Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-42779
The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
Apache MINA's Abstrac…
Mina
2.1.12 / 2.2.7+
HIGH 8.8
CVE-2026-27172
The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserializ…
Camel
4.14.6 / 4.18.1+
CRITICAL 9.8
CVE-2026-41409
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized …
Mina
2.0.28 / 2.1.11+
HIGH 8.8
CVE-2026-40858
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.…
Camel
4.14.7 / 4.18.2+
CRITICAL 9.4
CVE-2026-33454
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt…
Camel
4.14.6 / 4.18.1+
CRITICAL 9.8
CVE-2026-40860
JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa…
Camel
4.14.7 / 4.18.2+
CRITICAL 9.8
CVE-2026-41635
Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at …
Mina
2.0.28 / 2.1.11+
HIGH 8.8
CVE-2026-40473
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any…
Camel
4.14.6 / 4.18.2+
HIGH 7.8
CVE-2026-40048
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.Objec…
Camel
4.18.2+
MEDIUM 6.3
CVE-2025-62233
Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module.
This issue affects Apache DolphinScheduler:
Version >= 3.2.…
Dolphinscheduler
3.3.1+
HIGH 7.2
CVE-2026-25917
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit…
Airflow
3.2.0+
HIGH 8.8
CVE-2026-33858
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit…
Airflow
3.2.0+
HIGH 8.8
CVE-2026-35337
Deserialization of Untrusted Data vulnerability in Apache Storm.
Versions Affected:
before 2.8.6.
Description:
When processing topology credential…
Storm
2.8.6+
HIGH 8.8
CVE-2025-54920EPSS 5%
This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.…
Spark
3.5.7+
HIGH 8.8
CVE-2026-25747
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component.
The Camel-LevelDB DefaultLevelDBSerializer class deserializes dat…
Camel
4.10.9 / 4.14.5+
HIGH 8.8
CVE-2025-66524
Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Ser…
Nifi
2.7.0+
HIGH 8.8
CVE-2025-26866
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix en…
Hugegraph
1.7.0+
MEDIUM 6.3
CVE-2025-64408EPSS 11%
Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vul…
Causeway
3.5.0+
CRITICAL 9.8
CVE-2025-54539
A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client.
This issue affects all versions of Apache ActiveMQ …
Activemq Nms Amqp
2.4.0+
CRITICAL 9.8
CVE-2025-61622EPSS 41%
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows…
Fory
after 0.12.2
MEDIUM 5.3
CVE-2025-48459
Deserialization of Untrusted Data vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 2.0.5.
Users are recommended to…
Iotdb
2.0.5+
MEDIUM 6.5
CVE-2025-59328
A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untr…
Fory
0.12.2+
MEDIUM 6.5
CVE-2025-58782
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons.
This issue affects Apache Jackrabbit Co…
Jackrabbit
2.22.2+
CRITICAL 9.8
CVE-2025-53606
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This issue affects Apache Seata (incubating): 2.4.0.
Users are recomm…
Seata
Mitigation only
CRITICAL 9.8
CVE-2025-32897
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This security vulnerability is the same as CVE-2024-47552, but the ver…
Seata
2.3.0+
HIGH 8.8
CVE-2025-27818
A possible security vulnerability has been identified in Apache Kafka.
This requires access to a alterConfig to the cluster resource, or Kafka Connec…
Kafka
3.9.1+
HIGH 7.5
CVE-2025-27819
In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka…
Kafka
after 3.3.2
CRITICAL 9.8
CVE-2025-27531
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 before 2.1.0,
this issue would al…
Inlong
2.1.0+
CRITICAL 9.1
CVE-2025-27528
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability …
Inlong
2.2.0+
MEDIUM 6.5
CVE-2025-27522
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is…
Inlong
2.2.0+