TopBraid EDG Vulnerability Report

Generated 2026-06-29T15:42:33Z

9.2.2 (released 2026-06-29) — previous: 9.2.1

Not affected (33)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression7.0.7Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web7.0.7Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core7.0.7Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.15.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.15.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.22.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.4.0Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.4.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.4.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.4.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.4.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.4.0Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.4.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression7.0.7Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core7.0.7Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web7.0.7HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web7.0.7Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web7.0.7Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web7.0.7Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.15.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.15.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.15.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44489SNYK-JS-AXIOS-17111086axios1.15.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.4.0Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (6)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.13.FinalImproper Verification of Cryptographic Signature2026-06-12
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider7.0.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-10
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider7.0.5Cross-site Scripting (XSS)2026-06-10
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce8.4.0Cross-site Scripting (XSS)2026-05-28
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce8.4.0Cross-site Scripting (XSS)2026-05-28
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce8.4.0Cross-site Scripting (XSS)2026-05-28

9.2.1 (released 2026-05-22) — previous: 9.2.0

Affected (6)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.13.FinalImproper Verification of Cryptographic Signature2026-06-129.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider7.0.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider7.0.5Cross-site Scripting (XSS)2026-06-109.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.

Not affected (53)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.13.FinalIncorrect Comparison2026-06-089.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.14.1Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40993SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17304906org.springframework.security:spring-security-saml2-service-provider7.0.5Deserialization of Untrusted Data2026-06-099.2.2vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression7.0.7Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web7.0.7Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core7.0.7Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core4.0.3Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.14.1Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.15.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.15.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.4.0Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.4.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.4.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.4.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.4.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.4.0Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.4.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-129.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.13.FinalHTTP Request Smuggling2026-06-129.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.13.FinalMissing Release of Memory after Effective Lifetime2026-06-119.2.2vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web7.0.5Open Redirect2026-06-109.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider7.0.5Information Exposure2026-06-099.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-089.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.13.FinalMissing Release of Resource after Effective Lifetime2026-06-089.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression7.0.7Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core7.0.7Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web7.0.7HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web7.0.7Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web7.0.7Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web7.0.7Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.15.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.15.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.15.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44489SNYK-JS-AXIOS-17111086axios1.15.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.4.0Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.14.1Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.2.0 (released 2026-05-07) — previous: 9.1.7

Affected (6)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.13.FinalImproper Verification of Cryptographic Signature2026-06-129.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider7.0.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider7.0.5Cross-site Scripting (XSS)2026-06-109.2.2Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce8.4.0Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.

Not affected (56)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.13.FinalIncorrect Comparison2026-06-089.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.14.1Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40993SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17304906org.springframework.security:spring-security-saml2-service-provider7.0.5Deserialization of Untrusted Data2026-06-099.2.2vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression7.0.7Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web7.0.7Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core7.0.7Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core4.0.3Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.14.1Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.15.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.15.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.4.0Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.4.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.4.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.4.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.4.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.4.0Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.4.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-129.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.13.FinalHTTP Request Smuggling2026-06-129.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.13.FinalMissing Release of Memory after Effective Lifetime2026-06-119.2.2vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web7.0.5Open Redirect2026-06-109.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider7.0.5Information Exposure2026-06-099.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.13.FinalAllocation of Resources Without Limits or Throttling2026-06-089.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.13.FinalMissing Release of Resource after Effective Lifetime2026-06-089.2.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression7.0.7Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core7.0.7Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web7.0.7HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web7.0.7Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web7.0.7Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web7.0.7Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.15.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.15.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.15.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.15.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44489SNYK-JS-AXIOS-17111086axios1.15.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
mediumCVE-2026-8723SNYK-JS-QS-16721866qs6.15.1NULL Pointer Dereference2026-05-179.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.4.0Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.14.1Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (3)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-14
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-10
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-22

9.1.7 (released 2026-06-29) — previous: 9.1.6

Affected (6)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (71)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.18Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.18Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.22.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.18HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.18Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (3)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.12.FinalImproper Verification of Cryptographic Signature2026-06-12
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-10
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-10

9.1.6 (released 2026-05-29) — previous: 9.1.5

Affected (9)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.12.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (100)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.12.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.18Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.18Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.1Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.12.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.18HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.18Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (1)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-05

9.1.5 (released 2026-05-07) — previous: 9.1.4

Affected (10)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.12.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (100)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.12.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.18Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.18Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.12.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.18HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.18Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (4)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-10
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-10
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-10
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-10

9.1.4 (released 2026-04-09) — previous: 9.1.3

Affected (14)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.12.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (102)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.12.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.17Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.17Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.17Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.12.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.12.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.17Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.12.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.12.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.12.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.17Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.17Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.17HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.17Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.17Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.17Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.12.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.17Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (8)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-31
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-31
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-26
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-26
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-31
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-31
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-21
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.16Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-19

9.1.3 (released 2026-03-23) — previous: 9.1.2

Affected (22)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.9.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.11Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.6HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.16Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (102)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.21.2Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.21.2Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.9.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.6Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.6HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.16Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.16Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.16Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.6Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.6Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.6Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.6Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.6Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.16Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.21.2Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54517SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440307com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54518SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440360com.fasterxml.jackson.core:jackson-databind2.21.2Incorrect Authorization2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54516SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457397com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.21.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.3.3Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.3Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.3Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.3.3Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.5CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.9.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.16Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.16Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.16HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.16Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.16Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.16Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.6Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.6Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.6Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.6Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.6Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.6Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.6Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.6Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.6CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.6Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.16Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.3Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.6Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.3.3Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.3Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (3)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-20
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-09
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-03

9.1.2 (released 2026-02-20) — previous: 9.1.1

Affected (25)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-209.1.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.9.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.6Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.6Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.12Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (104)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.9.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.12Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.12Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.15Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.12Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.3.0Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.3.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.3.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.0Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.3.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.9.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.6Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.6Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.12Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.12Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.12HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.12Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.12Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.12Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.6Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.6Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.6Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.0Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.3.0Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.3.0Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.3.0Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.3.0Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.1.1 (released 2026-02-17) — previous: 9.1.0

Affected (25)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-209.1.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.9.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.6Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.6Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.12Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (104)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.9.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.12Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.12Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.15Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.12Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.3.0Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.3.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.3.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.0Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.3.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.9.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.6Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.6Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.12Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.12Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.12HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.12Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.12Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.12Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.6Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.6Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.6Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.0Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.3.0Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.3.0Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.3.0Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.3.0Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.1.0 (released 2026-02-03) — previous: 9.0.4

Affected (25)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.6Use of Cache Containing Sensitive Information2026-03-209.1.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.9.FinalImproper Verification of Cryptographic Signature2026-06-129.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.6Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.3Improper Output Neutralization for Logs2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.3Improper Encoding or Escaping of Output2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.13.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.23Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-03-269.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.13.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.6Cross-site Scripting (XSS)2026-06-109.1.7Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.3Improper Validation of Certificate with Host Mismatch2026-04-109.1.5The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.23Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.3.0Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.12Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.1.4Upgrade to TopBraid EDG 9.1.4 or later.

