Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
Apache cxf-core: No restriction on attachment headers per message High
CVE-2026-50645 was published for org.apache.cxf:cxf-core (Maven) Jun 12, 2026
julianladisch Credited to julianladisch, coheigea, and udengaardandersent-ELS coheigea coheigea
udengaardandersent-ELS udengaardandersent-ELS
Uncontrolled Resource Consumption in Jackson-databind High
CVE-2022-42003 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Oct 3, 2022
AdamKorcz Credited to AdamKorcz, coheigea, sonnyhcl, Christiaan-de-Wet, and sunSUNQ coheigea coheigea
sonnyhcl sonnyhcl Christiaan-de-Wet Christiaan-de-Wet sunSUNQ sunSUNQ
Jettison parser crash by stackoverflow Moderate
CVE-2022-40149 was published for org.codehaus.jettison:jettison (Maven) Sep 17, 2022
coheigea Credited to coheigea
Improper Authentication in Apache WSS4J Moderate
CVE-2014-3623 was published for org.apache.ws.security:wss4j (Maven) May 13, 2022
coheigea Credited to coheigea
ProTip! Advisories are also available from the GraphQL API