← All images

kafka

Updated: 2026-04-29 05:50 UTC  |  Commit: d48be5a

PackageVersionSeverityCVEFix VersionDescription
plexus-utils3.5.1HIGHGHSA-6fmv-xxpf-w3cw3.6.1Plexus-Utils has a Directory Traversal vulnerability in its extractFile method
jetty-server12.0.22HIGHGHSA-xxh7-fcf3-rj7f12.0.32The Eclipse Jetty Server Artifact has a Gzip request memory leak
glibc2.43-r6HIGHCVE-2026-5928n/aCalling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte
jetty-http12.0.22HIGHGHSA-355h-qmc2-wpwf12.0.33Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
log4j-1.2-api2.25.3MEDIUMGHSA-h383-gmxw-35v22.25.4Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
log4j-core2.25.3MEDIUMGHSA-445c-vh5m-36rj2.25.4Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
log4j-core2.25.3MEDIUMGHSA-3pxv-7cmr-fjr42.25.4Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
log4j-core2.25.3MEDIUMGHSA-6hg6-v5c8-fphq2.25.4Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration
jackson-core2.19.2MEDIUMGHSA-72hv-8253-57qq2.21.1jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
jetty-http12.0.22LOWGHSA-wjpw-4j6x-6rwh12.0.31org.eclipse.jetty:jetty-http has different parsing of invalid URIs