Not affected (104)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.9.FinalIncorrect Comparison2026-06-089.1.7vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.12.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.13.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.13.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.6User Impersonation2026-06-099.1.7vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.4Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.12Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.12Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.15Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.12.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.12.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.13.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.13.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.13.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.9.FinalAllocation of Resources Without Limits or Throttling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.9.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-05-069.1.7vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.7Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.7XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.7Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.13.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.13.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.12Incomplete Cleanup2026-04-179.1.5vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.1.3vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.1.3vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.3.0Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.3.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.3.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.3.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.3.0Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.3.0Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.3.0Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-06-129.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.9.FinalMissing Release of Memory after Effective Lifetime2026-06-119.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.6Open Redirect2026-06-109.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.6Information Exposure2026-06-099.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.9.FinalAllocation of Resources Without Limits or Throttling2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.9.FinalMissing Release of Resource after Effective Lifetime2026-06-089.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.12Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.12Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.12HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.12Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.12Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.12Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.13.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.13.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.13.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-33245SNYK-JS-REACTROUTER-17137545react-router7.12.0Cross-site Scripting (XSS)2026-06-029.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.13.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-079.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.9.FinalHTTP Request Smuggling2026-05-059.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.13.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.13.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.13.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.13.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.13.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.13.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-40542SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-16134546org.apache.httpcomponents.client5:httpclient55.6Missing Critical Step in Authentication2026-04-239.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.6Information Exposure2026-04-229.1.7vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.6Insufficient Verification of Data Authenticity2026-04-229.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.6Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.1.7vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.12Allocation of Resources Without Limits or Throttling2026-04-179.1.5vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.3.0Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.13.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.3.0Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.3.0Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.3.0Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.3.0Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-53663SNYK-JS-REACTROUTER-17342510react-router7.12.0Cross-site Request Forgery (CSRF)2026-06-159.2.2vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.3.0Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (7)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-08
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-08
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-13
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-21
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-08
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-08
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-08

9.0.4 (released 2026-06-29) — previous: 9.0.3

Affected (21)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (72)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.18Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.18Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.22.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.18HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.18Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (6)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-12
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-10
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-26
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-26
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-10
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-15

9.0.3 (released 2026-05-07) — previous: 9.0.2

Affected (27)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-129.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.0.4Upgrade to TopBraid EDG 9.0.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (100)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.6.FinalIncorrect Comparison2026-06-089.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.18Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.18Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.0.4vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.0.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.6.FinalMissing Release of Memory after Effective Lifetime2026-06-119.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-109.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-099.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.18HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.18Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-229.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-229.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (7)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-20
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-10
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-10
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-10
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-10
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-18
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-19

9.0.2 (released 2025-12-18) — previous: 9.0.1

Affected (34)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-209.0.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-129.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.5Cross-site Scripting (XSS)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-189.0.3Upgrade to TopBraid EDG 9.0.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.0.4Upgrade to TopBraid EDG 9.0.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.0.3Upgrade to TopBraid EDG 9.0.3 or later.

Not affected (102)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.6.FinalIncorrect Comparison2026-06-089.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.11Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.11Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.14Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-179.0.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.0.4vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.0.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.6.FinalMissing Release of Memory after Effective Lifetime2026-06-119.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.5Open Redirect2026-06-109.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.5Information Exposure2026-06-099.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.11Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.11Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.11HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.11Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.11Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.11Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-179.0.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (4)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-08
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-08
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.2.6.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-07
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.2.6.FinalGeneration of Predictable Numbers or Identifiers2026-06-08

9.0.1 (released 2025-11-18) — previous: 9.0.0

Affected (38)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-209.0.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-129.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.2.6.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.5Cross-site Scripting (XSS)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.2.6.FinalGeneration of Predictable Numbers or Identifiers2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-189.0.3Upgrade to TopBraid EDG 9.0.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.0.4Upgrade to TopBraid EDG 9.0.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.0.3Upgrade to TopBraid EDG 9.0.3 or later.

Not affected (104)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.6.FinalIncorrect Comparison2026-06-089.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.11Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.11Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.14Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-179.0.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.0.4vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.0.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.6.FinalMissing Release of Memory after Effective Lifetime2026-06-119.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.5Open Redirect2026-06-109.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.5Information Exposure2026-06-099.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41715SNYK-JAVA-IOPROJECTREACTORNETTY-17260961io.projectreactor.netty:reactor-netty-http1.2.9Cleartext Transmission of Sensitive Information2026-06-089.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.11Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.11Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.11HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.11Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.11Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.11Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.2.6.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-179.0.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

9.0.0 (released 2025-11-04) — previous: 8.5.4

Affected (38)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-209.0.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.2.6.FinalImproper Verification of Cryptographic Signature2026-06-129.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.2.6.FinalInsufficient Verification of Data Authenticity2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.2.6.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-079.0.2Upgrade to TopBraid EDG 9.0.2 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.25.2Improper Output Neutralization for Logs2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.25.2Improper Encoding or Escaping of Output2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.12.2HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-03-269.0.4Upgrade to TopBraid EDG 9.0.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.12.2Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.5Cross-site Scripting (XSS)2026-06-109.0.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.2.6.FinalGeneration of Predictable Numbers or Identifiers2026-06-089.0.2Upgrade to TopBraid EDG 9.0.2 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2026-04-109.0.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.25.2Improper Validation of Certificate with Host Mismatch2025-12-189.0.3Upgrade to TopBraid EDG 9.0.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.2.6.FinalCRLF Injection2025-12-159.0.4Upgrade to TopBraid EDG 9.0.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-059.1.6Upgrade to TopBraid EDG 9.1.6 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-199.0.3Upgrade to TopBraid EDG 9.0.3 or later.

Not affected (104)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.20.0Incomplete List of Disallowed Inputs2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.20.0Deserialization of Untrusted Data2026-06-239.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.2.6.FinalIncorrect Comparison2026-06-089.0.4vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.12.2Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.12.2HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40983SNYK-JAVA-IOMICROMETER-17339194io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-09vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.5User Impersonation2026-06-099.0.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.15.1Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.11Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.11Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.14Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.12.2Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.12.2Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.12.2Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438323io.netty:netty-codec-compression4.2.6.FinalAllocation of Resources Without Limits or Throttling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438931io.netty:netty-codec-compression4.2.6.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42577SNYK-JAVA-IONETTY-16438936io.netty:netty-transport-classes-epoll4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-05-069.0.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.5Unsafe Reflection2026-05-049.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.5XML External Entity (XXE) Injection2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.5Memory Allocation with Excessive Size Value2026-05-049.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.12.2Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.12.2Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-179.0.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.81Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.81Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-04-049.0.4vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.20.0Allocation of Resources Without Limits or Throttling2026-02-289.0.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.20.0Server-side Request Forgery (SSRF)2026-06-239.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.20.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.6Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.6Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.6Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.6Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-06-129.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.4CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.2.6.FinalMissing Release of Memory after Effective Lifetime2026-06-119.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.5Open Redirect2026-06-109.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.5Information Exposure2026-06-099.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.2.6.FinalAllocation of Resources Without Limits or Throttling2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.2.6.FinalMissing Release of Resource after Effective Lifetime2026-06-089.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41715SNYK-JAVA-IOPROJECTREACTORNETTY-17260961io.projectreactor.netty:reactor-netty-http1.2.9Cleartext Transmission of Sensitive Information2026-06-089.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.11Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.11Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.11HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.11Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.11Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.11Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.12.2Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.12.2Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.12.2Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.12.2Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-079.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.2.6.FinalCRLF Injection2026-05-079.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.2.6.FinalHTTP Request Smuggling2026-05-059.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.22.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.12.2Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.12.2Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.12.2Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.12.2Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.12.2CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.12.2Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-229.0.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-229.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-219.0.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-179.0.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.6Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.81LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.12.2Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.6Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.6Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.6Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.6Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.6Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.6Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

