JAVA-ORGBOUNCYCASTLE-18519180 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12802 | SNYK-JAVA-ORGBOUNCYCASTLE-18519217 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.6.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.6.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.6.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.6.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-68494 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.5 | User Impersonation | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.5 | User Impersonation | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.11 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.11 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.14 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.6.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.6.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.6.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.5 | Unsafe Reflection | 2026-05-04 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.5 | XML External Entity (XXE) Injection | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.5 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.12.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.12.2 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-22740 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615 | org.springframework:spring-web | 6.2.11 | Incomplete Cleanup | 2026-04-17 | 9.0.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-04-04 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-18401 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-02-28 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59647 | SNYK-JAVA-ORGBOUNCYCASTLE-18513013 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-15055 | SNYK-JAVA-ORGBOUNCYCASTLE-18517495 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518977 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518992 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-58063 | SNYK-JAVA-ORGBOUNCYCASTLE-18519071 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.6.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.6.Final | CRLF Injection | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.6.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.6.Final | Incorrect Authorization | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.2 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.2.6 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.2.6 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-06-12 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.4 | CRLF Injection | 2026-06-12 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.6.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.0.4 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.5 | Open Redirect | 2026-06-10 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.5 | Information Exposure | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.11 | Exposed Dangerous Method or Function | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.11 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.11 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.11 | Cross-site Scripting (XSS) | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.12.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-05 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.12.2 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.12.2 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.5 | Information Exposure | 2026-04-22 | 9.0.4 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.5 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.5 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22745 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618 | org.springframework:spring-core | 6.2.11 | Allocation of Resources Without Limits or Throttling | 2026-04-17 | 9.0.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.2.6 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.12.2 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-65913 | SNYK-JS-DOMPURIFY-15874903 | dompurify | 3.2.6 | Prototype Pollution | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65912 | SNYK-JS-DOMPURIFY-15874905 | dompurify | 3.2.6 | Permissive List of Allowed Inputs | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65914 | SNYK-JS-DOMPURIFY-15810938 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-27 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-15599 | SNYK-JS-DOMPURIFY-15371386 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.2.6 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.2.6 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.2.6 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
Previous release was affected, but this one is not.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed |
|---|---|---|---|---|---|---|
| high | CVE-2026-47691 | SNYK-JAVA-IONETTY-17261020 | io.netty:netty-resolver-dns | 4.2.6.Final | Insufficient Verification of Data Authenticity | 2026-06-08 |
| high | CVE-2026-45674 | SNYK-JAVA-IONETTY-17262734 | io.netty:netty-resolver-dns | 4.2.6.Final | Insufficient Verification of Data Authenticity | 2026-06-08 |
| high | CVE-2026-42579 | SNYK-JAVA-IONETTY-16438938 | io.netty:netty-codec-dns | 4.2.6.Final | Null Byte Interaction Error (Poison Null Byte) | 2026-05-07 |
| medium | CVE-2026-45673 | SNYK-JAVA-IONETTY-17261131 | io.netty:netty-resolver-dns | 4.2.6.Final | Generation of Predictable Numbers or Identifiers | 2026-06-08 |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-22732 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796 | org.springframework.security:spring-security-web | 6.5.5 | Use of Cache Containing Sensitive Information | 2026-03-20 | 9.0.3 | Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available. |
