Maven
5,667 CVEs tracked since 2000. Since Jul 2021, 19 of them reached CISA KEV.
Maven CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-07 | 28 | 0 |
| 2021-08 | 51 | 1 |
| 2021-09 | 26 | 0 |
| 2021-10 | 27 | 0 |
| 2021-11 | 46 | 0 |
| 2021-12 | 31 | 2 |
| 2022-01 | 75 | 0 |
| 2022-02 | 89 | 0 |
| 2022-03 | 88 | 1 |
| 2022-04 | 58 | 3 |
| 2022-05 | 77 | 0 |
| 2022-06 | 112 | 0 |
| 2022-07 | 75 | 1 |
| 2022-08 | 64 | 1 |
| 2022-09 | 108 | 0 |
| 2022-10 | 73 | 0 |
| 2022-11 | 93 | 0 |
| 2022-12 | 56 | 0 |
| 2023-01 | 78 | 0 |
| 2023-02 | 48 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 94 | 0 |
| 2023-05 | 99 | 2 |
| 2023-06 | 86 | 0 |
| 2023-07 | 86 | 0 |
| 2023-08 | 58 | 0 |
| 2023-09 | 59 | 0 |
| 2023-10 | 81 | 2 |
| 2023-11 | 65 | 0 |
| 2023-12 | 117 | 0 |
| 2024-01 | 62 | 1 |
| 2024-02 | 89 | 0 |
| 2024-03 | 67 | 0 |
| 2024-04 | 50 | 1 |
| 2024-05 | 29 | 0 |
| 2024-06 | 31 | 0 |
| 2024-07 | 48 | 1 |
| 2024-08 | 27 | 0 |
| 2024-09 | 38 | 0 |
| 2024-10 | 44 | 0 |
| 2024-11 | 48 | 0 |
| 2024-12 | 39 | 0 |
| 2025-01 | 43 | 0 |
| 2025-02 | 27 | 1 |
| 2025-03 | 64 | 1 |
| 2025-04 | 56 | 0 |
| 2025-05 | 35 | 0 |
| 2025-06 | 58 | 0 |
| 2025-07 | 69 | 0 |
| 2025-08 | 81 | 0 |
| 2025-09 | 90 | 0 |
| 2025-10 | 103 | 0 |
| 2025-11 | 30 | 1 |
| 2025-12 | 48 | 0 |
| 2026-01 | 53 | 0 |
| 2026-02 | 39 | 0 |
| 2026-03 | 23 | 0 |
| 2026-04 | 9 | 0 |
| 2026-05 | 7 | 0 |
| 2026-06 | 12 | 0 |
| 2026-07 | 19 | 0 |
Products
The products that kept showing up in Maven's monthly top three, with their CVEs summed over those months.
- Com.liferay.portal:release.portal.bom117
- Com.liferay.portal:release.dxp.bom96
- Org.keycloak:keycloak-services42
- Org.jenkins-ci.main:jenkins-core36
- Com.jfinal:jfinal31
- Com.thoughtworks.xstream:xstream14
- Org.xwiki.platform:xwiki-platform-oldcore13
- Org.geoserver.web:gs-web-app11
- Com.liferay.portal:com.liferay.portal.impl10
- Org.apache.inlong:manager-pojo10
Latest CVEs
The 15 most recently published vulnerabilities affecting Maven.
- GHSA-fp43-vj7g-pg92OmniFaces: Forged combined-resource IDs and related output/push boundaries—
- GHSA-7ppr-r889-mcf2blaze: Unbounded WebSocket message aggregation in http4s-blaze-server—
- GHSA-46q4-43ph-c6frblaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)—
- GHSA-mhvj-jhpq-885vblaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser—
- GHSA-p279-2cqp-84jgOpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check—
- GHSA-68r5-9hpg-7qw9OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway—
- GHSA-v74w-7mr3-4qg3Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion—
- GHSA-mfg7-5gfp-c4w3Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names—
- GHSA-464c-974j-9xm6AWS CDK CodeBuild S3 Log Encryption Boolean Inversion—
- GHSA-r7wm-3cxj-wff9jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)—
- GHSA-mhm7-754m-9p8wjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`—
- GHSA-x8mg-6r4p-87pfArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization—
- GHSA-vwjc-v7x7-cm6gArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js—
- GHSA-x9f9-r4m8-9xc2ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)—
- GHSA-48qw-824m-86prArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read—
The record
- Peak rank
- #3 in Dec 2023
- Busiest month shown
- Dec 2023, 117 CVEs
- Months with a KEV entry
- 14 since Jul 2021
- Monthly snapshots
- 213 since 2000