8.5.4 (released 2026-06-29) — previous: 8.5.3

Affected (20)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.8.4HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.8.4Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (71)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.8.4Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.8.4HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
criticalCVE-2025-7783SNYK-JS-FORMDATA-10841150form-data4.0.2Predictable Value Range from Previous Values2025-07-189.0.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.14.5Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.18Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.18Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.8.4Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.8.4Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.8.4Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.8.4Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.8.4Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.80Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.80Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.22.0Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.5Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.5Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.2CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-41715SNYK-JAVA-IOPROJECTREACTORNETTY-17260961io.projectreactor.netty:reactor-netty-http1.0.48Cleartext Transmission of Sensitive Information2026-06-089.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.18HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.18Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.8.4Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.8.4Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.8.4Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.8.4Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.8.4Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.8.4Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.8.4CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.5Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.80LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.8.4Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.5Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.5Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.5Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
mediumCVE-2025-58754SNYK-JS-AXIOS-12613773axios1.8.4Allocation of Resources Without Limits or Throttling2025-09-109.0.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.5Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2025-22227SNYK-JAVA-IOPROJECTREACTORNETTY-10770514io.projectreactor.netty:reactor-netty-http1.0.48Exposure of Sensitive System Information to an Unauthorized Control Sphere2025-07-159.0.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (11)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.1.128.FinalImproper Verification of Cryptographic Signature2026-06-12
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-10
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.1.128.FinalInsufficient Verification of Data Authenticity2026-06-08
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.1.128.FinalInsufficient Verification of Data Authenticity2026-06-08
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.1.128.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-07
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-03-26
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.1.128.FinalAllocation of Resources Without Limits or Throttling2026-03-26
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-10
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.1.128.FinalGeneration of Predictable Numbers or Identifiers2026-06-08
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.1.128.FinalCRLF Injection2025-12-15
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-05

8.5.3 (released 2026-05-07) — previous: 8.5.2

Affected (31)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.1.128.FinalImproper Verification of Cryptographic Signature2026-06-128.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.9Improper Handling of Highly Compressed Data (Data Amplification)2026-06-108.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.1.128.FinalInsufficient Verification of Data Authenticity2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.1.128.FinalInsufficient Verification of Data Authenticity2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.1.128.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-078.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.8.4HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-03-268.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.1.128.FinalAllocation of Resources Without Limits or Throttling2026-03-268.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.8.4Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.9Cross-site Scripting (XSS)2026-06-108.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.1.128.FinalGeneration of Predictable Numbers or Identifiers2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.1.128.FinalCRLF Injection2025-12-158.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-058.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.

Not affected (104)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.19.1Incomplete List of Disallowed Inputs2026-06-238.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.19.1Deserialization of Untrusted Data2026-06-238.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.1.128.FinalIncorrect Comparison2026-06-088.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.8.4Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.8.4HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
criticalCVE-2025-7783SNYK-JS-FORMDATA-10841150form-data4.0.2Predictable Value Range from Previous Values2025-07-189.0.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.9User Impersonation2026-06-098.5.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.9User Impersonation2026-06-098.5.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.14.5Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.1.128.FinalAllocation of Resources Without Limits or Throttling2026-06-088.5.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.18Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.18Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.18Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.16Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.8.4Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.8.4Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.8.4Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438322io.netty:netty-codec4.1.128.FinalAllocation of Resources Without Limits or Throttling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.1.128.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438930io.netty:netty-codec4.1.128.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.4Unsafe Reflection2026-05-048.5.4vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.4XML External Entity (XXE) Injection2026-05-048.5.4vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.4Memory Allocation with Excessive Size Value2026-05-048.5.4vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.8.4Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.8.4Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.80Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.80Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-04-048.5.4vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-02-288.5.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2025-8671SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-15857052org.apache.httpcomponents.core5:httpcore5-h25.3.4Denial of Service (DoS)2025-08-138.5.4vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.19.1Server-side Request Forgery (SSRF)2026-06-238.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.19.1Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.5Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.5Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-158.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.1.128.FinalAllocation of Resources Without Limits or Throttling2026-06-128.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-06-128.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.2CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.1.128.FinalMissing Release of Memory after Effective Lifetime2026-06-118.5.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.9Open Redirect2026-06-108.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.9Information Exposure2026-06-098.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.1.128.FinalAllocation of Resources Without Limits or Throttling2026-06-088.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.1.128.FinalMissing Release of Resource after Effective Lifetime2026-06-088.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41715SNYK-JAVA-IOPROJECTREACTORNETTY-17260961io.projectreactor.netty:reactor-netty-http1.0.48Cleartext Transmission of Sensitive Information2026-06-089.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.18Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.18Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.18HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.18Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.18Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.18Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.8.4Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.8.4Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.8.4Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.1.128.FinalCRLF Injection2026-05-078.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-058.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.8.4Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.8.4Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.8.4Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.8.4CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.9Information Exposure2026-04-228.5.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.9Insufficient Verification of Data Authenticity2026-04-228.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.9Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-218.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.5Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.80LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.8.4Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.5Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.5Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.5Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
mediumCVE-2025-58754SNYK-JS-AXIOS-12613773axios1.8.4Allocation of Resources Without Limits or Throttling2025-09-109.0.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.5Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2025-22227SNYK-JAVA-IOPROJECTREACTORNETTY-10770514io.projectreactor.netty:reactor-netty-http1.0.48Exposure of Sensitive System Information to an Unauthorized Control Sphere2025-07-159.0.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (7)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-20
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.24.3Improper Output Neutralization for Logs2026-04-10
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-10
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-10
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2026-04-10
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2025-12-18
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-19

8.5.2 (released 2025-12-09) — previous: 8.5.1

Affected (38)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.5Use of Cache Containing Sensitive Information2026-03-208.5.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.1.128.FinalImproper Verification of Cryptographic Signature2026-06-128.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.5Improper Handling of Highly Compressed Data (Data Amplification)2026-06-108.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.1.128.FinalInsufficient Verification of Data Authenticity2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.1.128.FinalInsufficient Verification of Data Authenticity2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.1.128.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-078.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.24.3Improper Output Neutralization for Logs2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.8.4HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-03-268.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.1.128.FinalAllocation of Resources Without Limits or Throttling2026-03-268.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.8.4Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.5Cross-site Scripting (XSS)2026-06-108.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.1.128.FinalGeneration of Predictable Numbers or Identifiers2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2025-12-188.5.3Upgrade to TopBraid EDG 8.5.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.1.128.FinalCRLF Injection2025-12-158.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-058.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.11Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-198.5.3Upgrade to TopBraid EDG 8.5.3 or later.