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.0.5 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.6.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.5 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-47691 | SNYK-JAVA-IONETTY-17261020 | io.netty:netty-resolver-dns | 4.2.6.Final | Insufficient Verification of Data Authenticity | 2026-06-08 | 9.0.2 | Upgrade to TopBraid EDG 9.0.2 or later. |
| high | CVE-2026-45674 | SNYK-JAVA-IONETTY-17262734 | io.netty:netty-resolver-dns | 4.2.6.Final | Insufficient Verification of Data Authenticity | 2026-06-08 | 9.0.2 | Upgrade to TopBraid EDG 9.0.2 or later. |
| high | CVE-2026-42579 | SNYK-JAVA-IONETTY-16438938 | io.netty:netty-codec-dns | 4.2.6.Final | Null Byte Interaction Error (Poison Null Byte) | 2026-05-07 | 9.0.2 | Upgrade to TopBraid EDG 9.0.2 or later. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.9 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Output Neutralization for Logs | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-03-26 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.12.2 | Prototype Pollution | 2026-02-09 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| high | CVE-2025-68470 | SNYK-JS-REACTROUTER-14908286 | react-router | 7.6.0 | Open Redirect | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2026-22029 | SNYK-JS-REACTROUTER-14908531 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2025-55163 | SNYK-JAVA-IOGRPC-13786834 | io.grpc:grpc-netty-shaded | 1.68.0 | Allocation of Resources Without Limits or Throttling | 2025-08-13 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.5 | Cross-site Scripting (XSS) | 2026-06-10 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-45673 | SNYK-JAVA-IONETTY-17261131 | io.netty:netty-resolver-dns | 4.2.6.Final | Generation of Predictable Numbers or Identifiers | 2026-06-08 | 9.0.2 | Upgrade to TopBraid EDG 9.0.2 or later. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASH-15053838 | lodash | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-59057 | SNYK-JS-REACTROUTER-14908289 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-21884 | SNYK-JS-REACTROUTER-14908293 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-22030 | SNYK-JS-REACTROUTER-14908429 | react-router | 7.6.0 | Cross-site Request Forgery (CSRF) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2025-68161 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Validation of Certificate with Host Mismatch | 2025-12-18 | 9.0.3 | Upgrade to TopBraid EDG 9.0.3 or later. |
| medium | CVE-2025-67735 | SNYK-JAVA-IONETTY-14423947 | io.netty:netty-codec-http | 4.2.6.Final | CRLF Injection | 2025-12-15 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| low | CVE-2026-22735 | SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 | org.springframework:spring-web | 6.2.11 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2026-03-19 | 9.0.3 | Upgrade to TopBraid EDG 9.0.3 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-8763 | SNYK-JAVA-ORGBOUNCYCASTLE-18512779 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-59650 | SNYK-JAVA-ORGBOUNCYCASTLE-18512810 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Input Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-58062 | SNYK-JAVA-ORGBOUNCYCASTLE-18519194 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Deserialization of Untrusted Data | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.6.Final | Incorrect Comparison | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.11 | Deserialization of Untrusted Data | 2026-06-08 | 9.0.5 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.6.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.12.2 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59645 | SNYK-JAVA-ORGBOUNCYCASTLE-18512330 | org.bouncycastle:bcutil-jdk18on | 1.81.1 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12185 | SNYK-JAVA-ORGBOUNCYCASTLE-18512520 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59651 | SNYK-JAVA-ORGBOUNCYCASTLE-18512572 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inadequate Encryption Strength | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59641 | SNYK-JAVA-ORGBOUNCYCASTLE-18512864 | org.bouncycastle:bcjmail-jdk18on | 1.81 | Insufficient Verification of Data Authenticity | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59642 | SNYK-JAVA-ORGBOUNCYCASTLE-18512967 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59639 | SNYK-JAVA-ORGBOUNCYCASTLE-18513021 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12860 | SNYK-JAVA-ORGBOUNCYCASTLE-18518014 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58061 | SNYK-JAVA-ORGBOUNCYCASTLE-18519127 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12803 | SNYK-JAVA-ORGBOUNCYCASTLE-18519148 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12816 | SNYK-JAVA-ORGBOUNCYCASTLE-18519163 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58060 | SNYK-JAVA-ORGBOUNCYCASTLE-18519180 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12802 | SNYK-JAVA-ORGBOUNCYCASTLE-18519217 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.6.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.6.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.6.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.6.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-68494 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.5 | User Impersonation | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.5 | User Impersonation | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.11 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.11 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.14 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.6.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.6.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.6.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.5 | Unsafe Reflection | 2026-05-04 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.5 | XML External Entity (XXE) Injection | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.5 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.12.