Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-67587
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the store…
Airflow
No fix yet
HIGH 7.3
CVE-2026-67260
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deseria…
Airflow
No fix yet
MEDIUM 5.4
CVE-2026-59242
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_v…
Airflow
3.3.1+
HIGH 8.8
CVE-2026-58076
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and in…
Airflow
3.3.1+
CRITICAL 9.8
CVE-2026-71558
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte…
Fory
1.5.0+
CRITICAL 9.1
CVE-2026-71560
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser…
Fory
1.5.0+
HIGH 7.5
CVE-2026-71559
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying …
Fory
1.5.0+
CRITICAL 9.8
CVE-2026-66909
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.8
CVE-2026-61484
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As th…
Lucy
No fix yet
CRITICAL 9.1
CVE-2026-58163
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: …
Traffic Server
9.2.15 / 10.1.4+
CRITICAL 9.8
CVE-2026-66713
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component
in Apache Software Foundation Apache Axis2/Java through 2.0.0…
Axis2\/java
2.0.1+
CRITICAL 9.8
CVE-2026-64606
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lamb…
Fory
1.4.0+
CRITICAL 9.8
CVE-2026-64608
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa…
Fory
1.4.0+
CRITICAL 9.8
CVE-2026-33264
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …
Airflow
3.3.0+
HIGH 7.3
CVE-2026-43825EPSS 9%
Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel
Versions Affected:
before 3.0.0-M4 (libsvm document categorization module; introdu…
Opennlp
Mitigation only
HIGH 8.8
CVE-2026-46590
Deserialization of Untrusted Data vulnerability in Apache Camel PQC component.
The camel-pqc component persists post-quantum key metadata (KeyMetada…
Camel
4.18.3 / 4.21.0+
CRITICAL 9.8
CVE-2026-43867
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.
The camel-pqc component persists post-quantum key metadata (KeyMetada…
Camel
4.18.3 / 4.21.0+
HIGH 8.1
CVE-2026-42527
Deserialization of Untrusted Data vulnerability in Apache Camel.
The default ObjectInputFilter pattern shipped with several Apache Camel components …
Camel
4.14.8 / 4.18.3+
HIGH 8.1
CVE-2026-43865
Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component.
The camel-hazelcast component creates and manages Hazelcast ins…
Camel
4.14.8 / 4.18.3+
HIGH 8.1
CVE-2026-40859
Deserialization of Untrusted Data vulnerability in Apache Camel.
The camel-vertx-http component deserializes HTTP response bodies carrying the Conte…
Camel
4.14.8 / 4.18.3+
HIGH 7.3
CVE-2026-43866
Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component.
JmsBinding.extractBodyFromJms() in camel-jms - and the …
Camel
4.14.8 / 4.18.3+
HIGH 8.1
CVE-2026-50632
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi…
Cxf
4.1.7 / 4.2.2+
HIGH 8.1
CVE-2026-50633
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able…
Cxf
4.1.7 / 4.2.2+
CRITICAL 9.1
CVE-2026-50076
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remo…
Fory
1.1.0+
CRITICAL 9.8
CVE-2026-47065
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the seri…
Mina
Mitigation only
HIGH 7.3
CVE-2026-45360
Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary clas…
Airflow
3.2.2+
HIGH 8.8
CVE-2026-42359
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a …
Airflow
3.2.2+
CRITICAL 9.8
CVE-2026-48207
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur…
Fory
1.0.0+
CRITICAL 9.8
CVE-2026-42027
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader
Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M…
Opennlp
2.5.9+
CRITICAL 9.8
CVE-2026-42778
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
The fix for CVE-2024-52046 i…
Mina
2.1.12 / 2.2.7+