| com.fasterxml.jackson.core:jackson-core |
CVE-2025-52999 |
高危 |
2.13.4 |
2.15.0 |
com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-52999
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-06-25 17:15 修改: 2026-06-17 09:37
|
| com.fasterxml.jackson.core:jackson-core |
CVE-2025-52999 |
高危 |
2.14.3 |
2.15.0 |
com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-52999
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-06-25 17:15 修改: 2026-06-17 09:37
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.14.3 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.14.3 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.18.1 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.18.1 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.18.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.18.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.21.1 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.21.1 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.21.1 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.21.1 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.21.1 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.21.1 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54512 |
高危 |
2.21.1 |
2.18.8, 3.1.4, 2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54513 |
高危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00
|
| com.google.protobuf:protobuf-java |
CVE-2024-7254 |
高危 |
3.19.6 |
3.25.5, 4.27.5, 4.28.2 |
protobuf: StackOverflow vulnerability in Protocol Buffers
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-7254
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-09-19 01:15 修改: 2026-06-17 08:19
|
| com.google.protobuf:protobuf-java |
CVE-2024-7254 |
高危 |
3.21.12 |
3.25.5, 4.27.5, 4.28.2 |
protobuf: StackOverflow vulnerability in Protocol Buffers
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-7254
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-09-19 01:15 修改: 2026-06-17 08:19
|
| io.airlift:aircompressor |
CVE-2025-67721 |
高危 |
0.27 |
2.0.3 |
aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67721
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-12 23:15 修改: 2026-06-17 09:58
|
| io.grpc:grpc-netty-shaded |
CVE-2025-55163 |
高危 |
1.67.1 |
1.75.0 |
netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-55163
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-08-13 15:15 修改: 2026-06-17 09:41
|
| io.netty:netty-codec |
CVE-2026-42583 |
高危 |
4.1.110.Final |
4.1.133.Final |
Netty is an asynchronous, event-driven network application framework. ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42583
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|
| io.netty:netty-codec-dns |
CVE-2026-42579 |
高危 |
4.1.110.Final |
4.2.13.Final, 4.1.133.Final |
netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42579
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|
| io.netty:netty-codec-haproxy |
CVE-2026-44893 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44893
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:51
|
| io.netty:netty-codec-haproxy |
CVE-2026-48059 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48059
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:54
|
| io.netty:netty-codec-http |
CVE-2026-33870 |
高危 |
4.1.110.Final |
4.1.132.Final, 4.2.10.Final |
io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33870
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-03-27 20:16 修改: 2026-06-17 10:38
|
| io.netty:netty-codec-http |
CVE-2026-42584 |
高危 |
4.1.110.Final |
4.2.13.Final, 4.1.133.Final |
netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42584
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|
| io.netty:netty-codec-http |
CVE-2026-42587 |
高危 |
4.1.110.Final |
4.2.13.Final, 4.1.133.Final |
netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|
| io.netty:netty-codec-http2 |
CVE-2025-55163 |
高危 |
4.1.110.Final |
4.2.4.Final, 4.1.124.Final |
netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-55163
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-08-13 15:15 修改: 2026-06-17 09:41
|
| io.netty:netty-codec-http2 |
CVE-2026-33871 |
高危 |
4.1.110.Final |
4.1.132.Final, 4.2.11.Final |
netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33871
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-03-27 20:16 修改: 2026-06-17 10:38
|
| io.netty:netty-codec-http2 |
CVE-2026-42587 |
高危 |
4.1.110.Final |
4.2.13.Final, 4.1.133.Final |
netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|
| io.netty:netty-codec-redis |
CVE-2026-44250 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44250
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-11 22:16 修改: 2026-06-17 10:50
|
| io.netty:netty-codec-redis |
CVE-2026-44890 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44890
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-11 22:16 修改: 2026-06-17 10:51
|
| io.netty:netty-codec-redis |
CVE-2026-48006 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48006
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:54
|
| io.netty:netty-codec-redis |
CVE-2026-50011 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-codec-redis: Netty: Denial of Service via malicious Redis array header
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50011
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57
|
| io.netty:netty-codec-smtp |
CVE-2025-59419 |
高危 |
4.1.110.Final |
4.2.7.Final, 4.1.128.Final |
io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59419
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-10-15 16:15 修改: 2026-06-17 09:46
|
| io.netty:netty-handler |
CVE-2025-24970 |
高危 |
4.1.110.Final |
4.1.118.Final |
io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-24970
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-02-10 22:15 修改: 2026-06-17 08:59
|
| io.netty:netty-handler |