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.12.2 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-22740 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615 | org.springframework:spring-web | 6.2.11 | Incomplete Cleanup | 2026-04-17 | 9.0.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-04-04 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-18401 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-02-28 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59647 | SNYK-JAVA-ORGBOUNCYCASTLE-18513013 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-15055 | SNYK-JAVA-ORGBOUNCYCASTLE-18517495 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518977 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518992 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-58063 | SNYK-JAVA-ORGBOUNCYCASTLE-18519071 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JAVA-IONETTY-18313049 | io.netty:netty-codec-dns | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-07-24 | 9.0.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.6.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.6.Final | CRLF Injection | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.6.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.6.Final | Incorrect Authorization | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.2 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.2.6 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.2.6 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-06-12 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.4 | CRLF Injection | 2026-06-12 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.6.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.0.4 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.5 | Open Redirect | 2026-06-10 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.5 | Information Exposure | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41715 | SNYK-JAVA-IOPROJECTREACTORNETTY-17260961 | io.projectreactor.netty:reactor-netty-http | 1.2.9 | Cleartext Transmission of Sensitive Information | 2026-06-08 | 9.0.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.11 | Exposed Dangerous Method or Function | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.11 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.11 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.11 | Cross-site Scripting (XSS) | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.12.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42578 | SNYK-JAVA-IONETTY-16438935 | io.netty:netty-handler-proxy | 4.2.6.Final | CRLF Injection | 2026-05-07 | 9.0.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-05 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.12.2 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.12.2 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.5 | Information Exposure | 2026-04-22 | 9.0.4 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.5 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.5 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22745 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618 | org.springframework:spring-core | 6.2.11 | Allocation of Resources Without Limits or Throttling | 2026-04-17 | 9.0.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.2.6 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.12.2 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-65913 | SNYK-JS-DOMPURIFY-15874903 | dompurify | 3.2.6 | Prototype Pollution | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65912 | SNYK-JS-DOMPURIFY-15874905 | dompurify | 3.2.6 | Permissive List of Allowed Inputs | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65914 | SNYK-JS-DOMPURIFY-15810938 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-27 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-15599 | SNYK-JS-DOMPURIFY-15371386 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.2.6 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.2.6 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.2.6 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |
The product is exposed and action should be taken.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Action statement |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-22732 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796 | org.springframework.security:spring-security-web | 6.5.5 | Use of Cache Containing Sensitive Information | 2026-03-20 | 9.0.3 | Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available. |
| high | CVE-2026-58059 | SNYK-JAVA-ORGBOUNCYCASTLE-18518039 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inefficient Algorithmic Complexity | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-14682 | SNYK-JAVA-ORGBOUNCYCASTLE-18518087 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-13506 | SNYK-JAVA-ORGBOUNCYCASTLE-18519010 | org.bouncycastle:bcprov-jdk18on | 1.81 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | Upgrade to TopBraid EDG 8.5.5, 9.0.5, 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-45112 | SNYK-JAVA-ORGAPACHETHRIFT-18389002 | org.apache.thrift:libthrift | 0.22.0 | Allocation of Resources Without Limits or Throttling | 2026-07-27 | 9.1.8 | Impact is negligible in TopBraid EDG and accepting the risk is reasonable; otherwise upgrade to TopBraid EDG 9.1.8, 9.2.3, 9.3.0, or later, when available. |
| high | CVE-2026-59887 | SNYK-JS-LINKIFYIT-17901217 | linkify-it | 5.0.0 | Inefficient Algorithmic Complexity | 2026-07-08 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-54399 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817218 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | Upgrade to TopBraid EDG 9.1.8, 9.2.3, or later, when available. |
| high | CVE-2026-48801 | SNYK-JS-LINKIFYIT-17817062 | linkify-it | 5.0.0 | Regular Expression Denial of Service (ReDoS) | 2026-06-26 | 9.0.5 | Upgrade to TopBraid EDG 9.3.0 or later, when available. |
