| π‘ medium |
CVE-2023-33201 |
org.bouncycastle:bcprov-jdk15on |
>= 1.49, <= 1.70 |
β |
β |
| π‘ medium |
CVE-2024-29857 |
org.bouncycastle:bcprov-jdk15on |
< 1.78 |
1.78 |
β |
| π‘ medium |
CVE-2024-30171 |
org.bouncycastle:bcprov-jdk15on |
< 1.78 |
1.78 |
β |
| π high |
CVE-2024-7254 |
com.google.protobuf:protobuf-java |
< 3.25.5 |
3.25.5 |
β |
| π‘ medium |
CVE-2024-31141 |
org.apache.kafka:kafka-clients |
>= 2.3.0, < 3.7.1 |
3.7.1 |
β |
| π high |
CVE-2024-50379 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.2 |
11.0.2 |
β |
| π high |
CVE-2024-56337 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.2 |
11.0.2 |
β |
| π΄ critical |
CVE-2025-24813 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.3 |
11.0.3 |
β |
| π΄ critical |
CVE-2025-30065 |
org.apache.parquet:parquet-avro |
< 1.15.1 |
1.15.1 |
β |
| π high |
CVE-2025-46762 |
org.apache.parquet:parquet-avro |
< 1.15.2 |
1.15.2 |
β |
| π‘ medium |
CVE-2025-31650 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M2, < 11.0.6 |
11.0.6 |
β |
| π΅ low |
CVE-2025-31651 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M2, < 11.0.6 |
11.0.6 |
β |
| π΅ low |
CVE-2025-46701 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.7 |
11.0.7 |
β |
| π‘ medium |
CVE-2025-27817 |
org.apache.kafka:kafka-clients |
>= 3.1.0, < 3.9.1 |
3.9.1 |
β |
| π high |
CVE-2025-48988 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, <= 11.0.7 |
11.0.8 |
β |
| π‘ medium |
CVE-2025-49125 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, <= 11.0.7 |
11.0.8 |
β |
| π high |
CVE-2024-51504 |
org.apache.zookeeper:zookeeper |
>= 3.9.0, < 3.9.3 |
3.9.3 |
β |
| π‘ medium |
CVE-2025-53864 |
com.nimbusds:nimbus-jose-jwt |
< 9.37.4 |
9.37.4 |
β |
| π high |
CVE-2025-48989 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.10 |
11.0.10 |
β |
| π‘ medium |
CVE-2025-58457 |
org.apache.zookeeper:zookeeper |
>= 3.9.0, < 3.9.4 |
3.9.4 |
β |
| π high |
CVE-2025-55752 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.11 |
11.0.11 |
β |
| π΅ low |
CVE-2025-55754 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.11 |
11.0.11 |
β |
| π΅ low |
CVE-2025-61795 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.12 |
11.0.12 |
β |
| π‘ medium |
CVE-2025-49124 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.8 |
11.0.8 |
β |
| π‘ medium |
CVE-2025-11226 |
ch.qos.logback:logback-core |
>= 1.4.0, < 1.5.19 |
1.5.19 |
β |
| π‘ medium |
CVE-2025-68161 |
org.apache.logging.log4j:log4j-core |
>= 2.0-beta9, < 2.25.3 |
2.25.3 |
β |
| π΅ low |
CVE-2026-1225 |
ch.qos.logback:logback-core |
< 1.5.25 |
1.5.25 |
β |
| π high |
CVE-2025-67721 |
io.airlift:aircompressor |
< 2.0.3 |
2.0.3 |
β |
| π high |
CVE-2026-1605 |
org.eclipse.jetty:jetty-server |
>= 12.0.0, <= 12.0.31 |
12.0.32 |
β |
| π high |
CVE-2025-53506 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.9 |
11.0.9 |
β |
| π high |
CVE-2025-52520 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.9 |
11.0.9 |
β |
| π high |
CVE-2026-24308 |
org.apache.zookeeper:zookeeper |
>= 3.9.0, < 3.9.5 |
3.9.5 |
β |
| π‘ medium |
CVE-2025-66614 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.15 |
11.0.15 |
β |
| π high |
CVE-2026-24281 |
org.apache.zookeeper:zookeeper |
>= 3.9.0, < 3.9.5 |
3.9.5 |
β |
| π high |
CVE-2026-24734 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.18 |
11.0.18 |
β |
| π‘ medium |
CVE-2026-25854 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.20 |
11.0.20 |
β |
| π high |
CVE-2026-34483 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.21 |
11.0.21 |
β |
| π‘ medium |
CVE-2026-34480 |
org.apache.logging.log4j:log4j-core |
>= 2.0-alpha1, < 2.25.4 |
2.25.4 |
β |
| π high |
CVE-2026-35554 |
org.apache.kafka:kafka-clients |
>= 2.8.0, < 3.9.2 |
3.9.2 |
β |
| π‘ medium |