CVE-2026-44249 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44249
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-11 22:16 修改: 2026-06-17 10:50
|
| io.netty:netty-handler |
CVE-2026-45416 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45416
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52
|
| io.netty:netty-handler |
CVE-2026-50010 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50010
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57
|
| io.netty:netty-resolver-dns |
CVE-2026-45674 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45674
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52
|
| io.netty:netty-resolver-dns |
CVE-2026-47691 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47691
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:54
|
| io.netty:netty-transport-sctp |
CVE-2026-46340 |
高危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-46340
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:53
|
| org.eclipse.jetty:jetty-http |
CVE-2026-2332 |
高危 |
9.4.58.v20250814 |
12.1.7, 12.0.33 |
org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2332
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-14 12:16 修改: 2026-06-17 10:30
|
| org.eclipse.jetty:jetty-http |
CVE-2026-2332 |
高危 |
9.4.58.v20250814 |
12.1.7, 12.0.33 |
org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2332
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-14 12:16 修改: 2026-06-17 10:30
|
| org.eclipse.jetty:jetty-http |
CVE-2026-2332 |
高危 |
9.4.58.v20250814 |
12.1.7, 12.0.33 |
org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2332
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-14 12:16 修改: 2026-06-17 10:30
|
| org.eclipse.jetty:jetty-http |
CVE-2026-2332 |
高危 |
9.4.58.v20250814 |
12.1.7, 12.0.33 |
org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2332
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-14 12:16 修改: 2026-06-17 10:30
|
| org.eclipse.jetty:jetty-http |
CVE-2026-2332 |
高危 |
9.4.58.v20250814 |
12.1.7, 12.0.33 |
org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2332
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-14 12:16 修改: 2026-06-17 10:30
|
| org.eclipse.jetty:jetty-http |
CVE-2026-2332 |
高危 |
9.4.58.v20250814 |
12.1.7, 12.0.33 |
org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2332
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-14 12:16 修改: 2026-06-17 10:30
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54517 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54517
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:51
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54517 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54517
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:51
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54517 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54517
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:51
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54517 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54517
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:51
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54517 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54517
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:51
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54517 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54517
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:51
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54518 |
中危 |
2.21.1 |
2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54518
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 22:16 修改: 2026-06-27 20:49
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54518 |
中危 |
2.21.1 |
2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54518
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 22:16 修改: 2026-06-27 20:49
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54518 |
中危 |
2.21.1 |
2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54518
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 22:16 修改: 2026-06-27 20:49
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54518 |
中危 |
2.21.1 |
2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54518
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 22:16 修改: 2026-06-27 20:49
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54518 |
中危 |
2.21.1 |
2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54518
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 22:16 修改: 2026-06-27 20:49
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54518 |
中危 |
2.21.1 |
2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54518
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 22:16 修改: 2026-06-27 20:49
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54518 |
中危 |
2.21.1 |
2.21.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54518
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 22:16 修改: 2026-06-27 20:49
|
| com.fasterxml.jackson.core:jackson-core |
GHSA-72hv-8253-57qq |
中危 |
2.13.4 |
2.21.1, 2.18.6 |
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30
|
| com.fasterxml.jackson.core:jackson-core |
GHSA-72hv-8253-57qq |
中危 |
2.14.3 |
2.21.1, 2.18.6 |
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30
|
| com.nimbusds:nimbus-jose-jwt |
CVE-2025-53864 |
中危 |
9.37.2 |
10.0.2, 9.37.4 |
com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53864
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 03:16 修改: 2026-06-17 09:39
|
| com.nimbusds:nimbus-jose-jwt |
CVE-2025-53864 |
中危 |
9.37.2 |
10.0.2, 9.37.4 |
com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53864
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 03:16 修改: 2026-06-17 09:39
|
| com.nimbusds:nimbus-jose-jwt |
CVE-2025-53864 |
中危 |
9.37.2 |
10.0.2, 9.37.4 |
com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53864
