CVE Tools

Eclipse Glassfish

14 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Eclipse Glassfish, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Eclipse Glassfish CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Eclipse Glassfish CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-076
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-052
2026-060
2026-071
2026-081
2026-090

Severity

How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical643%
  • Medium857%

Latest CVEs

The 14 most recently published vulnerabilities affecting Eclipse Glassfish.

  1. CVE-2026-12605In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Adm...9.6
  2. CVE-2026-12606Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling. Grizzly 5.0.1 suppo...5.3
  3. CVE-2026-2586An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution o...9.1
  4. CVE-2026-2587A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and ev...9.6
  5. CVE-2026-24457An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthor...9.1
  6. CVE-2024-9408In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.9.8
  7. CVE-2024-10032In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.5.4
  8. CVE-2024-10031In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system.5.4
  9. CVE-2024-10029In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.6.1
  10. CVE-2024-9343In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.6.1
  11. CVE-2024-9342In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attac...9.8
  12. CVE-2024-8646Eclipse Glassfish: URL redirection vulnerability to untrusted sites6.1
  13. CVE-2023-5763Glassfish remote code execution6.8
  14. CVE-2022-2712In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an ...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store