| Vulnerability Upgrades |
| CVE-2021-23926 |
(Apache XMLBeans): An XXE flaw in XMLBeans before 3.0.0. The XML parsers weren't configured to block external entities or entity expansion, so crafted XML could read local files, trigger SSRF, or cause a denial of service. Upgrading to 3.0.0 or later fixes it. |
✅ Resolved |
| CVE-2022-34169 |
(Apache Xalan-J): An integer truncation bug in the XSLTC compiler in Xalan-J 2.7.2 and earlier. A malicious XSLT stylesheet can produce corrupted Java class files, which can lead to arbitrary code execution. This mainly matters if you process untrusted stylesheets. It's fixed in Xalan-J 2.7.3, and the JDK's bundled internal copy of XSLTC was patched separately in the July 2022 Java updates. |
✅ Resolved |
| CVE-2013-4002 |
(Apache Xerces2-J): A denial-of-service bug in Xerces-J's XMLScanner, affecting 2.11.0 and earlier. Malformed XML with crafted attribute name/value sequences can make parsing consume excessive CPU. It's fixed in Xerces 2.12.0. Older JDKs that bundled the same code were also affected. |
✅ Resolved |
| CVE-2025-14813 |
(Bouncy Castle bcprov): The GOST CTR implementation (G3413CTRBlockCipher) can't process more than 255 blocks correctly. In practice, GOST 28147 CTR mode reuses keystream after 255 blocks, which undermines confidentiality. It affects BC-JAVA from 1.59 before 1.80.2, from 1.81 before 1.81.1, and from 1.82 before 1.84. Scanners rate it critical, but it only matters if your code actually uses GOST in CTR mode. |
✅ Resolved |
| CVE-2026-50645 |
(Apache CXF): CXF doesn't limit how many attachment headers a message can contain during deserialization, which allows uncontrolled resource consumption or denial of service. The fix added a default maximum of 500 attachments per message in CXF 4.1.7 and 4.2.2. That fix turned out to be incomplete. The follow-up, CVE-2026-64958, notes the DoS is still possible, and recommends upgrading to 4.2.3, 4.1.8, or 3.6.12. So target those versions rather than the original fix releases. IBM WebSphere and Liberty are also affected via their bundled CXF. |
✅ Resolved |
| CVE-2026-54512 |
(jackson-databind): A bypass of Jackson's PolymorphicTypeValidator allow-list, done by embedding denied classes as generic type parameters of permitted container types. For example, the attacker smuggles a gadget class inside an allowed ArrayList<...>. If a class with exploitable side effects is on the classpath, this can lead to unauthenticated remote code execution. Applications that accept untrusted JSON and rely on a configured PTV are the ones affected. It's rated high, CVSS 8.1. Affected versions run from 2.10.0 through 2.18.7, 2.21.3, and 3.1.3, with fixes in 2.18.8, 2.21.4, and 3.1.4. If polymorphic typing isn't enabled, you're not exposed. |
✅ Resolved |
| CVE-2020-13956 |
(Apache HttpClient): HttpClient before 4.5.13 (and 5.x before 5.0.3) could misinterpret a malformed authority component in a request URI and send the request to the wrong target host. It's moderate severity and fixed in 4.5.13 and 5.0.3. |
✅ Resolved |