| high | CVE-2026-50010 | SNYK-JAVA-IONETTY-17334567 | io.netty:netty-handler | 4.2.6.Final | Improper Verification of Cryptographic Signature | 2026-06-12 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-40988 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633 | org.springframework.security:spring-security-saml2-service-provider | 6.5.5 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-06-10 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| high | CVE-2026-47691 | SNYK-JAVA-IONETTY-17261020 | io.netty:netty-resolver-dns | 4.2.6.Final | Insufficient Verification of Data Authenticity | 2026-06-08 | 9.0.2 | Upgrade to TopBraid EDG 9.0.2 or later. |
| high | CVE-2026-45674 | SNYK-JAVA-IONETTY-17262734 | io.netty:netty-resolver-dns | 4.2.6.Final | Insufficient Verification of Data Authenticity | 2026-06-08 | 9.0.2 | Upgrade to TopBraid EDG 9.0.2 or later. |
| high | CVE-2026-42579 | SNYK-JAVA-IONETTY-16438938 | io.netty:netty-codec-dns | 4.2.6.Final | Null Byte Interaction Error (Poison Null Byte) | 2026-05-07 | 9.0.2 | Upgrade to TopBraid EDG 9.0.2 or later. |
| high | CVE-2026-40895 | SNYK-JS-FOLLOWREDIRECTS-16032162 | follow-redirects | 1.15.9 | Improper Removal of Sensitive Information Before Storage or Transfer | 2026-04-14 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| high | CVE-2026-34478 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Output Neutralization for Logs | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34480 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-34479 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Encoding or Escaping of Output | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| high | CVE-2026-40175 | SNYK-JS-AXIOS-15969258 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-10 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASH-15869625 | lodash | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-4800 | SNYK-JS-LODASHES-15869627 | lodash-es | 4.17.21 | Arbitrary Code Injection | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| high | CVE-2026-33870 | SNYK-JAVA-IONETTY-15789756 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-03-26 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| high | CVE-2026-33871 | SNYK-JAVA-IONETTY-15789758 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-03-26 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| high | CVE-2026-25639 | SNYK-JS-AXIOS-15252993 | axios | 1.12.2 | Prototype Pollution | 2026-02-09 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| high | CVE-2025-68470 | SNYK-JS-REACTROUTER-14908286 | react-router | 7.6.0 | Open Redirect | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2026-22029 | SNYK-JS-REACTROUTER-14908531 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| high | CVE-2025-55163 | SNYK-JAVA-IOGRPC-13786834 | io.grpc:grpc-netty-shaded | 1.68.0 | Allocation of Resources Without Limits or Throttling | 2025-08-13 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-41003 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632 | org.springframework.security:spring-security-saml2-service-provider | 6.5.5 | Cross-site Scripting (XSS) | 2026-06-10 | 9.0.4 | Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available. |
| medium | CVE-2026-45673 | SNYK-JAVA-IONETTY-17261131 | io.netty:netty-resolver-dns | 4.2.6.Final | Generation of Predictable Numbers or Identifiers | 2026-06-08 | 9.0.2 | Upgrade to TopBraid EDG 9.0.2 or later. |
| medium | CVE-2026-47761 | SNYK-JS-TINYMCE-17056137 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47762 | SNYK-JS-TINYMCE-17056141 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-47759 | SNYK-JS-TINYMCE-17056166 | tinymce | 7.5.1 | Cross-site Scripting (XSS) | 2026-05-28 | 9.2.2 | Upgrade to TopBraid EDG 9.2.2 or later. |
| medium | CVE-2026-34477 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Validation of Certificate with Host Mismatch | 2026-04-10 | 9.0.3 | The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026. |
| medium | CVE-2026-2950 | SNYK-JS-LODASH-15869619 | lodash | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-2950 | SNYK-JS-LODASHES-15869621 | lodash-es | 4.17.21 | Prototype Pollution | 2026-03-31 | 9.1.4 | Upgrade to TopBraid EDG 9.1.4 or later. |
| medium | CVE-2026-0540 | SNYK-JS-DOMPURIFY-15371376 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.1.3 | Upgrade to TopBraid EDG 9.1.3 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASH-15053838 | lodash | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-13465 | SNYK-JS-LODASHES-15053836 | lodash-es | 4.17.21 | Prototype Pollution | 2026-01-21 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-59057 | SNYK-JS-REACTROUTER-14908289 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-21884 | SNYK-JS-REACTROUTER-14908293 | react-router | 7.6.0 | Cross-site Scripting (XSS) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2026-22030 | SNYK-JS-REACTROUTER-14908429 | react-router | 7.6.0 | Cross-site Request Forgery (CSRF) | 2026-01-08 | 9.1.0 | Upgrade to TopBraid EDG 9.1.0 or later. |
| medium | CVE-2025-68161 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782 | org.apache.logging.log4j:log4j-core | 2.25.2 | Improper Validation of Certificate with Host Mismatch | 2025-12-18 | 9.0.3 | Upgrade to TopBraid EDG 9.0.3 or later. |
| medium | CVE-2025-67735 | SNYK-JAVA-IONETTY-14423947 | io.netty:netty-codec-http | 4.2.6.Final | CRLF Injection | 2025-12-15 | 9.0.4 | Upgrade to TopBraid EDG 9.0.4 or later. |
| medium | CVE-2026-2327 | SNYK-JS-MARKDOWNIT-10666750 | markdown-it | 14.1.0 | Regular Expression Denial of Service (ReDoS) | 2025-07-05 | 9.0.5 | Upgrade to TopBraid EDG 9.0.5 or later. |
| medium | CVE-2025-6493 | SNYK-JS-CODEMIRROR-10494092 | codemirror | 5.65.18 | Regular Expression Denial of Service (ReDoS) | 2025-06-22 | 9.2.0 | Upgrade to TopBraid EDG 9.2.0 or later. |
| low | CVE-2026-22735 | SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 | org.springframework:spring-web | 6.2.11 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 2026-03-19 | 9.0.3 | Upgrade to TopBraid EDG 9.0.3 or later. |
Component present in the product, but not exploitable.