Not affected (106)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.19.1Incomplete List of Disallowed Inputs2026-06-238.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.19.1Deserialization of Untrusted Data2026-06-238.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.1.128.FinalIncorrect Comparison2026-06-088.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.8.4Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.8.4HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.81.1Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
criticalCVE-2025-7783SNYK-JS-FORMDATA-10841150form-data4.0.2Predictable Value Range from Previous Values2025-07-189.0.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.5User Impersonation2026-06-098.5.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.5User Impersonation2026-06-098.5.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.14.5Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.1.128.FinalAllocation of Resources Without Limits or Throttling2026-06-088.5.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.11Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.11Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.14Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.8.4Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.8.4Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.8.4Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438322io.netty:netty-codec4.1.128.FinalAllocation of Resources Without Limits or Throttling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.1.128.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438930io.netty:netty-codec4.1.128.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.4Unsafe Reflection2026-05-048.5.4vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.4XML External Entity (XXE) Injection2026-05-048.5.4vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.4Memory Allocation with Excessive Size Value2026-05-048.5.4vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.8.4Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.8.4Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.11Incomplete Cleanup2026-04-178.5.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.80Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.80Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-04-048.5.4vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-02-288.5.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2025-8671SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-15857052org.apache.httpcomponents.core5:httpcore5-h25.3.4Denial of Service (DoS)2025-08-138.5.4vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.19.1Server-side Request Forgery (SSRF)2026-06-238.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.19.1Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.5Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.5Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-158.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.1.128.FinalAllocation of Resources Without Limits or Throttling2026-06-128.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-06-128.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.2CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.1.128.FinalMissing Release of Memory after Effective Lifetime2026-06-118.5.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.5Open Redirect2026-06-108.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.5Information Exposure2026-06-098.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.1.128.FinalAllocation of Resources Without Limits or Throttling2026-06-088.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.1.128.FinalMissing Release of Resource after Effective Lifetime2026-06-088.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41715SNYK-JAVA-IOPROJECTREACTORNETTY-17260961io.projectreactor.netty:reactor-netty-http1.0.48Cleartext Transmission of Sensitive Information2026-06-089.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.11Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.11Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.11HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.11Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.11Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.11Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.8.4Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.8.4Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.8.4Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.1.128.FinalCRLF Injection2026-05-078.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.1.128.FinalHTTP Request Smuggling2026-05-058.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.8.4Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.8.4Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.8.4Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.8.4CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.5Information Exposure2026-04-228.5.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.5Insufficient Verification of Data Authenticity2026-04-228.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.5Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-218.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.11Allocation of Resources Without Limits or Throttling2026-04-178.5.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.5Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.80LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.8.4Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.5Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.5Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.5Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
mediumCVE-2025-58754SNYK-JS-AXIOS-12613773axios1.8.4Allocation of Resources Without Limits or Throttling2025-09-109.0.0vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.5Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2025-22227SNYK-JAVA-IOPROJECTREACTORNETTY-10770514io.projectreactor.netty:reactor-netty-http1.0.48Exposure of Sensitive System Information to an Unauthorized Control Sphere2025-07-159.0.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (9)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
highCVE-2025-41249SNYK-JAVA-ORGSPRINGFRAMEWORK-12817817org.springframework:spring-core6.2.8Incorrect Authorization2025-09-16
highCVE-2025-58056SNYK-JAVA-IONETTY-12485149io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2025-09-03
highCVE-2025-58057SNYK-JAVA-IONETTY-12485150io.netty:netty-codec-http4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-03
highCVE-2025-58057SNYK-JAVA-IONETTY-12485151io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-03
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-12238980org.apache.tika:tika-parser-pdf-module3.2.0XML External Entity (XXE) Injection2025-08-20
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-14188255org.apache.tika:tika-core3.2.0XML External Entity (XXE) Injection2025-08-20
highCVE-2025-41242SNYK-JAVA-ORGSPRINGFRAMEWORK-12008931org.springframework:spring-beans6.2.8Relative Path Traversal2025-08-14
highCVE-2025-55163SNYK-JAVA-IONETTY-11799531io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2025-08-13
mediumCVE-2025-7962SNYK-JAVA-ORGECLIPSEANGUS-12239873org.eclipse.angus:angus-mail2.0.3Improper Neutralization2025-07-21

8.5.1 (released 2025-08-26) — previous: 8.5.0

Affected (47)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.1Use of Cache Containing Sensitive Information2026-03-208.5.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.1.119.FinalImproper Verification of Cryptographic Signature2026-06-128.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.1Improper Handling of Highly Compressed Data (Data Amplification)2026-06-108.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.1.112.FinalInsufficient Verification of Data Authenticity2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.1.112.FinalInsufficient Verification of Data Authenticity2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.1.112.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-078.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.24.3Improper Output Neutralization for Logs2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.8.4HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-03-268.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2026-03-268.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.8.4Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-41249SNYK-JAVA-ORGSPRINGFRAMEWORK-12817817org.springframework:spring-core6.2.8Incorrect Authorization2025-09-168.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58056SNYK-JAVA-IONETTY-12485149io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58057SNYK-JAVA-IONETTY-12485150io.netty:netty-codec-http4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58057SNYK-JAVA-IONETTY-12485151io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-12238980org.apache.tika:tika-parser-pdf-module3.2.0XML External Entity (XXE) Injection2025-08-208.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-14188255org.apache.tika:tika-core3.2.0XML External Entity (XXE) Injection2025-08-208.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-41242SNYK-JAVA-ORGSPRINGFRAMEWORK-12008931org.springframework:spring-beans6.2.8Relative Path Traversal2025-08-148.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IONETTY-11799531io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2025-08-138.5.2Upgrade to TopBraid EDG 8.5.2 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.1Cross-site Scripting (XSS)2026-06-108.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.1.112.FinalGeneration of Predictable Numbers or Identifiers2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2025-12-188.5.3Upgrade to TopBraid EDG 8.5.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.1.118.FinalCRLF Injection2025-12-158.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2025-7962SNYK-JAVA-ORGECLIPSEANGUS-12239873org.eclipse.angus:angus-mail2.0.3Improper Neutralization2025-07-218.5.2Upgrade to TopBraid EDG 8.5.2 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-058.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.8Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-198.5.3Upgrade to TopBraid EDG 8.5.3 or later.

