boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Maven

Package ecosystem Maven. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals
CVEs all-timeCVEs YTDPackages affected
169169111

Monthly trend

▁▁▁▂▆█▅

2026-02 1 · 2026-03 1 · 2026-04 2 · 2026-05 12 · 2026-06 49 · 2026-07 67 · 2026-08 37

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-341978.899.9KEVApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could…
CVE-2026-274469.395.2Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
CVE-2026-438257.394.8Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
CVE-2026-448259.880.8Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
CVE-2026-451126.978.5Apache Thrift: Unbounded Read Leading to Denial of Service
CVE-2026-400479.176.5Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables ar…
CVE-2026-23329.166.1HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
CVE-2026-539177.565.1Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: U…
CVE-2026-422536.163.2Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Pr…
CVE-2026-438718.762.3Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt…
CVE-2026-485868.762.3Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-438658.159.2Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured manage…
CVE-2026-257478.857.0Apache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB
CVE-2026-544757.557.0Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination own…
CVE-2026-438679.856.7Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes per…
CVE-2026-598787.556.3Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame siz…
CVE-2026-408598.156.3Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via…
CVE-2026-506338.155.7Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
CVE-2026-467267.553.2Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket q…
CVE-2026-559937.553.2Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSoc…

Most-affected packages

Packages with the most advisories
PackageCVEs
org.apache.activemq:apache-activemq16
org.apache.activemq:activemq-all13
org.apache.cxf:cxf-rt-rs-security-oauth211
org.apache.activemq:activemq-broker10
org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol7
org.apache.qpid:proton-j6
org.apache.dolphinscheduler:dolphinscheduler-api5
org.apache.qpid:protonj25
org.apache.cxf:cxf-core4
org.apache.cxf:cxf-rt-transports-jms3
org.apache.fory:fory-core3
org.apache.neethi:neethi3
org.apache.sshd:sshd-git3
org.apache.thrift:libthrift3
com.fasterxml.jackson.core:jackson-core2