CVE-2026-34477 |
org.apache.logging.log4j:log4j-core |
>= 2.12.0, < 2.25.4 |
2.25.4 |
β |
| π‘ medium |
CVE-2024-34447 |
org.bouncycastle:bcprov-jdk15on |
>= 1.61, < 1.78 |
1.78 |
β |
| π‘ medium |
CVE-2026-33558 |
org.apache.kafka:kafka-clients |
>= 0.11.0, < 3.9.2 |
3.9.2 |
β |
| π high |
CVE-2026-43869 |
org.apache.thrift:libthrift |
<= 0.22.0 |
0.23.0 |
β |
| π high |
CVE-2026-41284 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.22 |
11.0.22 |
β |
| π΄ critical |
CVE-2026-41293 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.22 |
11.0.22 |
β |
| π high |
CVE-2026-42498 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.22 |
11.0.22 |
β |
| π high |
CVE-2026-43513 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.22 |
11.0.22 |
β |
| π΄ critical |
CVE-2026-43512 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.22 |
11.0.22 |
β |
| π΅ low |
CVE-2026-43514 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.22 |
11.0.22 |
β |
| π΄ critical |
CVE-2026-43515 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.22 |
11.0.22 |
β |
| π‘ medium |
CVE-2026-45205 |
org.apache.commons:commons-configuration2 |
>= 2.2, < 2.15.0 |
2.15.0 |
β |
| π high |
CVE-2026-24880 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, <= 11.0.18 |
11.0.20 |
β |
| π high |
CVE-2026-44893 |
io.netty:netty-codec-haproxy |
<= 4.1.134.Final |
4.1.135.Final |
β |
| π high |
CVE-2026-48059 |
io.netty:netty-codec-haproxy |
<= 4.1.134.Final |
4.1.135.Final |
β |
| π high |
CVE-2026-54513 |
com.fasterxml.jackson.core:jackson-databind |
>= 2.10.0, < 2.18.8 |
2.18.8 |
β |
| π high |
CVE-2026-54512 |
com.fasterxml.jackson.core:jackson-databind |
>= 2.10.0, <= 2.18.7 |
2.18.8 |
β |
| π‘ medium |
CVE-2026-54515 |
com.fasterxml.jackson.core:jackson-databind |
>= 2.8.0, < 2.18.9 |
2.18.9 |
β |
| π‘ medium |
CVE-2026-54514 |
com.fasterxml.jackson.core:jackson-databind |
>= 2.0.0, < 2.18.8 |
2.18.8 |
β |
| π‘ medium |
CVE-2025-55668 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.8 |
11.0.8 |
β |
| π΅ low |
CVE-2026-9828 |
ch.qos.logback:logback-core |
<= 1.5.32 |
1.5.33 |
β |
| π‘ medium |
CVE-2026-46718 |
org.apache.calcite:calcite-core |
>= 1.5.0, < 1.42.0 |
1.42.0 |
β |
| π΅ low |
CVE-2026-10532 |
ch.qos.logback:logback-core |
< 1.5.34 |
1.5.34 |
β |
| π‘ medium |
CVE-2026-59888 |
com.fasterxml.jackson.core:jackson-databind |
>= 2.15.0, < 2.18.8 |
2.18.8 |
β |
| π high |
GHSA-r7wm-3cxj-wff9 |
com.fasterxml.jackson.core:jackson-core |
< 2.18.8 |
2.18.8 |
β |
| π‘ medium |
CVE-2026-59919 |
io.netty:netty-codec-haproxy |
< 4.1.136.Final |
4.1.136.Final |
β |
| π high |
CVE-2026-55851 |
io.netty:netty-codec-haproxy |
>= 4.1.0.Final, <= 4.1.135.Final |
4.1.136.Final |
β |
| π‘ medium |
CVE-2026-10051 |
org.eclipse.jetty:jetty-server |
>= 12.0.0, <= 12.0.35 |
12.0.36 |
β |
| π‘ medium |
CVE-2026-6790 |
org.eclipse.jetty:jetty-server |
>= 12.0.0, <= 12.0.34 |
12.0.35 |
β |
| π‘ medium |
CVE-2026-18401 |
com.fasterxml.jackson.core:jackson-core |
>= 2.15.0, <= 2.18.5 |
2.18.6 |
β |
| π high |
CVE-2026-34487 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.21 |
11.0.21 |
β |
| π‘ medium |
CVE-2026-49844 |
org.apache.logging.log4j:log4j-api |
>= 2.13.1, < 2.25.5 |
2.25.5 |
β |
| π high |
CVE-2026-43871 |
org.apache.thrift:libthrift |
< 0.24.0 |
0.24.0 |
β |
| π΄ critical |
CVE-2026-65905 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.25 |
11.0.25 |
β |
| π΄ critical |
CVE-2026-68525 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.25 |
11.0.25 |
β |
| π΄ critical |
CVE-2026-65182 |
org.apache.tomcat.embed:tomcat-embed-core |
>= 11.0.0-M1, < 11.0.25 |
11.0.25 |
β |
π Security Alerts β IBM/java-iceberg-toolkit
Attention: @brajeshkpandey
Dependabot Alerts
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.