Not affected (108)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.19.1Incomplete List of Disallowed Inputs2026-06-238.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.19.1Deserialization of Untrusted Data2026-06-238.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.1.119.FinalIncorrect Comparison2026-06-088.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.8.4Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.8.4HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.80.2Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
criticalCVE-2025-7783SNYK-JS-FORMDATA-10841150form-data4.0.2Predictable Value Range from Previous Values2025-07-189.0.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.1User Impersonation2026-06-098.5.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.1User Impersonation2026-06-098.5.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.14.5Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.1.119.FinalAllocation of Resources Without Limits or Throttling2026-06-088.5.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.8Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.8Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.8Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.12Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.8.4Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.8.4Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.8.4Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438322io.netty:netty-codec4.1.118.FinalAllocation of Resources Without Limits or Throttling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438930io.netty:netty-codec4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.4Unsafe Reflection2026-05-048.5.4vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.4XML External Entity (XXE) Injection2026-05-048.5.4vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.4Memory Allocation with Excessive Size Value2026-05-048.5.4vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.8.4Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.8.4Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.8Incomplete Cleanup2026-04-178.5.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.80Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.80Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-04-048.5.4vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-02-288.5.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2025-41248SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-12817818org.springframework.security:spring-security-core6.5.1Incorrect Authorization2025-09-168.5.2vulnerable_code_not_in_execute_path
highCVE-2025-8671SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-15857052org.apache.httpcomponents.core5:httpcore5-h25.3.4Denial of Service (DoS)2025-08-138.5.4vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.19.1Server-side Request Forgery (SSRF)2026-06-238.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.19.1Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.5Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.5Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-158.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2026-06-128.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-06-128.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.2CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.1.118.FinalMissing Release of Memory after Effective Lifetime2026-06-118.5.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.1Open Redirect2026-06-108.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.1Information Exposure2026-06-098.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2026-06-088.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.1.118.FinalMissing Release of Resource after Effective Lifetime2026-06-088.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41715SNYK-JAVA-IOPROJECTREACTORNETTY-17260961io.projectreactor.netty:reactor-netty-http1.0.48Cleartext Transmission of Sensitive Information2026-06-089.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.8Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.8Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.8HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.8Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.8Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.8Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.8.4Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.8.4Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.8.4Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.1.118.FinalCRLF Injection2026-05-078.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-058.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.8.4Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.8.4Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.8.4Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.8.4CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.1Information Exposure2026-04-228.5.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.1Insufficient Verification of Data Authenticity2026-04-228.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.1Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-218.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.8Allocation of Resources Without Limits or Throttling2026-04-178.5.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.5Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.80LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.8.4Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.5Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.5Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.5Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
mediumCVE-2025-58754SNYK-JS-AXIOS-12613773axios1.8.4Allocation of Resources Without Limits or Throttling2025-09-109.0.0vulnerable_code_not_in_execute_path
mediumCVE-2025-53864SNYK-JAVA-COMNIMBUSDS-10691768com.nimbusds:nimbus-jose-jwt9.37.3Uncontrolled Recursion2025-07-118.5.2vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.5Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2025-22227SNYK-JAVA-IOPROJECTREACTORNETTY-10770514io.projectreactor.netty:reactor-netty-http1.0.48Exposure of Sensitive System Information to an Unauthorized Control Sphere2025-07-159.0.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

8.5.0 (released 2025-08-05) — previous: 8.4.3

Affected (47)

The product is exposed and action should be taken.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inAction statement
criticalCVE-2026-22732SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796org.springframework.security:spring-security-web6.5.1Use of Cache Containing Sensitive Information2026-03-208.5.3Upgrade to TopBraid EDG 8.5.3, 9.0.3, 9.1.3, or later, when available.
highCVE-2026-50010SNYK-JAVA-IONETTY-17334567io.netty:netty-handler4.1.119.FinalImproper Verification of Cryptographic Signature2026-06-128.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-40988SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315633org.springframework.security:spring-security-saml2-service-provider6.5.1Improper Handling of Highly Compressed Data (Data Amplification)2026-06-108.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
highCVE-2026-47691SNYK-JAVA-IONETTY-17261020io.netty:netty-resolver-dns4.1.112.FinalInsufficient Verification of Data Authenticity2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-45674SNYK-JAVA-IONETTY-17262734io.netty:netty-resolver-dns4.1.112.FinalInsufficient Verification of Data Authenticity2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-42579SNYK-JAVA-IONETTY-16438938io.netty:netty-codec-dns4.1.112.FinalNull Byte Interaction Error (Poison Null Byte)2026-05-078.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-40895SNYK-JS-FOLLOWREDIRECTS-16032162follow-redirects1.15.9Improper Removal of Sensitive Information Before Storage or Transfer2026-04-149.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-34478SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967739org.apache.logging.log4j:log4j-core2.24.3Improper Output Neutralization for Logs2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Rfc5424Layout with a stream-based syslog appender should reconfigure to avoid Rfc5424Layout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34480SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use XmlLayout should reconfigure to avoid XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-34479SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804org.apache.logging.log4j:log4j-core2.24.3Improper Encoding or Escaping of Output2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use Log4j1XmlLayout should reconfigure to avoid Log4j1XmlLayout, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
highCVE-2026-40175SNYK-JS-AXIOS-15969258axios1.8.4HTTP Response Splitting2026-04-109.2.0Upgrade to TopBraid EDG 9.2.0 or later.
highCVE-2026-4800SNYK-JS-LODASH-15869625lodash4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-4800SNYK-JS-LODASHES-15869627lodash-es4.17.21Arbitrary Code Injection2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
highCVE-2026-33870SNYK-JAVA-IONETTY-15789756io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-03-268.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-33871SNYK-JAVA-IONETTY-15789758io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2026-03-268.5.4Upgrade to TopBraid EDG 8.5.4 or later.
highCVE-2026-25639SNYK-JS-AXIOS-15252993axios1.8.4Prototype Pollution2026-02-099.1.3Upgrade to TopBraid EDG 9.1.3 or later.
highCVE-2025-68470SNYK-JS-REACTROUTER-14908286react-router7.6.0Open Redirect2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2026-22029SNYK-JS-REACTROUTER-14908531react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-41249SNYK-JAVA-ORGSPRINGFRAMEWORK-12817817org.springframework:spring-core6.2.8Incorrect Authorization2025-09-168.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58056SNYK-JAVA-IONETTY-12485149io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58057SNYK-JAVA-IONETTY-12485150io.netty:netty-codec-http4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-58057SNYK-JAVA-IONETTY-12485151io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2025-09-038.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-12238980org.apache.tika:tika-parser-pdf-module3.2.0XML External Entity (XXE) Injection2025-08-208.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-54988SNYK-JAVA-ORGAPACHETIKA-14188255org.apache.tika:tika-core3.2.0XML External Entity (XXE) Injection2025-08-208.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-41242SNYK-JAVA-ORGSPRINGFRAMEWORK-12008931org.springframework:spring-beans6.2.8Relative Path Traversal2025-08-148.5.2Upgrade to TopBraid EDG 8.5.2 or later.
highCVE-2025-55163SNYK-JAVA-IOGRPC-13786834io.grpc:grpc-netty-shaded1.68.0Allocation of Resources Without Limits or Throttling2025-08-139.1.0Upgrade to TopBraid EDG 9.1.0 or later.
highCVE-2025-55163SNYK-JAVA-IONETTY-11799531io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2025-08-138.5.2Upgrade to TopBraid EDG 8.5.2 or later.
mediumCVE-2026-41003SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17315632org.springframework.security:spring-security-saml2-service-provider6.5.1Cross-site Scripting (XSS)2026-06-108.5.4Upgrade to TopBraid EDG 8.5.4, 9.0.4, 9.1.7, 9.2.2, or later, when available.
mediumCVE-2026-45673SNYK-JAVA-IONETTY-17261131io.netty:netty-resolver-dns4.1.112.FinalGeneration of Predictable Numbers or Identifiers2026-06-088.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2026-47761SNYK-JS-TINYMCE-17056137tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47762SNYK-JS-TINYMCE-17056141tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-47759SNYK-JS-TINYMCE-17056166tinymce7.5.1Cross-site Scripting (XSS)2026-05-289.2.2Upgrade to TopBraid EDG 9.2.2 or later.
mediumCVE-2026-34477SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967727org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2026-04-108.5.3The default configuration is not exposed. Customers who have customised their Log4j configuration to use SocketAppender, SmtpAppender, or SyslogAppender with TLS should reconfigure to avoid those appenders, or upgrade to TopBraid EDG 9.2.0, 9.1.5, 9.0.3, 8.5.3, or 8.4.3, all scheduled for release in May 2026.
mediumCVE-2026-2950SNYK-JS-LODASH-15869619lodash4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-2950SNYK-JS-LODASHES-15869621lodash-es4.17.21Prototype Pollution2026-03-319.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2026-0540SNYK-JS-DOMPURIFY-15371376dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.3Upgrade to TopBraid EDG 9.1.3 or later.
mediumCVE-2025-13465SNYK-JS-LODASH-15053838lodash4.17.21Prototype Pollution2026-01-219.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-13465SNYK-JS-LODASHES-15053836lodash-es4.17.21Prototype Pollution2026-01-219.1.4Upgrade to TopBraid EDG 9.1.4 or later.
mediumCVE-2025-59057SNYK-JS-REACTROUTER-14908289react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-21884SNYK-JS-REACTROUTER-14908293react-router7.6.0Cross-site Scripting (XSS)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2026-22030SNYK-JS-REACTROUTER-14908429react-router7.6.0Cross-site Request Forgery (CSRF)2026-01-089.1.0Upgrade to TopBraid EDG 9.1.0 or later.
mediumCVE-2025-68161SNYK-JAVA-ORGAPACHELOGGINGLOG4J-14532782org.apache.logging.log4j:log4j-core2.24.3Improper Validation of Certificate with Host Mismatch2025-12-188.5.3Upgrade to TopBraid EDG 8.5.3 or later.
mediumCVE-2025-67735SNYK-JAVA-IONETTY-14423947io.netty:netty-codec-http4.1.118.FinalCRLF Injection2025-12-158.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2025-7962SNYK-JAVA-ORGECLIPSEANGUS-12239873org.eclipse.angus:angus-mail2.0.3Improper Neutralization2025-07-218.5.2Upgrade to TopBraid EDG 8.5.2 or later.
mediumCVE-2026-2327SNYK-JS-MARKDOWNIT-10666750markdown-it14.1.0Regular Expression Denial of Service (ReDoS)2025-07-058.5.4Upgrade to TopBraid EDG 8.5.4 or later.
mediumCVE-2025-6493SNYK-JS-CODEMIRROR-10494092codemirror5.65.18Regular Expression Denial of Service (ReDoS)2025-06-229.2.0Upgrade to TopBraid EDG 9.2.0 or later.
lowCVE-2026-22735SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755org.springframework:spring-web6.2.8Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2026-03-198.5.3Upgrade to TopBraid EDG 8.5.3 or later.

