Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-57303
Jenkins Assembla Plugin has an XXE vulnerability
CVE-2026-57301
Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE
CVE-2026-57296
Jenkins External Workspace Manager Plugin has a path traversal vulnerability
CVE-2026-57281
Jenkins Script Security Plugin has a script security bypass vulnerability
CVE-2026-57280
Jenkins Script Security Plugin sandbox bypass vulnerability
CVE-2026-41862
Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist
GHSA-vjr9-f93j-mjr7
Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2025-14813
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
CVE-2026-54148
http4k: `DigestAuthProvider.verify` did not bind to request URI
CVE-2026-61814
Jawn: Quadratic parsing effort in AsyncParser
CVE-2026-59990
Jawn: Uncontrolled nesting depth in JSON parser
CVE-2026-77422
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping
CVE-2026-61570
MPXJ: XXE Vulnerability in MerlinReader
CVE-2026-85058
io.moquette:moquette-broker has a Missing Authorization issue
CVE-2026-13506
Bouncy Castle: Lazy ASN.1 sequence forcing resets nesting-depth guard
CVE-2026-48059
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
CVE-2026-48006
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
CVE-2026-45674
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
CVE-2026-47691
Netty has Insufficient Bailiwick Validation for NS Records
CVE-2026-77615
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
CVE-2026-81876
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
CVE-2026-81875
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
CVE-2026-73247
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
CVE-2026-85721
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
CVE-2026-63126
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
CVE-2026-65831
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
CVE-2026-88975
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
CVE-2026-69213
Http4s Ember HTTP/2 has an unbounded outbound frame queue
CVE-2026-69218
Http4s Ember HTTP/2: unbounded continuation frame accumulation
CVE-2026-69203
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
CVE-2026-69205
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
CVE-2026-69208
Http4s: DigestAuth nonce map grows unbounded
CVE-2026-69202
Http4s Ember HTTP/2: unbounded inbound body buffering
CVE-2026-44913
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
CVE-2026-40983
Micrometer gRPC server instrumentation DoS
CVE-2026-40984
Micrometer HTTP server instrumentations DoS
CVE-2026-54513
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
CVE-2026-34487
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
CVE-2026-34483
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
CVE-2026-41284
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
CVE-2026-24880
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
CVE-2026-43513
Apache Tomcat: LockOutRealm treats user names as case-sensitive
CVE-2026-55175
Spinnaker: Improper yaml processing on kustomize bake operations
CVE-2026-55153
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
CVE-2026-59902
Netty: Memory Exhaustion in SctpMessageCompletionHandler
CVE-2026-55839
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
CVE-2026-56822
Netty: TOCTOU in OcspServerCertificateValidator
CVE-2026-44891
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVE-2026-73507
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
CVE-2026-54428
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
CVE-2026-50559
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
CVE-2026-56816
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
CVE-2026-56819
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
CVE-2026-41695
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
CVE-2026-40859
Apache Camel-Vertx-Http and Camel-Netty-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
CVE-2026-55831
Netty SPDY SETTINGS frame count materializes unbounded settings map
GHSA-387m-935m-c4vw
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
CVE-2026-56820
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
CVE-2026-41720
Spring LDAP has Authentication Bypass with Empty Password
CVE-2026-44795
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types
Ready to move
Start Securing
Free, no credit card | First findings in minutes