| Severity | CVE | Snyk ID | Module | Version | Title | Disclosed | Fixed in | Justification |
|---|---|---|---|---|---|---|---|---|
| critical | CVE-2026-8763 | SNYK-JAVA-ORGBOUNCYCASTLE-18512779 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-59650 | SNYK-JAVA-ORGBOUNCYCASTLE-18512810 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Input Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-58062 | SNYK-JAVA-ORGBOUNCYCASTLE-18519194 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Certificate Validation | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54513 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Incomplete List of Disallowed Inputs | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-54512 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Deserialization of Untrusted Data | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-44249 | SNYK-JAVA-IONETTY-17254120 | io.netty:netty-handler | 4.2.6.Final | Incorrect Comparison | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-41855 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326609 | org.springframework:spring-web | 6.2.11 | Deserialization of Untrusted Data | 2026-06-08 | 9.0.5 | vulnerable_code_not_present |
| critical | CVE-2026-42211 | SNYK-JS-REACTROUTER-17137394 | react-router | 7.6.0 | Deserialization of Untrusted Data | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| critical | CVE-2026-42264 | SNYK-JS-AXIOS-16417750 | axios | 1.12.2 | Prototype Pollution | 2026-05-05 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42035 | SNYK-JS-AXIOS-16298058 | axios | 1.12.2 | HTTP Response Splitting | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-42033 | SNYK-JS-AXIOS-16299904 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| critical | CVE-2026-5588 | SNYK-JAVA-ORGBOUNCYCASTLE-16075260 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| critical | (none) | SNYK-JS-JQUERYFORM-574783 | jquery-form | 3.50.0 | Cross-site Scripting (XSS) | 2015-04-10 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59645 | SNYK-JAVA-ORGBOUNCYCASTLE-18512330 | org.bouncycastle:bcutil-jdk18on | 1.81.1 | Uncontrolled Recursion | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12185 | SNYK-JAVA-ORGBOUNCYCASTLE-18512520 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59651 | SNYK-JAVA-ORGBOUNCYCASTLE-18512572 | org.bouncycastle:bcprov-jdk18on | 1.81 | Inadequate Encryption Strength | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59641 | SNYK-JAVA-ORGBOUNCYCASTLE-18512864 | org.bouncycastle:bcjmail-jdk18on | 1.81 | Insufficient Verification of Data Authenticity | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59642 | SNYK-JAVA-ORGBOUNCYCASTLE-18512967 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59639 | SNYK-JAVA-ORGBOUNCYCASTLE-18513021 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12860 | SNYK-JAVA-ORGBOUNCYCASTLE-18518014 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Verification of Cryptographic Signature | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58061 | SNYK-JAVA-ORGBOUNCYCASTLE-18519127 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12803 | SNYK-JAVA-ORGBOUNCYCASTLE-18519148 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12816 | SNYK-JAVA-ORGBOUNCYCASTLE-18519163 | org.bouncycastle:bcprov-jdk18on | 1.81 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-58060 | SNYK-JAVA-ORGBOUNCYCASTLE-18519180 | org.bouncycastle:bcprov-jdk18on | 1.81 | Memory Allocation with Excessive Size Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-12802 | SNYK-JAVA-ORGBOUNCYCASTLE-18519217 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Improper Validation of Integrity Check Value | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-48586 | SNYK-JAVA-ORGAPACHETHRIFT-18389256 | org.apache.thrift:libthrift | 0.22.0 | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-07-27 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55685 | SNYK-JS-REACTROUTER-18313148 | react-router | 7.6.0 | Inefficient Algorithmic Complexity | 2026-07-24 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-53669 | SNYK-JS-REACTROUTER-18313144 | react-router | 7.6.0 | Open Redirect | 2026-07-23 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230935 | io.netty:netty-codec | 4.2.6.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-59901 | SNYK-JAVA-IONETTY-18230936 | io.netty:netty-codec-compression | 4.2.6.Final | Infinite loop | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55831 | SNYK-JAVA-IONETTY-18233079 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-68494 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-18517159 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-55833 | SNYK-JAVA-IONETTY-18170202 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56819 | SNYK-JAVA-IONETTY-18170204 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-56745 | SNYK-JAVA-IONETTY-18170213 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-54428 | SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-17817217 | org.apache.httpcomponents.core5:httpcore5-h2 | 5.3.6 | Allocation of Resources Without Limits or Throttling | 2026-07-01 | 9.1.8 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40983 | SNYK-JAVA-IOMICROMETER-17339194 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-09 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998 | org.springframework.security:spring-security-web | 6.5.5 | User Impersonation | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-47838 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999 | org.springframework.security:spring-security-config | 6.5.5 | User Impersonation | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40984 | SNYK-JAVA-IOMICROMETER-17260885 | io.micrometer:micrometer-core | 1.15.1 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-45416 | SNYK-JAVA-IONETTY-17254117 | io.netty:netty-handler | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41850 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311 | org.springframework:spring-expression | 6.2.11 | Inefficient Algorithmic Complexity | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41851 | SNYK-JAVA-ORGSPRINGFRAMEWORK-18326606 | org.springframework:spring-expression | 6.2.11 | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-41720 | SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845 | org.springframework.ldap:spring-ldap-core | 3.2.14 | Incorrect Implementation of Authentication Algorithm | 2026-06-08 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44486 | SNYK-JS-AXIOS-17172681 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42342 | SNYK-JS-REACTROUTER-17138701 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.2 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-34077 | SNYK-JS-REACTROUTER-17138883 | react-router | 7.6.0 | Allocation of Resources Without Limits or Throttling | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40181 | SNYK-JS-REACTROUTER-17138887 | react-router | 7.6.0 | Open Redirect | 2026-06-02 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44495 | SNYK-JS-AXIOS-17111060 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-44492 | SNYK-JS-AXIOS-17111062 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-44494 | SNYK-JS-AXIOS-17111079 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-45292 | SNYK-JAVA-IOOPENTELEMETRY-17280222 | io.opentelemetry:opentelemetry-api | 1.42.1 | Allocation of Resources Without Limits or Throttling | 2026-05-28 | vulnerable_code_not_in_execute_path | |
| high | CVE-2026-42583 | SNYK-JAVA-IONETTY-16438323 | io.netty:netty-codec-compression | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42585 | SNYK-JAVA-IONETTY-16438737 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42584 | SNYK-JAVA-IONETTY-16438923 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438929 | io.netty:netty-codec-http2 | 4.2.6.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42587 | SNYK-JAVA-IONETTY-16438931 | io.netty:netty-codec-compression | 4.2.6.Final | Improper Handling of Highly Compressed Data (Data Amplification) | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42581 | SNYK-JAVA-IONETTY-16438934 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42577 | SNYK-JAVA-IONETTY-16438936 | io.netty:netty-transport-classes-epoll | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-05-06 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-42027 | SNYK-JAVA-ORGAPACHEOPENNLP-16419373 | org.apache.opennlp:opennlp-tools | 2.5.5 | Unsafe Reflection | 2026-05-04 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-40682 | SNYK-JAVA-ORGAPACHEOPENNLP-16419377 | org.apache.opennlp:opennlp-tools | 2.5.5 | XML External Entity (XXE) Injection | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42440 | SNYK-JAVA-ORGAPACHEOPENNLP-16535521 | org.apache.opennlp:opennlp-tools | 2.5.5 | Memory Allocation with Excessive Size Value | 2026-05-04 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42044 | SNYK-JS-AXIOS-16299921 | axios | 1.12.2 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| high | CVE-2026-42039 | SNYK-JS-AXIOS-16299923 | axios | 1.12.2 | Uncontrolled Recursion | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-22740 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615 | org.springframework:spring-web | 6.2.11 | Incomplete Cleanup | 2026-04-17 | 9.0.3 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-5598 | SNYK-JAVA-ORGBOUNCYCASTLE-16074612 | org.bouncycastle:bcprov-jdk18on | 1.81 | Timing Attack | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-14813 | SNYK-JAVA-ORGBOUNCYCASTLE-16075266 | org.bouncycastle:bcprov-jdk18on | 1.81 | Use of a Broken or Risky Cryptographic Algorithm | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| high | (none) | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-04-04 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2026-18401 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 | com.fasterxml.jackson.core:jackson-core | 2.20.0 | Allocation of Resources Without Limits or Throttling | 2026-02-28 | 9.0.4 | vulnerable_code_not_in_execute_path |
| high | CVE-2025-68280 | SNYK-JAVA-ORGAPACHESISCORE-14874786 | org.apache.sis.core:sis-metadata | 1.4 | XML External Entity (XXE) Injection | 2026-01-05 | vulnerable_code_not_in_execute_path | |
| high | CVE-2021-23370 | SNYK-JS-SWIPER-1088062 | swiper | 3.4.1 | Prototype Pollution | 2021-03-22 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59647 | SNYK-JAVA-ORGBOUNCYCASTLE-18513013 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-15055 | SNYK-JAVA-ORGBOUNCYCASTLE-18517495 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518977 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-13586 | SNYK-JAVA-ORGBOUNCYCASTLE-18518992 | org.bouncycastle:bcpkix-jdk18on | 1.81.1 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-58063 | SNYK-JAVA-ORGBOUNCYCASTLE-18519071 | org.bouncycastle:bcprov-jdk18on | 1.81 | Allocation of Resources Without Limits or Throttling | 2026-08-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JAVA-IONETTY-18313049 | io.netty:netty-codec-dns | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-07-24 | 9.0.