Not affected (108)

Component present in the product, but not exploitable.

SeverityCVESnyk IDModuleVersionTitleDisclosedFixed inJustification
criticalCVE-2026-54513SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366com.fasterxml.jackson.core:jackson-databind2.19.1Incomplete List of Disallowed Inputs2026-06-238.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-54512SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598com.fasterxml.jackson.core:jackson-databind2.19.1Deserialization of Untrusted Data2026-06-238.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-44249SNYK-JAVA-IONETTY-17254120io.netty:netty-handler4.1.119.FinalIncorrect Comparison2026-06-088.5.4vulnerable_code_not_in_execute_path
criticalCVE-2026-42211SNYK-JS-REACTROUTER-17137394react-router7.6.0Deserialization of Untrusted Data2026-06-029.2.2vulnerable_code_not_in_execute_path
criticalCVE-2026-42264SNYK-JS-AXIOS-16417750axios1.8.4Prototype Pollution2026-05-059.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42035SNYK-JS-AXIOS-16298058axios1.8.4HTTP Response Splitting2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-42033SNYK-JS-AXIOS-16299904axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
criticalCVE-2026-5588SNYK-JAVA-ORGBOUNCYCASTLE-16075260org.bouncycastle:bcpkix-jdk18on1.80.2Improper Verification of Cryptographic Signature2026-04-159.2.0vulnerable_code_not_in_execute_path
criticalCVE-2025-7783SNYK-JS-FORMDATA-10841150form-data4.0.2Predictable Value Range from Previous Values2025-07-189.0.0vulnerable_code_not_in_execute_path
critical(none)SNYK-JS-JQUERYFORM-574783jquery-form3.50.0Cross-site Scripting (XSS)2015-04-109.2.0vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305998org.springframework.security:spring-security-web6.5.1User Impersonation2026-06-098.5.4vulnerable_code_not_in_execute_path
highCVE-2026-47838SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17305999org.springframework.security:spring-security-config6.5.1User Impersonation2026-06-098.5.4vulnerable_code_not_in_execute_path
highCVE-2026-40984SNYK-JAVA-IOMICROMETER-17260885io.micrometer:micrometer-core1.14.5Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-45416SNYK-JAVA-IONETTY-17254117io.netty:netty-handler4.1.119.FinalAllocation of Resources Without Limits or Throttling2026-06-088.5.4vulnerable_code_not_in_execute_path
highCVE-2026-41850SNYK-JAVA-ORGSPRINGFRAMEWORK-17253311org.springframework:spring-expression6.2.8Inefficient Algorithmic Complexity2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41840SNYK-JAVA-ORGSPRINGFRAMEWORK-17253520org.springframework:spring-web6.2.8Missing Release of Memory after Effective Lifetime2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41851SNYK-JAVA-ORGSPRINGFRAMEWORK-17255206org.springframework:spring-core6.2.8Allocation of Resources Without Limits or Throttling2026-06-08vulnerable_code_not_in_execute_path
highCVE-2026-41720SNYK-JAVA-ORGSPRINGFRAMEWORKLDAP-17260845org.springframework.ldap:spring-ldap-core3.2.12Incorrect Implementation of Authentication Algorithm2026-06-089.2.2vulnerable_code_not_in_execute_path
highCVE-2026-44486SNYK-JS-AXIOS-17172681axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
highCVE-2026-42342SNYK-JS-REACTROUTER-17138701react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.2vulnerable_code_not_in_execute_path
highCVE-2026-34077SNYK-JS-REACTROUTER-17138883react-router7.6.0Allocation of Resources Without Limits or Throttling2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-40181SNYK-JS-REACTROUTER-17138887react-router7.6.0Open Redirect2026-06-029.2.0vulnerable_code_not_in_execute_path
highCVE-2026-44495SNYK-JS-AXIOS-17111060axios1.8.4Prototype Pollution2026-05-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-44492SNYK-JS-AXIOS-17111062axios1.8.4Server-side Request Forgery (SSRF)2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-44494SNYK-JS-AXIOS-17111079axios1.8.4Prototype Pollution2026-05-29vulnerable_code_not_in_execute_path
highCVE-2026-45292SNYK-JAVA-IOOPENTELEMETRY-17280222io.opentelemetry:opentelemetry-api1.42.1Allocation of Resources Without Limits or Throttling2026-05-28vulnerable_code_not_in_execute_path
highCVE-2026-42583SNYK-JAVA-IONETTY-16438322io.netty:netty-codec4.1.118.FinalAllocation of Resources Without Limits or Throttling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42585SNYK-JAVA-IONETTY-16438737io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42584SNYK-JAVA-IONETTY-16438923io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438929io.netty:netty-codec-http24.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42587SNYK-JAVA-IONETTY-16438930io.netty:netty-codec4.1.118.FinalImproper Handling of Highly Compressed Data (Data Amplification)2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42581SNYK-JAVA-IONETTY-16438934io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
highCVE-2026-42027SNYK-JAVA-ORGAPACHEOPENNLP-16419373org.apache.opennlp:opennlp-tools2.5.4Unsafe Reflection2026-05-048.5.4vulnerable_code_not_in_execute_path
highCVE-2026-40682SNYK-JAVA-ORGAPACHEOPENNLP-16419377org.apache.opennlp:opennlp-tools2.5.4XML External Entity (XXE) Injection2026-05-048.5.4vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42440SNYK-JAVA-ORGAPACHEOPENNLP-16535521org.apache.opennlp:opennlp-tools2.5.4Memory Allocation with Excessive Size Value2026-05-048.5.4vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42044SNYK-JS-AXIOS-16299921axios1.8.4Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
highCVE-2026-42039SNYK-JS-AXIOS-16299923axios1.8.4Uncontrolled Recursion2026-04-249.2.0vulnerable_code_not_in_execute_path
highCVE-2026-22740SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615org.springframework:spring-web6.2.8Incomplete Cleanup2026-04-178.5.3vulnerable_code_not_in_execute_path
highCVE-2026-5598SNYK-JAVA-ORGBOUNCYCASTLE-16074612org.bouncycastle:bcprov-jdk18on1.80Timing Attack2026-04-159.2.0vulnerable_code_not_in_execute_path
highCVE-2025-14813SNYK-JAVA-ORGBOUNCYCASTLE-16075266org.bouncycastle:bcprov-jdk18on1.80Use of a Broken or Risky Cryptographic Algorithm2026-04-159.2.0vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-04-048.5.4vulnerable_code_not_in_execute_path
high(none)SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924com.fasterxml.jackson.core:jackson-core2.19.1Allocation of Resources Without Limits or Throttling2026-02-288.5.4vulnerable_code_not_in_execute_path
highCVE-2025-68280SNYK-JAVA-ORGAPACHESISCORE-14874786org.apache.sis.core:sis-metadata1.4XML External Entity (XXE) Injection2026-01-05vulnerable_code_not_in_execute_path
highCVE-2025-41248SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-12817818org.springframework.security:spring-security-core6.5.1Incorrect Authorization2025-09-168.5.2vulnerable_code_not_in_execute_path
highCVE-2025-8671SNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCORE5-15857052org.apache.httpcomponents.core5:httpcore5-h25.3.4Denial of Service (DoS)2025-08-138.5.4vulnerable_code_not_in_execute_path
highCVE-2021-23370SNYK-JS-SWIPER-1088062swiper3.4.1Prototype Pollution2021-03-229.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-54514SNYK-JAVA-COMFASTERXMLJACKSONCORE-17434790com.fasterxml.jackson.core:jackson-databind2.19.1Server-side Request Forgery (SSRF)2026-06-238.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-54515SNYK-JAVA-COMFASTERXMLJACKSONCORE-17457695com.fasterxml.jackson.core:jackson-databind2.19.1Improperly Controlled Modification of Dynamically-Determined Object Attributes2026-06-23vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17375136dompurify3.2.5Improper Initialization2026-06-18vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17342528dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49978SNYK-JS-DOMPURIFY-17344504dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344516dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49458SNYK-JS-DOMPURIFY-17344526dompurify3.2.5Trust Boundary Violation2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-49459SNYK-JS-DOMPURIFY-17344538dompurify3.2.5Prototype Pollution2026-06-15vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-17344549dompurify3.2.5Cross-site Scripting (XSS)2026-06-15vulnerable_code_not_in_execute_path
