Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Package ecosystem Maven. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 169 | 169 | 111 |
▁▁▁▂▆█▅
2026-02 1 · 2026-03 1 · 2026-04 2 · 2026-05 12 · 2026-06 49 · 2026-07 67 · 2026-08 37
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-34197 | 8.8 | 99.9 | KEV | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could… |
| CVE-2026-27446 | 9.3 | 95.2 | — | Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation |
| CVE-2026-43825 | 7.3 | 94.8 | — | Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel |
| CVE-2026-44825 | 9.8 | 80.8 | — | Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users |
| CVE-2026-45112 | 6.9 | 78.5 | — | Apache Thrift: Unbounded Read Leading to Denial of Service |
| CVE-2026-40047 | 9.1 | 76.5 | — | Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables ar… |
| CVE-2026-2332 | 9.1 | 66.1 | — | HTTP Request Smuggling via Chunked Extension Quoted-String Parsing |
| CVE-2026-53917 | 7.5 | 65.1 | — | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: U… |
| CVE-2026-42253 | 6.1 | 63.2 | — | Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Pr… |
| CVE-2026-43871 | 8.7 | 62.3 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt… |
| CVE-2026-48586 | 8.7 | 62.3 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-43865 | 8.1 | 59.2 | — | Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured manage… |
| CVE-2026-25747 | 8.8 | 57.0 | — | Apache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB |
| CVE-2026-54475 | 7.5 | 57.0 | — | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination own… |
| CVE-2026-43867 | 9.8 | 56.7 | — | Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes per… |
| CVE-2026-59878 | 7.5 | 56.3 | — | Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame siz… |
| CVE-2026-40859 | 8.1 | 56.3 | — | Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via… |
| CVE-2026-50633 | 8.1 | 55.7 | — | Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl |
| CVE-2026-46726 | 7.5 | 53.2 | — | Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket q… |
| CVE-2026-55993 | 7.5 | 53.2 | — | Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSoc… |
| Package | CVEs |
|---|---|
| org.apache.activemq:apache-activemq | 16 |
| org.apache.activemq:activemq-all | 13 |
| org.apache.cxf:cxf-rt-rs-security-oauth2 | 11 |
| org.apache.activemq:activemq-broker | 10 |
| org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol | 7 |
| org.apache.qpid:proton-j | 6 |
| org.apache.dolphinscheduler:dolphinscheduler-api | 5 |
| org.apache.qpid:protonj2 | 5 |
| org.apache.cxf:cxf-core | 4 |
| org.apache.cxf:cxf-rt-transports-jms | 3 |
| org.apache.fory:fory-core | 3 |
| org.apache.neethi:neethi | 3 |
| org.apache.sshd:sshd-git | 3 |
| org.apache.thrift:libthrift | 3 |
| com.fasterxml.jackson.core:jackson-core | 2 |