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 03:16 修改: 2026-06-17 09:39
|
| com.nimbusds:nimbus-jose-jwt |
CVE-2025-53864 |
中危 |
9.37.2 |
10.0.2, 9.37.4 |
com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53864
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 03:16 修改: 2026-06-17 09:39
|
| com.nimbusds:nimbus-jose-jwt |
CVE-2025-53864 |
中危 |
9.37.2 |
10.0.2, 9.37.4 |
com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53864
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 03:16 修改: 2026-06-17 09:39
|
| com.nimbusds:nimbus-jose-jwt |
CVE-2025-53864 |
中危 |
9.37.2 |
10.0.2, 9.37.4 |
com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53864
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 03:16 修改: 2026-06-17 09:39
|
| commons-lang:commons-lang |
CVE-2025-48924 |
中危 |
2.6 |
|
commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30
|
| commons-lang:commons-lang |
CVE-2025-48924 |
中危 |
2.6 |
|
commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30
|
| commons-lang:commons-lang |
CVE-2025-48924 |
中危 |
2.6 |
|
commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30
|
| commons-lang:commons-lang |
CVE-2025-48924 |
中危 |
2.6 |
|
commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.18.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.18.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.18.1 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| io.netty:netty-codec |
CVE-2025-58057 |
中危 |
4.1.110.Final |
4.1.125.Final |
netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58057
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-09-04 10:42 修改: 2026-06-17 09:43
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.18.1 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.14.3 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.14.3 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| com.fasterxml.jackson.core:jackson-core |
GHSA-72hv-8253-57qq |
中危 |
2.18.1 |
2.21.1, 2.18.6 |
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30
|
| com.fasterxml.jackson.core:jackson-core |
GHSA-72hv-8253-57qq |
中危 |
2.18.1 |
2.21.1, 2.18.6 |
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| io.netty:netty-codec-http |
CVE-2025-67735 |
中危 |
4.1.110.Final |
4.2.8.Final, 4.1.129.Final |
netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67735
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-16 01:15 修改: 2026-06-17 09:58
|
| io.netty:netty-codec-http |
CVE-2026-41417 |
中危 |
4.1.110.Final |
4.1.133.Final, 4.2.13.Final |
netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41417
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-06 22:16 修改: 2026-06-17 10:46
|
| io.netty:netty-codec-http |
CVE-2026-42580 |
中危 |
4.1.110.Final |
4.2.13.Final, 4.1.133.Final |
netty: Netty: Request smuggling via chunk size parser integer overflow
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42580
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|
| io.netty:netty-codec-http |
CVE-2026-42581 |
中危 |
4.1.110.Final |
4.2.13.Final, 4.1.133.Final |
netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42581
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|
| io.netty:netty-codec-http |
CVE-2026-42585 |
中危 |
4.1.110.Final |
4.2.13.Final, 4.1.133.Final |
netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42585
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|
| io.netty:netty-codec-http |
CVE-2026-50020 |
中危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50020
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| io.netty:netty-codec-http2 |
CVE-2026-47244 |
中危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47244
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:54
|
| io.netty:netty-codec-http2 |
CVE-2026-48043 |
中危 |
4.1.110.Final |
4.1.135.Final, 4.2.15.Final |
netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48043
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:54
|
| io.netty:netty-codec-http2 |
CVE-2026-50560 |
中危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50560
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57
|
| io.netty:netty-codec-mqtt |
CVE-2026-44248 |
中危 |
4.1.110.Final |
4.2.13.Final, 4.1.133.Final |
netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44248
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:50
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54514 |
中危 |
2.21.1 |
2.18.8, 2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.21.1 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| io.netty:netty-codec-redis |
CVE-2026-42586 |
中危 |
4.1.110.Final |
4.2.13.Final, 4.1.133.Final |
netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42586
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.21.1 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| io.netty:netty-common |
CVE-2024-47535 |
中危 |
4.1.110.Final |
4.1.115.Final |
netty: Denial of Service attack on windows app using Netty
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47535
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-11-12 16:15 修改: 2026-06-17 07:57
|
| io.netty:netty-common |
CVE-2025-25193 |
中危 |
4.1.110.Final |
4.1.118.Final |
netty: Denial of Service attack on windows app using Netty
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-25193
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-02-10 22:15 修改: 2026-06-17 09:00
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.21.1 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.21.1 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.21.1 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.21.1 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54515 |
中危 |
2.21.1 |
3.1.4, 2.18.9, 2.21.5 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54516 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54516
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:52
|
| io.netty:netty-resolver-dns |