mediumCVE-2026-48988SNYK-JS-MARKDOWNIT-17353909markdown-it14.1.0Inefficient Algorithmic Complexity2026-06-158.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50560SNYK-JAVA-IONETTY-17337010io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2026-06-128.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-50020SNYK-JAVA-IONETTY-17337012io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-06-128.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-12143SNYK-JS-FORMDATA-17337015form-data4.0.2CRLF Injection2026-06-12vulnerable_code_not_in_execute_path
mediumCVE-2026-48043SNYK-JAVA-IONETTY-17311220io.netty:netty-codec-http24.1.118.FinalMissing Release of Memory after Effective Lifetime2026-06-118.5.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41706SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17314598org.springframework.security:spring-security-web6.5.1Open Redirect2026-06-108.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41694SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-17307750org.springframework.security:spring-security-saml2-service-provider6.5.1Information Exposure2026-06-098.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-47244SNYK-JAVA-IONETTY-17254661io.netty:netty-codec-http24.1.118.FinalAllocation of Resources Without Limits or Throttling2026-06-088.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-45536SNYK-JAVA-IONETTY-17260879io.netty:netty-transport-native-unix-common4.1.118.FinalMissing Release of Resource after Effective Lifetime2026-06-088.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41715SNYK-JAVA-IOPROJECTREACTORNETTY-17260961io.projectreactor.netty:reactor-netty-http1.0.48Cleartext Transmission of Sensitive Information2026-06-089.0.2vulnerable_code_not_in_execute_path
mediumCVE-2026-41852SNYK-JAVA-ORGSPRINGFRAMEWORK-17253570org.springframework:spring-expression6.2.8Exposed Dangerous Method or Function2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41848SNYK-JAVA-ORGSPRINGFRAMEWORK-17254051org.springframework:spring-core6.2.8Regular Expression Denial of Service (ReDoS)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41853SNYK-JAVA-ORGSPRINGFRAMEWORK-17254109org.springframework:spring-web6.2.8HTTP Request Smuggling2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41839SNYK-JAVA-ORGSPRINGFRAMEWORK-17254128org.springframework:spring-web6.2.8Session Fixation2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-41854SNYK-JAVA-ORGSPRINGFRAMEWORK-17254521org.springframework:spring-web6.2.8Server-side Request Forgery (SSRF)2026-06-08vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-41845SNYK-JAVA-ORGSPRINGFRAMEWORK-17255245org.springframework:spring-web6.2.8Cross-site Scripting (XSS)2026-06-08vulnerable_code_not_in_execute_path
mediumCVE-2026-44496SNYK-JS-AXIOS-17172532axios1.8.4Regular Expression Denial of Service (ReDoS)2026-06-04vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-44488SNYK-JS-AXIOS-17172751axios1.8.4Allocation of Resources Without Limits or Throttling2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44487SNYK-JS-AXIOS-17172930axios1.8.4Insertion of Sensitive Information Into Sent Data2026-06-04vulnerable_code_not_in_execute_path
mediumCVE-2026-44490SNYK-JS-AXIOS-17111081axios1.8.4Prototype Pollution2026-05-29vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42580SNYK-JAVA-IONETTY-16438926io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-078.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-42578SNYK-JAVA-IONETTY-16438935io.netty:netty-handler-proxy4.1.118.FinalCRLF Injection2026-05-078.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41417SNYK-JAVA-IONETTY-16425695io.netty:netty-codec-http4.1.118.FinalHTTP Request Smuggling2026-05-058.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-43869SNYK-JAVA-ORGAPACHETHRIFT-16432027org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-05-059.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-41603SNYK-JAVA-ORGAPACHETHRIFT-16323114org.apache.thrift:libthrift0.21.0Improper Validation of Certificate with Host Mismatch2026-04-289.2.1vulnerable_code_not_in_execute_path
mediumCVE-2026-42040SNYK-JS-AXIOS-16298055axios1.8.4Improper Encoding or Escaping of Output2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42038SNYK-JS-AXIOS-16298095axios1.8.4Server-side Request Forgery (SSRF)2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42034SNYK-JS-AXIOS-16298130axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42036SNYK-JS-AXIOS-16298162axios1.8.4Allocation of Resources Without Limits or Throttling2026-04-249.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-42042SNYK-JS-AXIOS-16299478axios1.8.4Insertion of Sensitive Information Into Sent Data2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42037SNYK-JS-AXIOS-16299819axios1.8.4CRLF Injection2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-42041SNYK-JS-AXIOS-16299925axios1.8.4Prototype Pollution2026-04-249.2.0vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22746SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121176org.springframework.security:spring-security-core6.5.1Information Exposure2026-04-228.5.4vulnerable_code_cannot_be_controlled_by_adversary
mediumCVE-2026-22748SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16121448org.springframework.security:spring-security-oauth2-jose6.5.1Insufficient Verification of Data Authenticity2026-04-228.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-22751SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-16120313org.springframework.security:spring-security-core6.5.1Time-of-check Time-of-use (TOCTOU) Race Condition2026-04-218.5.4vulnerable_code_not_in_execute_path
mediumCVE-2026-41238SNYK-JS-DOMPURIFY-16132234dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-22745SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618org.springframework:spring-core6.2.8Allocation of Resources Without Limits or Throttling2026-04-178.5.3vulnerable_code_not_in_execute_path
mediumCVE-2026-41240SNYK-JS-DOMPURIFY-16078387dompurify3.2.5Operator Precedence Logic Error2026-04-169.2.0vulnerable_code_not_in_execute_path
mediumCVE-2026-0636SNYK-JAVA-ORGBOUNCYCASTLE-16075254org.bouncycastle:bcprov-jdk18on1.80LDAP Injection2026-04-159.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-62718SNYK-JS-AXIOS-15965856axios1.8.4Unintended Proxy or Intermediary ('Confused Deputy')2026-04-099.2.0component_not_present
medium(none)SNYK-JS-DOMPURIFY-15874903dompurify3.2.5Prototype Pollution2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15874905dompurify3.2.5Permissive List of Allowed Inputs2026-04-039.1.3vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-DOMPURIFY-15810938dompurify3.2.5Cross-site Scripting (XSS)2026-03-279.1.3vulnerable_code_not_in_execute_path
mediumCVE-2026-33532SNYK-JS-YAML-15765520yaml1.10.2Uncontrolled Recursion2026-03-259.2.0vulnerable_code_not_in_execute_path
mediumCVE-2025-15599SNYK-JS-DOMPURIFY-15371386dompurify3.2.5Cross-site Scripting (XSS)2026-03-039.1.0vulnerable_code_not_in_execute_path
mediumCVE-2025-58754SNYK-JS-AXIOS-12613773axios1.8.4Allocation of Resources Without Limits or Throttling2025-09-109.0.0vulnerable_code_not_in_execute_path
mediumCVE-2025-53864SNYK-JAVA-COMNIMBUSDS-10691768com.nimbusds:nimbus-jose-jwt9.37.3Uncontrolled Recursion2025-07-118.5.2vulnerable_code_not_in_execute_path
medium(none)SNYK-JS-D3COLOR-1076592d3-color1.4.1Regular Expression Denial of Service (ReDoS)2021-02-189.2.0vulnerable_code_not_in_execute_path
low(none)SNYK-JS-DOMPURIFY-17344552dompurify3.2.5Protection Mechanism Failure2026-06-15vulnerable_code_not_in_execute_path
lowCVE-2026-41239SNYK-JS-DOMPURIFY-16131135dompurify3.2.5Cross-site Scripting (XSS)2026-04-199.2.0vulnerable_code_not_in_execute_path
lowCVE-2025-22227SNYK-JAVA-IOPROJECTREACTORNETTY-10770514io.projectreactor.netty:reactor-netty-http1.0.48Exposure of Sensitive System Information to an Unauthorized Control Sphere2025-07-159.0.0vulnerable_code_not_in_execute_path
lowCVE-2018-25050SNYK-JS-CHOSENJS-3184933chosen-js1.6.2Cross-site Scripting (XSS)2022-12-299.2.0vulnerable_code_cannot_be_controlled_by_adversary
lowCVE-2020-29582SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744org.jetbrains.kotlin:kotlin-stdlib1.8.21Information Exposure2022-02-03vulnerable_code_not_in_execute_path

