Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
CRITICAL 9.8 CVE-2026-42779 The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's Abstrac… Mina 2.1.12 / 2.2.7+ Fix from $2,3002026-05-01 HIGH 8.8 CVE-2026-27172 The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserializ… Camel 4.14.6 / 4.18.1+ Fix from $1,9502026-04-27 CRITICAL 9.8 CVE-2026-41409 The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 HIGH 8.8 CVE-2026-40858 The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.… Camel 4.14.7 / 4.18.2+ Fix from $1,9502026-04-27 CRITICAL 9.4 CVE-2026-33454 The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt… Camel 4.14.6 / 4.18.1+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-40860 JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa… Camel 4.14.7 / 4.18.2+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-41635 Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 HIGH 8.8 CVE-2026-40473 The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any… Camel 4.14.6 / 4.18.2+ Fix from $1,9502026-04-27 HIGH 7.8 CVE-2026-40048 The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.Objec… Camel 4.18.2+ Fix from $1,9502026-04-27 MEDIUM 6.3 CVE-2025-62233 Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.… Dolphinscheduler 3.3.1+ Fix from $1,6002026-04-24 HIGH 7.2 CVE-2026-25917 Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit… Airflow 3.2.0+ Fix from $1,9502026-04-18 HIGH 8.8 CVE-2026-33858 Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit… Airflow 3.2.0+ Fix from $1,9502026-04-13 HIGH 8.8 CVE-2026-35337 Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credential… Storm 2.8.6+ Fix from $1,9502026-04-13 HIGH 8.8 CVE-2025-54920EPSS 5% This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.… Spark 3.5.7+ Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-25747 Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes dat… Camel 4.10.9 / 4.14.5+ Fix from $1,9502026-02-23 HIGH 8.8 CVE-2025-66524 Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Ser… Nifi 2.7.0+ Fix from $1,9502025-12-19 HIGH 8.8 CVE-2025-26866 A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix en… Hugegraph 1.7.0+ Fix from $1,9502025-12-12 MEDIUM 6.3 CVE-2025-64408EPSS 11% Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vul… Causeway 3.5.0+ Fix from $1,6002025-11-19 CRITICAL 9.8 CVE-2025-54539 A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ … Activemq Nms Amqp 2.4.0+ Fix from $2,3002025-10-16 CRITICAL 9.8 CVE-2025-61622EPSS 41% Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows… Fory after 0.12.2 Fix from $2,3002025-10-01 MEDIUM 5.3 CVE-2025-48459 Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to… Iotdb 2.0.5+ Fix from $1,6002025-09-24 MEDIUM 6.5 CVE-2025-59328 A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untr… Fory 0.12.2+ Fix from $1,6002025-09-15 MEDIUM 6.5 CVE-2025-58782 Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Co… Jackrabbit 2.22.2+ Fix from $1,6002025-09-08 CRITICAL 9.8 CVE-2025-53606 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomm… Seata Mitigation only Fix from $2,3002025-08-08 CRITICAL 9.8 CVE-2025-32897 Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the ver… Seata 2.3.0+ Fix from $2,3002025-06-28 HIGH 8.8 CVE-2025-27818 A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connec… Kafka 3.9.1+ Fix from $1,9502025-06-10 HIGH 7.5 CVE-2025-27819 In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka… Kafka after 3.3.2 Fix from $1,9502025-06-10 CRITICAL 9.8 CVE-2025-27531 Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would al… Inlong 2.1.0+ Fix from $2,3002025-06-06 CRITICAL 9.1 CVE-2025-27528 Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability … Inlong 2.2.0+ Fix from $2,3002025-05-28 MEDIUM 6.5 CVE-2025-27522 Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is… Inlong 2.2.0+ Fix from $1,6002025-05-28