CVE-2026-45673 |
中危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45673
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52
|
| io.netty:netty-transport-native-epoll |
CVE-2026-45536 |
中危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52
|
| io.netty:netty-transport-native-kqueue |
CVE-2026-45536 |
中危 |
4.1.110.Final |
4.2.15.Final, 4.1.135.Final |
netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45536
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54516 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54516
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:52
|
| io.opentelemetry:opentelemetry-api |
CVE-2026-45292 |
中危 |
1.42.1 |
1.62.0 |
opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45292
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-28 17:16 修改: 2026-06-17 10:51
|
| junit:junit |
CVE-2020-15250 |
中危 |
4.10 |
4.13.1 |
junit4: TemporaryFolder is shared between all users across system which could result in information disclosure
漏洞详情: https://avd.aquasec.com/nvd/cve-2020-15250
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2020-10-12 18:15 修改: 2026-06-17 02:56
|
| org.apache.commons:commons-configuration2 |
CVE-2026-45205 |
中危 |
2.10.1 |
2.15.0 |
Uncontrolled Recursion vulnerability in Apache Commons. When processi ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51
|
| org.apache.commons:commons-configuration2 |
CVE-2026-45205 |
中危 |
2.10.1 |
2.15.0 |
Uncontrolled Recursion vulnerability in Apache Commons. When processi ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51
|
| org.apache.commons:commons-configuration2 |
CVE-2026-45205 |
中危 |
2.10.1 |
2.15.0 |
Uncontrolled Recursion vulnerability in Apache Commons. When processi ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51
|
| org.apache.commons:commons-configuration2 |
CVE-2026-45205 |
中危 |
2.10.1 |
2.15.0 |
Uncontrolled Recursion vulnerability in Apache Commons. When processi ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51
|
| org.apache.commons:commons-configuration2 |
CVE-2026-45205 |
中危 |
2.10.1 |
2.15.0 |
Uncontrolled Recursion vulnerability in Apache Commons. When processi ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51
|
| org.apache.commons:commons-configuration2 |
CVE-2026-45205 |
中危 |
2.10.1 |
2.15.0 |
Uncontrolled Recursion vulnerability in Apache Commons. When processi ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45205
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-14 12:16 修改: 2026-06-17 10:51
|
| org.apache.commons:commons-lang3 |
CVE-2025-48924 |
中危 |
3.12.0 |
3.18.0 |
commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30
|
| org.apache.commons:commons-lang3 |
CVE-2025-48924 |
中危 |
3.9 |
3.18.0 |
commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-07-11 15:15 修改: 2026-06-17 09:30
|
| org.apache.logging.log4j:log4j-core |
CVE-2025-68161 |
中危 |
2.23.1 |
2.25.3 |
Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68161
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-18 21:15 修改: 2026-06-17 09:58
|
| org.apache.logging.log4j:log4j-core |
CVE-2025-68161 |
中危 |
2.23.1 |
2.25.3 |
Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68161
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-18 21:15 修改: 2026-06-17 09:58
|
| org.apache.logging.log4j:log4j-core |
CVE-2025-68161 |
中危 |
2.23.1 |
2.25.3 |
Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68161
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-18 21:15 修改: 2026-06-17 09:58
|
| org.apache.logging.log4j:log4j-core |
CVE-2025-68161 |
中危 |
2.23.1 |
2.25.3 |
Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68161
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-18 21:15 修改: 2026-06-17 09:58
|
| org.apache.logging.log4j:log4j-core |
CVE-2025-68161 |
中危 |
2.23.1 |
2.25.3 |
Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68161
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-18 21:15 修改: 2026-06-17 09:58
|
| org.apache.logging.log4j:log4j-core |
CVE-2025-68161 |
中危 |
2.23.1 |
2.25.3 |
Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68161
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-18 21:15 修改: 2026-06-17 09:58
|
| org.apache.logging.log4j:log4j-core |
CVE-2025-68161 |
中危 |
2.23.1 |
2.25.3 |
Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68161
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-18 21:15 修改: 2026-06-17 09:58
|
| org.apache.logging.log4j:log4j-core |
CVE-2025-68161 |
中危 |
2.23.1 |
2.25.3 |
Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68161
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-12-18 21:15 修改: 2026-06-17 09:58
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34477 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34477
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34477 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34477
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34477 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34477
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34477 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34477
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34477 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34477
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34477 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34477
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34477 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34477
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34477 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34477
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34478 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34478
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34478 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34478
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34478 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34478
