Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Maven
Package ecosystem Maven. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
Totals
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 331 | 327 | 199 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅▅█▂
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 2 · 2026-03 1 · 2026-04 5 · 2026-05 15 · 2026-06 49 · 2026-07 67 · 2026-08 61 · 2026-09 113 · 2026-10 13
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-46604 | 10.0 | 100.0 | KEV | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization caus… |
| CVE-2026-34197 | 8.8 | 96.7 | KEV | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could… |
| CVE-2025-68493 | 8.1 | 98.8 | — | Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component |
| CVE-2026-43825 | 7.3 | 96.4 | — | Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel |
| CVE-2026-44825 | 9.8 | 86.2 | — | Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users |
| CVE-2026-40047 | 9.1 | 83.7 | — | Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables ar… |
| CVE-2026-40860 | 9.8 | 73.9 | — | Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, cam… |
| CVE-2026-41042 | 9.1 | 73.6 | — | Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through th… |
| CVE-2026-2332 | 9.1 | 69.5 | — | HTTP Request Smuggling via Chunked Extension Quoted-String Parsing |
| CVE-2026-42027 | 9.8 | 68.8 | — | Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader |
| CVE-2026-50633 | 8.1 | 68.8 | — | Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl |
| CVE-2026-40858 | 8.8 | 67.8 | — | Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository |
| CVE-2026-27446 | 9.3 | 66.6 | — | Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation |
| CVE-2026-66909 | 9.8 | 65.7 | — | Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage |
| CVE-2026-50632 | 8.1 | 64.9 | — | Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory |
| CVE-2026-52680 | 9.8 | 64.8 | — | Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write |
| CVE-2026-53913 | 9.8 | 64.1 | — | Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only ins… |
| CVE-2026-57967 | 9.8 | 63.7 | — | Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol sessio… |
| CVE-2026-42440 | 7.5 | 63.5 | — | Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader |
| CVE-2026-55976 | 9.1 | 62.7 | — | Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation… |
Most-affected packages
| Package | CVEs |
|---|---|
| org.apache.activemq:apache-activemq | 17 |
| org.apache.activemq:activemq-all | 14 |
| org.apache.dolphinscheduler:dolphinscheduler-api | 14 |
| org.apache.activemq:activemq-broker | 11 |
| org.apache.cxf:cxf-rt-rs-security-oauth2 | 11 |
| org.apache.thrift:libthrift | 9 |
| org.apache.wicket:wicket-core | 9 |
| org.apache.neethi:neethi | 8 |
| org.apache.storm:storm-server | 8 |
| org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol | 7 |
| org.apache.qpid:proton-j | 6 |
| org.apache.syncope.core:syncope-core-spring | 6 |
| com.vaadin:vaadin | 5 |
| org.apache.activemq:artemis-server | 5 |
| org.apache.artemis:artemis-server | 5 |