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65911 | SNYK-JS-DOMPURIFY-18307175 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-07-23 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-53666 | SNYK-JS-REACTROUTER-18313130 | react-router | 7.6.0 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 2026-07-23 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59921 | SNYK-JAVA-IONETTY-18231070 | io.netty:netty-codec-http | 4.2.6.Final | CRLF Injection | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59899 | SNYK-JAVA-IONETTY-18233081 | io.netty:netty-codec-http | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59898 | SNYK-JAVA-IONETTY-18233107 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59900 | SNYK-JAVA-IONETTY-18233111 | io.netty:netty-codec-http2 | 4.2.6.Final | HTTP Request Smuggling | 2026-07-22 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-56746 | SNYK-JAVA-IONETTY-18170206 | io.netty:netty-codec-http | 4.2.6.Final | Incorrect Authorization | 2026-07-21 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67312 | SNYK-JS-AXIOS-18060165 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67313 | SNYK-JS-AXIOS-18060167 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67314 | SNYK-JS-AXIOS-18060659 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67321 | SNYK-JS-AXIOS-18060730 | axios | 1.12.2 | Uncontrolled Recursion | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67319 | SNYK-JS-AXIOS-18065349 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-67320 | SNYK-JS-AXIOS-18065351 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67317 | SNYK-JS-AXIOS-18065353 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-67316 | SNYK-JS-AXIOS-18065355 | axios | 1.12.2 | Prototype Pollution | 2026-07-20 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-59888 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17972437 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-07-14 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49844 | SNYK-JAVA-ORGAPACHELOGGINGLOG4J-17954276 | org.apache.logging.log4j:log4j-api | 2.25.2 | Improper Encoding or Escaping of Output | 2026-07-10 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54514 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Server-side Request Forgery (SSRF) | 2026-06-23 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-54515 | SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695 | com.fasterxml.jackson.core:jackson-databind | 2.20.0 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | 2026-06-23 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65898 | SNYK-JS-DOMPURIFY-17375136 | dompurify | 3.2.6 | Improper Initialization | 2026-06-18 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65901 | SNYK-JS-DOMPURIFY-17342528 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49978 | SNYK-JS-DOMPURIFY-17344504 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65902 | SNYK-JS-DOMPURIFY-17344516 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49458 | SNYK-JS-DOMPURIFY-17344526 | dompurify | 3.2.6 | Trust Boundary Violation | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-49459 | SNYK-JS-DOMPURIFY-17344538 | dompurify | 3.2.6 | Prototype Pollution | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65900 | SNYK-JS-DOMPURIFY-17344549 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48988 | SNYK-JS-MARKDOWNIT-17353909 | markdown-it | 14.1.0 | Inefficient Algorithmic Complexity | 2026-06-15 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50560 | SNYK-JAVA-IONETTY-17337010 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-12 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-50020 | SNYK-JAVA-IONETTY-17337012 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-06-12 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-12143 | SNYK-JS-FORMDATA-17337015 | form-data | 4.0.4 | CRLF Injection | 2026-06-12 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-48043 | SNYK-JAVA-IONETTY-17311220 | io.netty:netty-codec-http2 | 4.2.6.Final | Missing Release of Memory after Effective Lifetime | 2026-06-11 | 9.0.4 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41706 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598 | org.springframework.security:spring-security-web | 6.5.5 | Open Redirect | 2026-06-10 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41694 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750 | org.springframework.security:spring-security-saml2-service-provider | 6.5.5 | Information Exposure | 2026-06-09 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-47244 | SNYK-JAVA-IONETTY-17254661 | io.netty:netty-codec-http2 | 4.2.6.Final | Allocation of Resources Without Limits or Throttling | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-45536 | SNYK-JAVA-IONETTY-17260879 | io.netty:netty-transport-native-unix-common | 4.2.6.Final | Missing Release of Resource after Effective Lifetime | 2026-06-08 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41715 | SNYK-JAVA-IOPROJECTREACTORNETTY-17260961 | io.projectreactor.netty:reactor-netty-http | 1.2.9 | Cleartext Transmission of Sensitive Information | 2026-06-08 | 9.0.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41852 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570 | org.springframework:spring-expression | 6.2.11 | Exposed Dangerous Method or Function | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41848 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051 | org.springframework:spring-core | 6.2.11 | Regular Expression Denial of Service (ReDoS) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41854 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521 | org.springframework:spring-web | 6.2.11 | Server-side Request Forgery (SSRF) | 2026-06-08 | 9.0.5 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-41845 | SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245 | org.springframework:spring-web | 6.2.11 | Cross-site Scripting (XSS) | 2026-06-08 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44496 | SNYK-JS-AXIOS-17172532 | axios | 1.12.2 | Regular Expression Denial of Service (ReDoS) | 2026-06-04 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-44488 | SNYK-JS-AXIOS-17172751 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44487 | SNYK-JS-AXIOS-17172930 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-06-04 | 9.3.