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34478 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34478
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34478 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34478
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34478 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34478
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34478 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34478
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34478 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34478
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34480 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34480
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34480 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34480
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34480 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34480
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34480 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34480
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34480 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34480
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34480 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34480
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34480 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34480
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.apache.logging.log4j:log4j-core |
CVE-2026-34480 |
中危 |
2.23.1 |
2.25.4 |
org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34480
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-04-10 16:16 修改: 2026-06-17 10:39
|
| org.bouncycastle:bcprov-jdk15on |
CVE-2023-33201 |
中危 |
1.70 |
|
bouncycastle: potential blind LDAP injection attack using a self-signed certificate
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-33201
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2023-07-05 03:15 修改: 2026-06-17 06:01
|
| org.bouncycastle:bcprov-jdk15on |
CVE-2024-29857 |
中危 |
1.70 |
1.78 |
org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29857
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-05-14 15:17 修改: 2026-06-17 07:23
|
| org.bouncycastle:bcprov-jdk15on |
CVE-2024-30171 |
中危 |
1.70 |
1.78 |
bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-30171
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-05-14 15:21 修改: 2026-06-17 07:26
|
| org.bouncycastle:bcprov-jdk15on |
CVE-2024-34447 |
中危 |
1.70 |
1.78 |
org.bouncycastle: Use of Incorrectly-Resolved Name or Reference
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34447
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-05-03 16:15 修改: 2026-06-17 07:33
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54516 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54516
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:52
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54516 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54516
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:52
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54516 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54516
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:52
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54516 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54516
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:52
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54516 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54516
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:52
|
| com.fasterxml.jackson.core:jackson-databind |
CVE-2026-54517 |
中危 |
2.21.1 |
2.21.4, 3.1.4 |
jackson-databind contains the general-purpose data-binding functionali ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54517
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:51
|
| org.eclipse.jetty:jetty-http |
CVE-2024-6763 |
中危 |
9.4.58.v20250814 |
12.0.12 |
org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6763
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-10-14 16:15 修改: 2026-06-17 08:18
|
| org.eclipse.jetty:jetty-http |
CVE-2024-6763 |
中危 |
9.4.58.v20250814 |
12.0.12 |
org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6763
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-10-14 16:15 修改: 2026-06-17 08:18
|
| org.eclipse.jetty:jetty-http |
CVE-2024-6763 |
中危 |
9.4.58.v20250814 |
12.0.12 |
org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6763
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-10-14 16:15 修改: 2026-06-17 08:18
|
| org.eclipse.jetty:jetty-http |
CVE-2024-6763 |
中危 |
9.4.58.v20250814 |
12.0.12 |
org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6763
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-10-14 16:15 修改: 2026-06-17 08:18
|
| org.eclipse.jetty:jetty-http |
CVE-2024-6763 |
中危 |
9.4.58.v20250814 |
12.0.12 |
org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6763
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-10-14 16:15 修改: 2026-06-17 08:18
|
| org.eclipse.jetty:jetty-http |
CVE-2024-6763 |
中危 |
9.4.58.v20250814 |
12.0.12 |
org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6763
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2024-10-14 16:15 修改: 2026-06-17 08:18
|
| io.netty:netty-codec-http |
CVE-2025-58056 |
低危 |
4.1.110.Final |
4.1.125.Final, 4.2.5.Final |
netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58056
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2025-09-03 21:15 修改: 2026-06-17 09:43
|
| io.netty:netty-handler-proxy |
CVE-2026-42578 |
低危 |
4.1.110.Final |
4.1.133.Final, 4.2.13.Final |
netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42578
镜像层: sha256:6079351f35513d714974e84c3d32bd1f8f0e391aca89272f71f05ae208e7906f
发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48
|