Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Mina CRITICAL 9.8
CVE-2026-42779

The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's Abstrac…

Fix: 2.1.12 / 2.2.7+
Fix from $2,300 2026-05-01
Camel HIGH 8.8
CVE-2026-27172

The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserializ…

Fix: 4.14.6 / 4.18.1+
Fix from $1,950 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41409

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Camel HIGH 8.8
CVE-2026-40858

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.…

Fix: 4.14.7 / 4.18.2+
Fix from $1,950 2026-04-27
Camel CRITICAL 9.4
CVE-2026-33454

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt…

Fix: 4.14.6 / 4.18.1+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.8
CVE-2026-40860

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa…

Fix: 4.14.7 / 4.18.2+
Fix from $2,300 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41635

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Camel HIGH 8.8
CVE-2026-40473

The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any…

Fix: 4.14.6 / 4.18.2+
Fix from $1,950 2026-04-27
Camel HIGH 7.8
CVE-2026-40048

The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.Objec…

Fix: 4.18.2+
Fix from $1,950 2026-04-27
Dolphinscheduler MEDIUM 6.3
CVE-2025-62233

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.…

Fix: 3.3.1+
Fix from $1,600 2026-04-24
Airflow HIGH 7.2
CVE-2026-25917

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit…

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Airflow HIGH 8.8
CVE-2026-33858

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit…

Fix: 3.2.0+
Fix from $1,950 2026-04-13
Storm HIGH 8.8
CVE-2026-35337

Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credential…

Fix: 2.8.6+
Fix from $1,950 2026-04-13
Spark HIGH 8.8
CVE-2025-54920EPSS 5%

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.…

Fix: 3.5.7+
Fix from $1,950 2026-03-16
Camel HIGH 8.8
CVE-2026-25747

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes dat…

Fix: 4.10.9 / 4.14.5+
Fix from $1,950 2026-02-23
Nifi HIGH 8.8
CVE-2025-66524

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Ser…

Fix: 2.7.0+
Fix from $1,950 2025-12-19
Hugegraph HIGH 8.8
CVE-2025-26866

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix en…

Fix: 1.7.0+
Fix from $1,950 2025-12-12
Causeway MEDIUM 6.3
CVE-2025-64408EPSS 11%

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vul…

Fix: 3.5.0+
Fix from $1,600 2025-11-19
Activemq Nms Amqp CRITICAL 9.8
CVE-2025-54539

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ …

Fix: 2.4.0+
Fix from $2,300 2025-10-16
Fory CRITICAL 9.8
CVE-2025-61622EPSS 41%

Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows…

Fix: after 0.12.2
Fix from $2,300 2025-10-01
Iotdb MEDIUM 5.3
CVE-2025-48459

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to…

Fix: 2.0.5+
Fix from $1,600 2025-09-24
Fory MEDIUM 6.5
CVE-2025-59328

A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untr…

Fix: 0.12.2+
Fix from $1,600 2025-09-15
Jackrabbit MEDIUM 6.5
CVE-2025-58782

Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Co…

Fix: 2.22.2+
Fix from $1,600 2025-09-08
Seata CRITICAL 9.8
CVE-2025-53606

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm…

Mitigation only
Fix from $2,300 2025-08-08
Seata CRITICAL 9.8
CVE-2025-32897

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the ver…

Fix: 2.3.0+
Fix from $2,300 2025-06-28
Kafka HIGH 8.8
CVE-2025-27818

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connec…

Fix: 3.9.1+
Fix from $1,950 2025-06-10
Kafka HIGH 7.5
CVE-2025-27819

In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka…

Fix: after 3.3.2
Fix from $1,950 2025-06-10
Inlong CRITICAL 9.8
CVE-2025-27531

Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would al…

Fix: 2.1.0+
Fix from $2,300 2025-06-06
Inlong CRITICAL 9.1
CVE-2025-27528

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability …

Fix: 2.2.0+
Fix from $2,300 2025-05-28
Inlong MEDIUM 6.5
CVE-2025-27522

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is…

Fix: 2.2.0+
Fix from $1,600 2025-05-28