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-44490 | SNYK-JS-AXIOS-17111081 | axios | 1.12.2 | Prototype Pollution | 2026-05-29 | 9.3.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42580 | SNYK-JAVA-IONETTY-16438926 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-07 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42578 | SNYK-JAVA-IONETTY-16438935 | io.netty:netty-handler-proxy | 4.2.6.Final | CRLF Injection | 2026-05-07 | 9.0.2 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41417 | SNYK-JAVA-IONETTY-16425695 | io.netty:netty-codec-http | 4.2.6.Final | HTTP Request Smuggling | 2026-05-05 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-43869 | SNYK-JAVA-ORGAPACHETHRIFT-16432027 | org.apache.thrift:libthrift | 0.22.0 | Improper Validation of Certificate with Host Mismatch | 2026-05-05 | 9.1.8 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42040 | SNYK-JS-AXIOS-16298055 | axios | 1.12.2 | Improper Encoding or Escaping of Output | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42038 | SNYK-JS-AXIOS-16298095 | axios | 1.12.2 | Server-side Request Forgery (SSRF) | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42034 | SNYK-JS-AXIOS-16298130 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42036 | SNYK-JS-AXIOS-16298162 | axios | 1.12.2 | Allocation of Resources Without Limits or Throttling | 2026-04-24 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-42042 | SNYK-JS-AXIOS-16299478 | axios | 1.12.2 | Insertion of Sensitive Information Into Sent Data | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42037 | SNYK-JS-AXIOS-16299819 | axios | 1.12.2 | CRLF Injection | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-42041 | SNYK-JS-AXIOS-16299925 | axios | 1.12.2 | Prototype Pollution | 2026-04-24 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22746 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176 | org.springframework.security:spring-security-core | 6.5.5 | Information Exposure | 2026-04-22 | 9.0.4 | vulnerable_code_cannot_be_controlled_by_adversary |
| medium | CVE-2026-22748 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448 | org.springframework.security:spring-security-oauth2-jose | 6.5.5 | Insufficient Verification of Data Authenticity | 2026-04-22 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22751 | SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313 | org.springframework.security:spring-security-core | 6.5.5 | Time-of-check Time-of-use (TOCTOU) Race Condition | 2026-04-21 | 9.0.4 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41238 | SNYK-JS-DOMPURIFY-16132234 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-22745 | SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618 | org.springframework:spring-core | 6.2.11 | Allocation of Resources Without Limits or Throttling | 2026-04-17 | 9.0.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-41240 | SNYK-JS-DOMPURIFY-16078387 | dompurify | 3.2.6 | Operator Precedence Logic Error | 2026-04-16 | 9.2.0 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-0636 | SNYK-JAVA-ORGBOUNCYCASTLE-16075254 | org.bouncycastle:bcprov-jdk18on | 1.81 | LDAP Injection | 2026-04-15 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-62718 | SNYK-JS-AXIOS-15965856 | axios | 1.12.2 | Unintended Proxy or Intermediary ('Confused Deputy') | 2026-04-09 | 9.2.0 | component_not_present |
| medium | CVE-2026-65913 | SNYK-JS-DOMPURIFY-15874903 | dompurify | 3.2.6 | Prototype Pollution | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65912 | SNYK-JS-DOMPURIFY-15874905 | dompurify | 3.2.6 | Permissive List of Allowed Inputs | 2026-04-03 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-65914 | SNYK-JS-DOMPURIFY-15810938 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-27 | 9.1.3 | vulnerable_code_not_in_execute_path |
| medium | CVE-2026-33532 | SNYK-JS-YAML-15765520 | yaml | 1.10.2 | Uncontrolled Recursion | 2026-03-25 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | CVE-2025-15599 | SNYK-JS-DOMPURIFY-15371386 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-03-03 | 9.0.5 | vulnerable_code_not_in_execute_path |
| medium | (none) | SNYK-JS-D3COLOR-1076592 | d3-color | 1.4.1 | Regular Expression Denial of Service (ReDoS) | 2021-02-18 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65904 | SNYK-JS-DOMPURIFY-18307177 | dompurify | 3.2.6 | Improper Check for Unusual or Exceptional Conditions | 2026-07-23 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-66010 | SNYK-JS-DOMPURIFY-18170233 | dompurify | 3.2.6 | Incomplete List of Disallowed Inputs | 2026-07-21 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-65899 | SNYK-JS-DOMPURIFY-17344552 | dompurify | 3.2.6 | Protection Mechanism Failure | 2026-06-15 | 9.2.3 | vulnerable_code_not_in_execute_path |
| low | CVE-2026-41239 | SNYK-JS-DOMPURIFY-16131135 | dompurify | 3.2.6 | Cross-site Scripting (XSS) | 2026-04-19 | 9.2.0 | vulnerable_code_not_in_execute_path |
| low | CVE-2018-25050 | SNYK-JS-CHOSENJS-3184933 | chosen-js | 1.6.2 | Cross-site Scripting (XSS) | 2022-12-29 | 9.2.0 | vulnerable_code_cannot_be_controlled_by_adversary |
| low | CVE-2020-29582 | SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 | org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | Information Exposure | 2022-02-03 | vulnerable_code_not_in_execute_path |