Fixed (13)

Previous release was affected, but this one is not.

SeverityCVESnyk IDModuleVersionTitleDisclosed
high(none)SNYK-JAVA-COMGITHUBJUNRAR-16097905com.github.junrar:junrar7.5.5Directory Traversal2026-04-16
highCVE-2026-28208SNYK-JAVA-COMGITHUBJUNRAR-15360268com.github.junrar:junrar7.5.5Directory Traversal2026-02-27
highCVE-2025-68470SNYK-JS-REMIXRUNROUTER-14908287@remix-run/router1.14.1Open Redirect2026-01-08
highCVE-2026-22029SNYK-JS-REMIXRUNROUTER-14908530@remix-run/router1.14.1Cross-site Scripting (XSS)2026-01-08
highCVE-2025-48976SNYK-JAVA-ORGAPACHECOMMONS-10363251org.apache.commons:commons-fileupload2-core2.0.0-M2Allocation of Resources Without Limits or Throttling2025-06-16
highCVE-2025-48734SNYK-JAVA-COMMONSBEANUTILS-10259368commons-beanutils:commons-beanutils1.9.4Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')2025-05-28
mediumCVE-2026-41245SNYK-JAVA-COMGITHUBJUNRAR-16115493com.github.junrar:junrar7.5.5Directory Traversal2026-04-20
mediumCVE-2025-8916SNYK-JAVA-ORGBOUNCYCASTLE-11789695org.bouncycastle:bcprov-jdk18on1.78.1Allocation of Resources Without Limits or Throttling2025-08-13
mediumCVE-2025-41234SNYK-JAVA-ORGSPRINGFRAMEWORK-10345766org.springframework:spring-web6.1.18HTTP Response Splitting2025-06-12
mediumCVE-2025-4949SNYK-JAVA-ORGECLIPSEJGIT-10231763org.eclipse.jgit:org.eclipse.jgit7.2.0.202503040940-rXML External Entity (XXE) Injection2025-05-21
mediumCVE-2025-22234SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-9789380org.springframework.security:spring-security-crypto6.3.8Timing Attack2025-04-22
lowCVE-2025-22233SNYK-JAVA-ORGSPRINGFRAMEWORK-10176071org.springframework:spring-context6.1.18Improper Handling of Case Sensitivity2025-05-15
lowCVE-2025-26791SNYK-JS-DOMPURIFY-8722251dompurify2.5.7Cross-site Scripting (XSS)2025-02-14